Security/FirefoxOperations: Difference between revisions

Jump to navigation Jump to search
No edit summary
Line 13: Line 13:
The table below summarizes the open issues assigned to the CloudSec team, sorted by area of focus.
The table below summarizes the open issues assigned to the CloudSec team, sorted by area of focus.


=== Operational Security ===
{| class="wikitable"
{| class="wikitable"
|- style="vertical-align:top;"
|- style="vertical-align:bottom;"
! style="height:100px; width:300px; text-align:center;" |
! style="height:100px; width:200px; text-align:center;" |
! style="height:100px; width:200px; text-align:center;" |
Continous Testing
Continuous Testing (TDS)
! style="height:100px; width:200px; text-align:center;" |
! style="height:100px; width:200px; text-align:center;" |
Fraud Detection
Fraud Detection
Line 24: Line 24:
! style="height:100px; width:200px; text-align:center;" |
! style="height:100px; width:200px; text-align:center;" |
Infra Hardening
Infra Hardening
! style="height:100px; width:200px; text-align:center;" |
Threat monitoring
|-
|-
! Operational security
| style="background-color: red;"|
| style="background-color: yellow;"|
[https://github.com/mozilla-services/cloudsec/issues?q=is%3Aopen+is%3Aissue+label%3A&quot;1.1+TDS&quot; '''3 HIGH'''<br />'''2 MEDIUM'''<br />'''3 LOW'''<br />]
2 HIGH<br />2 MEDIUM<br />2 LOW<br />
| style="background-color: red;"|
[https://github.com/mozilla-services/cloudsec/issues?q=is%3Aopen+is%3Aissue+label%3A&quot;1.2+fraud+detection&quot; '''3 HIGH'''<br />'''1 MEDIUM'''<br />]
| style="background-color: green;"|
[https://github.com/mozilla-services/cloudsec/issues?q=is%3Aopen+is%3Aissue+label%3A&quot;1.3+identity+management&quot; '''1 MEDIUM'''<br />'''1 LOW'''<br />]
| style="background-color: yellow;"|
| style="background-color: yellow;"|
2 HIGH<br />1 MEDIUM<br />
[https://github.com/mozilla-services/cloudsec/issues?q=is%3Aopen+is%3Aissue+label%3A&quot;1.4+infra+hardening&quot; '''4 MEDIUM'''<br />'''3 LOW'''<br />]
| style="background-color: green;"|
| style="background-color: green;"|
1 MEDIUM<br />1 LOW<br />
[https://github.com/mozilla-services/cloudsec/issues?q=is%3Aopen+is%3Aissue+label%3A&quot;3.2+monitor+external+threats&quot; '''2 LOW'''<br />]
| style="background-color: yellow;"|
3 MEDIUM<br />3 LOW<br />  
|}
|}


=== Application Security ===
{| class="wikitable"
{| class="wikitable"
|- style="vertical-align:top;"
|- style="vertical-align:bottom;"
! style="height:100px; width:300px; text-align:center;" |
! style="height:100px; width:200px; text-align:center;" |
! style="height:100px; width:200px; text-align:center;" |
Risk & Security reviews
Risk & Security reviews
! style="height:100px; width:200px; text-align:center;" |
! style="height:100px; width:200px; text-align:center;" |
Test & Implement Baseline Security
Test & Implement Baseline Security
! style="height:100px; width:200px; text-align:center;" |
Data & Code Signing
! style="height:100px; width:200px; text-align:center;" |
! style="height:100px; width:200px; text-align:center;" |
Training & Communication
Training & Communication
! style="height:100px; width:200px; text-align:center;" |
! style="height:100px; width:200px; text-align:center;" |
Bug Bounty
Bug Bounty
! style="height:100px; width:200px; text-align:center;" |
External audits
|-
|-
! Application Security
| style="background-color: yellow;"|
| style="background-color: yellow;"|
2 HIGH<br />1 LOW<br />
[https://github.com/mozilla-services/cloudsec/issues?q=is%3Aopen+is%3Aissue+label%3A&quot;2.1+risk+assessment&quot; '''2 HIGH'''<br />'''1 LOW'''<br />]
| style="background-color: yellow;"|
| style="background-color: yellow;"|
1 HIGH<br />1 MEDIUM<br />
[https://github.com/mozilla-services/cloudsec/issues?q=is%3Aopen+is%3Aissue+label%3A&quot;2.2+appsec+baseline&quot; '''1 HIGH'''<br />'''1 MEDIUM'''<br />]
| style="background-color: yellow;"|
[https://github.com/mozilla-services/cloudsec/issues?q=is%3Aopen+is%3Aissue+label%3A&quot;3.1+signature&quot; '''1 HIGH'''<br />'''1 MEDIUM'''<br />'''1 LOW'''<br />]
| style="background-color: green;"|
| style="background-color: green;"|
1 HIGH<br />2 LOW<br />
[https://github.com/mozilla-services/cloudsec/issues?q=is%3Aopen+is%3Aissue+label%3A&quot;2.3+security+communication&quot; '''1 HIGH'''<br />'''2 LOW'''<br />]
| no pending task
| no pending task
|}
{| class="wikitable"
|- style="vertical-align:top;"
! style="height:100px; width:300px; text-align:center;" |
! style="height:100px; width:200px; text-align:center;" |
Data & Code Signing
! style="height:100px; width:200px; text-align:center;" |
Threat monitoring
! style="height:100px; width:200px; text-align:center;" |
External audits
|-
! Core security services
| style="background-color: yellow;"|
1 HIGH<br />1 MEDIUM<br />1 LOW<br />
| style="background-color: green;"|
2 LOW<br />
| style="background-color: green;"|
| style="background-color: green;"|
1 LOW<br />
[https://github.com/mozilla-services/cloudsec/issues?q=is%3Aopen+is%3Aissue+label%3A&quot;3.3+external+audits&quot; '''2 LOW'''<br />]
|}
|}


Confirmed users
529

edits

Navigation menu