Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Considerations for projects that dont fit modern repo management practices #23

Open
TheFoxAtWork opened this issue Aug 6, 2024 · 2 comments

Comments

@TheFoxAtWork
Copy link
Contributor

In Risk Management, we occasionally need to apply tailored controls or compensating mechanisms that achieve or partially meet the desired outcome. This could be the result of technical limitations, design, or other factors that impact or block security outcomes.

In the course of this group's work, should we consider development of guidance for adopters where projects, by design or technical limitation, cannot provide metadata to align with the metric? Should we guide projects on compensating mechanisms that offset risk their project may present to potential adopters?

@eddie-knight
Copy link
Contributor

eddie-knight commented Feb 22, 2025

@TheFoxAtWork do you think we've managed this in the latest progress?

@TheFoxAtWork
Copy link
Contributor Author

Yes i believe we have and this can be closed. It may be worthwhile to add this to a "principles in continued development of the baselines". This would allows us to establish update guidance and capture fundamental points that allowed us to craft the baselines into what they've become. Similar to how we have guidance for updating whitepapers in CNCF, declaring the intent, reasoning, and elements not in scope with why.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants