2022-11-29 Security Subcommittee Meeting Notes

Please find below the Minutes of Meetings and recording for the SECCOM meeting that was held on 29th of November 2022.

Jira No

Summary

Description

Status

Solution

Jira No

Summary

Description

Status

Solution



ONAP's evolution

Magnus's presentation invokes discussions in Archcom and in SECCOM.

SECCOM does not identify specific value in moving from subcommittee to Special Interest Group. We value fast decitsion making and execution on time.

ORAN defined ONAP core functions from their perspective. It cvould be a good baseline for us.

started





ONAP security review questionnaire

In October the first application finished filling out our ONAP security review questionnaire, DCAE - ONAP Security Review Questionnaire Template

-3 x 1 hour sessions needed to go through the process.

-To be further discussed on how we should proceed with reviewing it.

Grade system usefullness to be discussed. Actions to follow up are valuable.

ongoing

We book the slot in the agenda for next week to collect feedback on Vijay's answers and questionnaire itself.



SECCOM Dashboard

Weekly scans re-enabled with Michal’s support:

-https://logs.onap.org/onap-integration/weekly/onap-weekly-dt-oom-kohn/2022-11/18_17-45/security/versions/versions.html







ONES NA summary

Multiple interesting presentations, SECCOM included. It was great to meet some of you in person!

Waivers policy was presented and discussed. We can not accept never ending waivers.







TSC meeting

TSC Chair voting process started – Pawel candidates

Discussion on supercommitter rights







SCA analysis

Automated NEXUS-IQ scans and recommendations for packages upgrades for London release. Work in progress.







SECCOM MEETING CALL WILL BE HELD ON 6th OF
December'22. 













Recordings: 

2022-11-29_SECCOM_week.mp4



SECCOM presentation:

2022-11-29 ONAP Security Meeting - AgendaAndMinutes.pptx