Jump to: navigation, search

Difference between revisions of "Security Teams"

m (ThierryCarrez moved page SecurityTeams to Security Teams)
 
(5 intermediate revisions by 3 users not shown)
Line 1: Line 1:
 +
OpenStack historically had two security organizations - the Vulnerability Management Team (VMT) and the OpenStack Security Group (OSSG).
  
= [[OpenStack]] Security Teams =
+
These organizations have now combined under the [[Security|Security Project]]. The VMT continues to operate as a largely independent body for confidentially handling vulnerabilities but with stronger ties to the Security Project as a whole, which leads efforts to make OpenStack more secure through education, software tooling and security evangelism.
  
== [[OpenStack]] Vulnerability Management team (VMT) ==
+
==Security Project ==
 +
* [[Security|Security Project wiki page]]
 +
* https://launchpad.net/~openstack-ossg
 +
* http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-security
 +
* Security experts and auditors working on OpenStack security
 +
* Publishes OSSN (OpenStack Security Notes)
 +
* Advises on [[Security/OSSA-Metrics|Vulnerability Metrics]]
 +
 
 +
== Vulnerability Management team (VMT) ==
 
* https://launchpad.net/~openstack-vuln-mgmt
 
* https://launchpad.net/~openstack-vuln-mgmt
 
* Handles incoming vulnerability reports, following [[VulnerabilityManagement]]
 
* Handles incoming vulnerability reports, following [[VulnerabilityManagement]]
 
+
* Publishes OSSA (OpenStack Security Advisories)
== Nova security improvements team ==
 
* https://launchpad.net/~nova-security-improvements
 
* Open team working on security improvements for Nova
 

Latest revision as of 14:07, 24 September 2015

OpenStack historically had two security organizations - the Vulnerability Management Team (VMT) and the OpenStack Security Group (OSSG).

These organizations have now combined under the Security Project. The VMT continues to operate as a largely independent body for confidentially handling vulnerabilities but with stronger ties to the Security Project as a whole, which leads efforts to make OpenStack more secure through education, software tooling and security evangelism.

Security Project

Vulnerability Management team (VMT)