WebAppSec/Security Review Request: Difference between revisions
Jump to navigation
Jump to search
(Created page with '= Infrasec Security Review Request = #File a new bug within Bugzilla for the request. #Block an existing deployment request bug with the infrasec review bug.<br> #Assign the …') |
|||
| Line 3: | Line 3: | ||
#File a new bug within Bugzilla for the request. | #File a new bug within Bugzilla for the request. | ||
#Block an existing deployment request bug with the infrasec review bug.<br> | #Block an existing deployment request bug with the infrasec review bug.<br> | ||
#Assign the bug to '''Component: Mozilla.org''' and '''Product: | #Assign the bug to '''Component: Mozilla.org''' and '''Product: Infrastructure Security: Web Security''' | ||
#Make sure to copy clyon <at> mozilla.com and mcoates <at> mozilla.com | #Make sure to copy clyon <at> mozilla.com and mcoates <at> mozilla.com | ||
#Within the request, please answer the questions below | #Within the request, please answer the questions below | ||
Revision as of 16:56, 29 September 2010
Infrasec Security Review Request
- File a new bug within Bugzilla for the request.
- Block an existing deployment request bug with the infrasec review bug.
- Assign the bug to Component: Mozilla.org and Product: Infrastructure Security: Web Security
- Make sure to copy clyon <at> mozilla.com and mcoates <at> mozilla.com
- Within the request, please answer the questions below
Questions to Address within Request Body
Please copy these questions into the bug and answer inline.
- A quick intro to what this app does.
- Where is the source code located?
- Is there a stage server running that we can also test against? If so, please indicate what machine the web server is running on.
- Where would you like the bugs filed in bugzilla? Please specify the product, component and if anyone specific should be copied on the bugs.
- Please describe if this app will be connecting to any internal or external services or if it is able to interact with the OS.
- Does this app support logins or multiple roles? If so, we'll need test accounts created for each available role.
- What is the worst case scenario that could happen with this system, data or connected systems? (This is used to help understand the criticality of this server.)
- This review will be scheduled amongst other requested reviews. What is the urgency or needed completion date of this review?