Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Check MinSec controls #10

Open
akkornel opened this issue Apr 8, 2018 · 0 comments
Open

Check MinSec controls #10

akkornel opened this issue Apr 8, 2018 · 0 comments
Labels
content Web site content help wanted Extra attention is needed

Comments

@akkornel
Copy link
Member

akkornel commented Apr 8, 2018

As per #7, "If we meet the technical controls on our side, that is sufficient." So, let's take a look at those controls, and see what (if anything) needs to be done.

Below are all of the different MinSec points that apply to the Low and Medium Risk levels. Applications and Saas/PaaS are both listed because Globus is a tightly-bound collection of programs that run on the client/server side, and the Globus Internet-based service. For more information, reference the draft Globus Security page, at TBD.

Each point below will have a referenced GitHub issue number, where notes/discussion on that issue can take place. Items marked "N/A" do not apply. Items without any marking haven't been reviewed yet.

MinSec for Applications, all risk levels:

• Patching: #11
• Vulnerability Management: #13
• Inventory: #21
• Firewall: #12
• Credentials and Access Control: #14

MinSec for Applications, Medium Risk and above:

• Two-Step Authentication: #15
• Centralized Logging: #16
• Secure Software Development: #23
• Developer Training: #22
• Backups: #8

MinSec for SaaS/PaaS, all risk levels:

• Product Selection:
• Pre-implementation Planning:
• Inventory and Asset Classification: #21
• Credential and Key Management: #24
• Encryption: #25

MinSec for SaaS/PaaS, Medium Risk and above:

• Two-Step Authentication: #26
• Logging and Auditing: #27
• Data Management: #28

@akkornel akkornel added help wanted Extra attention is needed content Web site content labels Apr 8, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
content Web site content help wanted Extra attention is needed
Projects
None yet
Development

No branches or pull requests

1 participant