2022-03-22 Security Subcommittee Meeting Notes
Please find below the Minutes of Meetings and recording for the SECCOM meeting that was held on 22nd of March 2022.
Jira No | Summary | Description | Status | Solution |
---|---|---|---|---|
| Updates to Secure Design Questionnaire - Maggie | Know Secure Design Just wording change:
Larger comment
Implement Secure Design
Crypto Call – Generic
Crypto Random - Generic (NIST SP 800-90C)
90C is about putting various pieces together (entropy source and the "pseudo-random number generator" PRNG). 90A has the PRNG algorithms. 90B has testing requirements for entropy sources. | ongoing | Update to be incorporated by Maggie into the existing Wiki: https://lf-onap.atlassian.net/wiki/display/DW/ONAP+Security+Review+Questionnaire+Template Muddasar will prepare grade rate assessment proposal. |
| New SECCOM contributor | Welcome on board Alexander from Samsung. Major interests:
|
| Ticket to be opened by Alexander to LFN-IT - done https://jira.linuxfoundation.org/plugins/servlet/theme/portal/2/IT-23764# ticket created E-mail about SPDX SBOM configuration to be shared by Muddasar with Alex. |
| Istanbul Maintenance Release Notes on Log4j transitive dependencies | ongoing | To be checked with Dan if Reload4j is a good alternative for his projects. | |
| ONAP Jakarta: Vulnerable Package Upgrades - Amy | We reached 60% of packages upgraded. | ongoing |
|
| Quality gates - PoC with SO. | Meeting with Seshu done. SO would like to use https://www.sonarlint.org/ , Looking for IDE expertise. https://docs.sonarqube.org/latest/user-guide/clean-as-you-code/ - quality code would be for a new code. | ongoing | Ticket to be opened to LFN-IT to get clarification on SonarLint licensing. Maggie will check for IDE expertise. Details on IDE environment (Dual Studio?) to be provided by Fabian. |
| Security Logging requirements | Bob provided logging update presentation to last PTL's meeting. Comment from Dan on potential conflicting with Logging Analytics project (unmaintained). Dan will do some research. | ongoing | Synch up with Toine by Bob to address timeline for PoC. |
| Out of band planning for issues and topics, technical debt | Target of 10-20% of development capacity on technical debt. This should be discussed at the planning meetings. El-Alto release was focussed on technical debt. Now we have Global Requirements implemented and reviewed compliance every release. We first focussed on Java and Python upgrades, but also to take all of the interfaces to support HTTPs, upgrade direct dependencies, or Sonarcloud findings that are security related that are critical to be fixed. Other activity is code quality improvement. ODL allignement is managed by Dan who does the upgrade based on what is available on ODL side. Mainly requirement coming from security point of view are the recurring ones (every 6 months cycle), except for code quality improvement requirement. Log4j was a good example of out of band planning, extraordinary event that we responded. | started | Meeting with David is planned. Waiting for Kenny's feedback. Correlation with ODL meeting. |
| SBOM meetings | The meeting on March 7th was focussed on fixing the issue with Maven which was resolved. There are no other meetings scheduled. | ongoing |
|
| SECCOM calendar - old link | In the list.onap.org for SECCOM meetings there is an old link - tobe fixed | done | Pawel to replace old zoom link with the new one - done. |
| SECCOM MEETING CALL WILL BE HELD ON 29th OF MARCH'22. | Quality gates for code quality improvements - Fabian's presentation. 5Y review criteria. SonarCloud fixing with new code focus.
|
|
|
Recording:
SECCOM presentation: