2023-02-21 Security Subcommittee Meeting Notes

Please find below the Minutes of Meetings and recording for the SECCOM meeting that was held on 21st of February 2023.

Jira No

Summary

Description

Status

Solution

Jira No

Summary

Description

Status

Solution



Reviewed DTF presentations

  • Nephio

  • London security architecture

  • Logging POC with FluentBit

  • Reducing PTL work (Magnus, David McBride)

  • What's Next for ONAP (Pawel)







Security Questionnaire for CPS



  • Review SECCOM feedback on 28 February call

  • Invite CPS to 7 March SECCOM call



CPS Security review questionaire by Tony

  • CPS provided their feedback.

  • CPS - ONAP Security Review Questionnaire

  • Updated the wiki during the call with SECCOM feedback

  • All participants asked to provide feedback before the 28 February SECCOM call

  • Invite CPS to 7 March SECCOM call to review our assessment with them

ongoing

We should now review answers and provide comments by February 28th and CPS team could be invited to SECCOM on March 7th.



NIST has also just joined ORAN Alliance.

https://www.nist.gov/news-events/news/2023/01/nist-joins-alliance-promote-open-wireless-technologies-and-supply-chains
https://www.theregister.com/AMP/2023/01/26/nist_5g_open_ran/







SECCOM MEETING CALL WILL BE HELD ON 28th February 2023. 

  • CPS Security questionnaire review by SECCOM.

  • IT-24999 Security Issue - Sensitive information leakage 

  • Python PoC by Bob – Work in Progress – Fiachra still to be contacted

  • Progress on package upgrades

  • Progress on unmaintained repos











Recordings: 

2023_02_21 audio recording.m4a

2023_02_21 video recording.mp4



SECCOM presentation:

2023-02-21 ONAP Security Meeting - AgendaAndMinutes.pptx