Serverless

Reminder for tomorrow's call+Meeting Minutes 22nd September 2022

  • 1.  Reminder for tomorrow's call+Meeting Minutes 22nd September 2022

    Posted Oct 06, 2022 09:35:00 AM
    Edited by Marina Bregkou Oct 06, 2022 09:36:02 AM
    Dear members,

    Here are the main topics discussed at the latest Serverless WG call, followed by the action items.

    Previous action items:
    • All lead authors to review their respective control categories and wherever they mention Serverless in the implementations details column it should be changed to FaaS. In case the details mentioned are specific to Serverless then they should be made FaaS specific. - DONE
    • Joseph ( @Joseph Arcelo) to finalize: CM-6 to point at CM-2, CM-8 define system components, CM-9, CM-11, CM-13, CM-14. - DONE
    • Joseph ( @Joseph Arcelo) to review AC-5, AC-6 (1), (5), (9), and AC-14 from the Access Control category. - Pending.
    • Christopher ( @Christopher Wall) to finalize column G for the SC: System and Communications Protection control category. -DONE
    • Christopher ( @Christopher Wall) to fill in the FaaS Relevance of AC-16 in Access Control category, row 19. - DONE.
    • Christopher ( @Christopher Wall) to fill in column G for SC-3 (X) in row 136 and for SC-8 in row 141 and for SC-13( X), row 146, and SC- 16, SC-17 in row 149, 150 respectively. - DONE
    • Aradhna ( @Aradhna Chetal) to review and vote on the details of the SI: System and Information Integrity control category entered by Eric Peeters. - PENDING
    • Vrettos ( @Vrettos Moulos) to work on column I of the CA: Assessment, Authorization, and Monitoring control category. - PENDING
    • Reviewer needed for the AT: Awareness and Training control category. - PENDING
    • Shamik ( @Shamik Kacker) to review and vote on AU-3 and AU-3 (1) in rows 35, 36 respectively. - DONE
    • Vishwas ( @Vishwas Manral) to review and vote on column G of the CA: CA: Assessment, Authorization, and Monitoring control category filled in by Vrettos. - PENDING
    • Vishwas ( @Vishwas Manral) to fill in column G for SC-12 in row 145. - PENDING
    • Vrettos ( @Vrettos Moulos) to review column H of the CA: CA: Assessment, Authorization, and Monitoring control category filled in by Vishwas. - PENDING
    • Vani ( @Vani Murthy) to fill in column G and I for the IA-1 sub-control in row 89. - Half done/Half pending.
    • Crystal ( @Crystal Cuneo @Crystal Cuneo) to fill in columns G, H, I for sub-control RA-01, row 106. - PENDING
    Work on 'NIST implementation to FaaS' document is almost done. Now there is only the need for all authors to finalize their pending items and the document will be ready for peer review.

    Action items for next call:
    • Joseph @Joseph Arcelo) to review AC-5, AC-6 (1), (5), (9), and AC-14 from the Access Control category.
    • Aradhna ( @Aradhna Chetal) to review and vote on the details of the SI: System and Information Integrity control category entered by Eric Peeters
    • Vrettos ( @Vrettos Moulos) to work on column I of the CA: Assessment, Authorization, and Monitoring control category.
    • Reviewer needed for the AT: Awareness and Training control category.
    • Vishwas ( @Vishwas Manral) to review and vote on column G of the CA: CA: Assessment, Authorization, and Monitoring control category filled in by Vrettos.
    • Vishwas ( @Vishwas Manral) to help Christopher on SC-12, SC-13X and SC-17 implementation.
    • Vrettos ( @Vrettos Moulos) to review column H of the CA: CA: Assessment, Authorization, and Monitoring control category filled in by Vishwas.
    • Vani ( @Vani Murthy) to fill in column I for the IA-1 sub-control in row 89.
    • Crystal, or Rajiv ( @Rajiv Gunja) or Wayne ( @Wayne Anderson) to fill in columns G, H, I for sub-control RA-01, row 106.
    • Rajiv ( @Rajiv Gunja) to review and vote on CM-13 and CM 14, after Joseph's latest update.

    Our WG's next call is tomorrow, Friday, 7 October at 09:00 a.m. PST / 12:00 p.m. EST / 17:00 GMT / 18:00 CET.
    url: https://zoom.us/j/98681420926  (Meeting ID: 986 8142 0926).

    Kind regards,
    Marina




    ​​​​

    ------------------------------
    Marina Bregkou,
    Senior Research Analyst,
    CSA
    ------------------------------