tag-security icon indicating copy to clipboard operation
tag-security copied to clipboard

[Sec Assess WG] Getting more reviewers for Security Assessments

Open lumjjb opened this issue 4 years ago • 20 comments

This issue was created from results of the Security Assessment Improvement Working Group (https://github.com/cncf/sig-security/issues/167#issuecomment-714514142).

Getting more reviewers for Security Assessments

Premise

  • Challenge of assembling a team for each review

Ideas

  • what are the reasons that people want to participate? can we incentivize more?
  • Provide swag/recognition
  • For issues found they would get discount for courses and conferences
  • actively reach out to past reviewers (This is currently done by co-chairs and TLs informally)
  • Create a more concrete list of the expectations/requirements of a reviewer
  • Find new ways to engage new reviewers including in-experienced ones
  • Reach out to researchers to review the projects
  • Recommend the CNCF provide training/skills to community members to be able to perform assessments and audits

Logistics

  • [x] Contributors (For multiple contributors, 1 lead to coordinate)
  • @magnologan
  • Placeholder_2
  • [x] SIG-Representative @lumjjb

lumjjb avatar Oct 30 '20 15:10 lumjjb

I'm interested!

magnologan avatar Nov 03 '20 16:11 magnologan

This issue has been automatically marked as inactive because it has not had recent activity.

stale[bot] avatar Jan 09 '21 20:01 stale[bot]

Working on it! =)

magnologan avatar Jan 11 '21 15:01 magnologan

what are the reasons that people want to participate?

  • Help the community
  • Participate in an open source project
  • Help share the security of Cloud Native applications
  • Make an impact on the future of cloud infrastructure

can we incentivize more?

  • Yes, better marketing on Security Forums and Lists would be good.
  • Any swag or recognition such as a Hall of Fame of Contributors would be helpful

Provide swag/recognition

  • Swag is great for this, anything from stickers, to keychains, mugs, shirts or hoodies.

For issues found they would get discount for courses and conference

Example:

  • Critical Issue: 30% on any LF course
  • High Issue: 20% on any LF course
  • Medium Issue: 10% on any LF course
  • Low Issue: 5% on any LF course

Actively reach out to past reviewers (This is currently done by co-chairs and TLs informally)

  • Create a DL and maybe rank past reviewers based on the number of past reviews and number of issues found.

Create a more concrete list of the expectations/requirements of a reviewer Find new ways to engage new reviewers including inexperienced ones

  • What needs to be checked?
  • Do I need to review code? If so, what language?
  • Common issues to look for
  • Link to past reviews from similar projects
  • Security Audit Review Checklist (series of basic security verifications that should be performed on all CNCF projects)

Reach out to researchers to review the projects

  • Security companies that are interested in Cloud Native Security would probably be interested to help.

Recommend the CNCF provide training/skills to community members to be able to perform assessments and audits

  • Create a short training on How to Perform Security Audit Reviews and assign it to 1st-time reviwers

magnologan avatar Jan 14 '21 23:01 magnologan

plus add a guide on how to sign up as a security auditor/participant and how to claim a work item as part of the short training video.

aspanner avatar Jan 15 '21 00:01 aspanner

This issue has been automatically marked as inactive because it has not had recent activity.

stale[bot] avatar Mar 16 '21 02:03 stale[bot]

what are the reasons that people want to participate?

Plus learn new stuff during the assessment.

I think one question we want to answer do we consider the assessments as a learning opportunity too?

There is an old issue I created before https://github.com/cncf/sig-security/issues/256 about the need for a lower entry-level position in the assessments which will allow an inexperienced developer to learn during security assessments and eventually volunteer for security reviewers.

I added a new comment about why I think this would be useful here: https://github.com/cncf/sig-security/issues/256#issue-484537322

MVrachev avatar Mar 19 '21 16:03 MVrachev

This issue has been automatically marked as inactive because it has not had recent activity.

stale[bot] avatar May 19 '21 02:05 stale[bot]

I've talked to @lumjjb before, and I'll submit a PR this week with the suggestions I've mentioned previously on this issue. Then, once they are accepted, we can close this one. Thanks!

magnologan avatar May 23 '21 15:05 magnologan

Hey @magnologan ! How is this going? Any way that we can help out with this?

lumjjb avatar Jun 09 '21 16:06 lumjjb

Hi @lumjjb sorry, I missed this, since the isn't assigned to me I forgot to follow up here. I'll submit a PR this week with the suggestions above. Do you mind assigning this to me just to make sure I don't forget? Thank you!

magnologan avatar Jun 16 '21 15:06 magnologan

Ok - assigned now :). Looking forward to the PR!

lumjjb avatar Jun 20 '21 13:06 lumjjb

Checking back on this @magnologan

lumjjb avatar Jun 28 '21 18:06 lumjjb

Adding myself to the project of turning Magno’s contributions here into a PR for the repo

apmarshall avatar Jul 28 '21 17:07 apmarshall

This is definitely something I can help with, I've also been working on a few (scrappy) tools that make threat modelling and security reviews code driven, git friendly and a bit more accessible. Will share more if there's interest.

hyakuhei avatar Aug 04 '21 17:08 hyakuhei

Hi @hyakuhei , @apmarshall !

Just checking back on this!

lumjjb avatar Sep 15 '21 13:09 lumjjb

Still happy to help but a bit unclear on what the engagement model is; how do we arrange and conduct a review?

hyakuhei avatar Sep 15 '21 17:09 hyakuhei

This issue has been automatically marked as inactive because it has not had recent activity.

stale[bot] avatar Nov 15 '21 16:11 stale[bot]

The security facilitator role helps with the tasks outlined in this issue.

ashutosh-narkar avatar Nov 15 '21 19:11 ashutosh-narkar

This issue has been automatically marked as inactive because it has not had recent activity.

stale[bot] avatar Jan 15 '22 01:01 stale[bot]

Closing this out -- the onus of convocating reviewers lies on the tag leadership and the assessments facilitator.

anvega avatar Jun 20 '23 03:06 anvega