Skip to content

Conversation

@fubuloubu
Copy link
Contributor

Summary

Responding to @maurelian

We need a common model to use between auditors and developers in order to succinctly describe risk levels and agree on severity. This is often tied directly to decisions around whether the severity of an issue requires a change to the underlying code, or could be deferred without substantial impact to users. This is the old risk assessment model we had included prior, updates are probably required to complete the model and make it acceptable for use in audits.

@fubuloubu
Copy link
Contributor Author

Also need to see if we add links to development/managing-changes.md describing how risk assessment fits into the decision making process behind implementing changes.

Link to that article from audit revisions

@rpavlovs
Copy link
Member

rpavlovs commented Jan 4, 2019

Do we want to merge this and release as part of v0.2?

Copy link
Contributor

@RexShinka RexShinka left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants