SONiC icon indicating copy to clipboard operation
SONiC copied to clipboard

Security Vulnerability Management Process for SONiC Community

Open zhangyanzhao opened this issue 1 year ago • 4 comments

This document outlines SONiC vulnerability reporting and management process.

zhangyanzhao avatar Apr 02 '24 21:04 zhangyanzhao

TSC members, can you please help to review and approve this PR? Thanks.

zhangyanzhao avatar Apr 02 '24 21:04 zhangyanzhao

Looks good to me.

eddieruan-alibaba avatar Apr 02 '24 23:04 eddieruan-alibaba

Is there a template to report SONiC security issues? Regarding security issues - do we want all security issues dealt with within 90 days? Critical item (CVSS > 9.0) might require a more immediate response if the item is highly critical and highly visible.

Yarden-Z avatar Apr 03 '24 08:04 Yarden-Z

Is there a template to report SONiC security issues? Regarding security issues - do we want all security issues dealt with within 90 days? Critical item (CVSS > 9.0) might require a more immediate response if the item is highly critical and highly visible.

Security template will be defined later by security committee. The 90 days is the duration from date when mitigation is identified to vul expose date, overall, we expect the reported issues to be mitigated as soon as possible.

zhangyanzhao avatar Apr 09 '24 15:04 zhangyanzhao

Is there a template to report SONiC security issues? Regarding security issues - do we want all security issues dealt with within 90 days? Critical item (CVSS > 9.0) might require a more immediate response if the item is highly critical and highly visible.

Security committee can define a template if they want. The 90 days is the longest waiting time from when a mitigation/fix is ready, we expect the vulnerability is mitigated as soon as possible.

zhangyanzhao avatar May 15 '24 05:05 zhangyanzhao

@adyeung @balajib-cisco @eddieruan-alibaba can you please help to approve this PR if you are ok with the updated content? Thanks.

zhangyanzhao avatar May 15 '24 05:05 zhangyanzhao