Split OSPS-VM-01.01 into two requirements - #555
Satarupa22-SD wants to merge 3 commits into
Conversation
Signed-off-by: Satarupa22-SD <satarupa2212@gmail.com>
funnelfiasco
left a comment
There was a problem hiding this comment.
I don't think this is a case of needing to retire a control and introduce a new one. Ultimately, we're still asking for the same result. The timeframe for response is one required element of the CVD policy
| Retired in https://github.com/ossf/security-baseline/pull/555 | ||
| applicability: | ||
| - maturity-2 | ||
| - maturity-3 | ||
| state: Retired | ||
| - id: OSPS-VM-01.02 | ||
| text: | | ||
| The project documentation MUST include a coordinated | ||
| vulnerability disclosure (CVD) policy. |
There was a problem hiding this comment.
I can get behind Ben's idea here... We are loosening this slightly, but not changing the meaning. Adding strictness or changing meaning would demand a retirement.
| Retired in https://github.com/ossf/security-baseline/pull/555 | |
| applicability: | |
| - maturity-2 | |
| - maturity-3 | |
| state: Retired | |
| - id: OSPS-VM-01.02 | |
| text: | | |
| The project documentation MUST include a coordinated | |
| vulnerability disclosure (CVD) policy. | |
| The project documentation MUST include a coordinated | |
| vulnerability disclosure (CVD) policy. |
There was a problem hiding this comment.
In that case, should i just update the existing control instead of splitting this?
There was a problem hiding this comment.
Yeah, I think so. The text should just say "have a policy" and we can include the desired elements in the description.
evankanderson
left a comment
There was a problem hiding this comment.
I'm with Ben here -- I think this is one check, rather than "is there a policy" and "does the policy contain certain content". More granularity and more checks is not necessarily better, even if we have a few checks which are too big.
Signed-off-by: Satarupa22-SD <satarupa2212@gmail.com>
refer #546