/
2022-09-27 Security Subcommittee Meeting Notes

2022-09-27 Security Subcommittee Meeting Notes

Please find below the Minutes of Meetings and recording for the SECCOM meeting that was held on 27th of September 2022.

Jira No

Summary

Description

Status

Solution

Jira No

Summary

Description

Status

Solution



Architecture review template

Byung prsented he current template: ONAP Component Architecture Review Template Security related comments were shared on container hardening, pen testing, API security, logging requirements.  

ongoing





TSC elections

New e-mail for voting process will be sent.







Superblueprint demo update

Enterprise IOT URLLC demo - camera doing the inspection. Severs instalation just completed. 







PTLs meeting

Vijay was surprised with latest scans and smal progress - Amy will have a meeting with him on that.

SBOM - Muddasar plans to contact a few PTLs.







Update on the Security Logging Fields  

 Python container PoC and extending Andrew Lang's work on logging architecture.

Additional internal resource might be available from MITRE.

Michal's feedback on modyfing Python base image.

ongoing

We have to identify right PTLs - Pawel and Amy to propose PTL by end of this week. Michal could be involved.



Daylight saving time 

To be further elaborated. In US in the week of November 4th, to be checked for Europe/Poland.







SECCOM MEETING CALL WILL BE HELD ON 4th OF October'22. 

Architecture review template to be reviewed.











Recordings: 

1: SECCOM-2022-09-27-1.mp4

2: SECCOM-2022-09-27-2.mp4

3: SECCOM-2022-09-27-3.mp4



SECCOM presentation: