Git Product home page Git Product logo

flexion-sig-security's People

Contributors

tdonaworth avatar tohch4 avatar

Stargazers

 avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

flexion-sig-security's Issues

Automate Onboarding of Flexion Staff into Security SIG

As a Flexion engineer, to indulge my curiosity and desire to spend more time listening to the cool security-minded folk, I want some way to have other members of the SIG request access on behalf of newcomers so they do not have to wait for @tohch4 or other busy individuals.

Security Lightning Talks

As a Flexion staff member, in order to benefits from experiences and interests of my peers, I would like to begin a 5-minute lightning talk series for guild meetings. I would like a way to see past talks, and upvote potential future talks.

Draft Recommendations for Securing SaaS CI/CD Platforms

As a Flexion engineer, in order to be confident in the sanity and safety of my build artifacts and related data, I would like guidance on how to properly configure SaaS CI/CD platforms, including, but not exclusively limited to:

  • Github Actions
  • CircleCI
  • Travis

Vulnerability Management Plans

Hypothesis: Flexion teams would benefit from a written Vulnerability Management Plan to out like the vulnerability management policy for each team and the standard operating procedure for dealing with findings from each type of security scanner in use by the team.

Security Engineering Knowledgebase

As a QPP engineer, in order to collaborate with teams across boundaries of customers and their projects, I would like a Flexion Security Knowledge base be created for common approaches to security design, practice, and implementation. That why I do not have to rediscover it myself!

Threat Modeling Guidance

As a Flexioneer, in order to best understand techniques for assessing my project's security posture, I want to know how to create a new, minimal threat model, using the Flexion threat model template(s), understanding the terminology and how to complete it accurately.

(Thanks to @csykora-flexion for asking questions about the threat model template he is using for one project and convincing me to solicit the guild for feedback about this.)

Guidance on Auditing Source Code Repositories for Secrets

As a Flexion engineer, to increase my confidence in safely collaborating with other contributors, I want guidance on specific tools and techniques security engineers use to examine a source code repository for erroneously-committed application secrets.

Update Playbooks to Provide Onboarding Guidance

As a Flexion security engineer, in order to assist new employees, we should provide some quick summary information on recommended configuration of Flexion workstations to make following company policy easier and more consistent.

Flexion Security Playbook

As a Flexion employee, to clarify ambiguity in and help prioritize overall security efforts for my project (new or ongoing), I would like a playbook to help me level set, start new security efforts, enhance important ones, and stop bad security practices.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.