Skip to content

EPIC: Security Management Plan ML2 #441

@masc2023

Description

@masc2023
  • Are all Tool Requirements and Dependencies addressed?
  • Is the content from PMP and Process area checked and properly aligned?
  • Are the standard requirements, work products complete, correct linked?
  • Is the documentation header complete, correct linked?
  • Is the naming of the document correct?
  • Is the tailoring correct?

Security Plan: https://eclipse-score.github.io/score/main/platform_management_plan/index.html
Security Management Plan: https://eclipse-score.github.io/score/main/platform_management_plan/security_management.html

As Guidance compare Safety Management Plan

Sub-issues to be discussed and planned:
General: Add security relevant topics to any plan, if required
Add secure coding guidelines for Cpp and Rust
Automated Code scanning: Tools?
SBOM Generation: Tools?, including result of open source scans
Check SCA Tools and apply additional rules for security purposes
Fuzz Testing, etc. enhance Verification Plan, Software Development Plan
Apply the method defined for Security Analysis on every level
Enhance Release Plan, if applicable, etc.

Apply the roles defined on platform, feature, module/component level
Define and roll-out Security Management Plan

Sub-issues

Metadata

Metadata

Assignees

Labels

documentationImprovements or additions to documentation

Type

Projects

Status

In Progress

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions