Security/SOP/Security Preview: Difference between revisions
mNo edit summary |
mNo edit summary |
||
| Line 13: | Line 13: | ||
'''Work product this is not relevant for:''' |
'''Work product this is not relevant for:''' |
||
* Reviewing specific code repositories prior to deployment. That would a [[Security/SOP/Security_Readiness_Reviews|Security Readiness Review]] |
* Reviewing specific code repositories prior to deployment. That would be a [[Security/SOP/Security_Readiness_Reviews|Security Readiness Review]] |
||
* Access requests to [[Security/SOP/Access_to_Phabricator_Security_Issues|protected Phabricator tasks or NDA protected content]] |
* Access requests to [[Security/SOP/Access_to_Phabricator_Security_Issues|protected Phabricator tasks or NDA protected content]] |
||
| Line 26: | Line 26: | ||
# If your request is not on the schedule and you believe it should be, or if you have any questions about the Security Teams Concept Review process, please (contact the Security Team) as soon as possible. |
# If your request is not on the schedule and you believe it should be, or if you have any questions about the Security Teams Concept Review process, please (contact the Security Team) as soon as possible. |
||
Towards the conclusion of the |
Towards the conclusion of the concept review, the Security Team will work to ensure that you understand what sufficient controls should be in place to address specific threats based upon your architecture. The Security Team may also suggest additional ways to reduce the attack surface for your initiative. |
||
==Expectations== |
==Expectations== |
||
Revision as of 19:15, 7 January 2020
Review Required by: 7th January 2021
Purpose
When considering a new initiative you can consult with the Security Team during the conceptual/planning phase. Although concept reviews are optional, performing one allows issues to be identified early in the lifecycle of an initiative.
Work product this may be relevant for:
- A team wants to use AWS Mechanical Turk and desires the Security Team's input on the plan
- A team needs wants to use a third party products key management solution and needs assistance understanding the implications for data leakage/confidentiality
- An extension is planned that would allow users to include <iframe>'s in wiki pages, to embed content from other sites. (We would surface this is inappropriate for Wikimedia as it leaks user IP addresses to a third parties in violation of our Privacy Policy.)
Work product this is not relevant for:
- Reviewing specific code repositories prior to deployment. That would be a Security Readiness Review
- Access requests to protected Phabricator tasks or NDA protected content
If you are unsure it may be best to submit a general Request For Service
Process
- Create a Security Concept Review request within Phabricator.
- Security Team members will triage requests weekly
- See the 'Incoming' #Security-Concept-Review workboard column for current requests in need of triage
- The “In Progress” column reflects all active Security Concept Reviews.
- If your request is not on the schedule and you believe it should be, or if you have any questions about the Security Teams Concept Review process, please (contact the Security Team) as soon as possible.
Towards the conclusion of the concept review, the Security Team will work to ensure that you understand what sufficient controls should be in place to address specific threats based upon your architecture. The Security Team may also suggest additional ways to reduce the attack surface for your initiative.
Expectations
Required Information (The task template prompts for all this)
- Name of project:
- Project home page:
- Name of team which owns the project:
- Primary contact for the project:
- Target date for deployment:
- Link to code repository:
- Is this a brand-new project:
- Has this project ever been reviewed before: (Phab tasks, etc.)
- Has any risk assessment (STRIDE, etc.) been performed:
- Is there an existing RFC or has this been presented to the community:
- Is this project tied to a team quarterly goal:
- Does this project require its own privacy policy:
- Description of the project and how it will be used
- Topology or flow diagrams outlining data flow
- Description of any sensitive data to be collected or exposed
- Technologies employed
- Dependencies and vendor code
- Working test environment (if one exists already)
If your project is not on the schedule and you believe it should be, or if you have any questions about the Security Teams Readiness Review process, please (contact the Security Team) as soon as possible.
References
- Directive terms capitalized requirement level terms: https://www.ietf.org/rfc/rfc2119.txt
- Definitions
Notes