-
Notifications
You must be signed in to change notification settings - Fork 2
Description
CISO has asked us to nail down this part of the process a bit.
Related (possible duplicate)
Acceptance criteria
A formal core committer policy is drafted and covers what action core committer are allowed to perform.use existing documentation per discussion in comments below- Core committers are required to attest that they have read the policy and agreed to it.
- Core committers are required to re-read the policy on a regular basis.
- The access to the security repo process is folded back into this policy.
- Policy is short enough not to dissuade core committers from reading.
- CISO is satisfied that the policy meet our ISO27K obligations.
- Silverstripe has a defined process for recording and storing proof that core committers have read the policy.
Notes
- We'll have a chat with the core committers about having a formal policy for removing people off if they haven't done something in a while.
Draft policy
This is no longer in consideration.
https://docs.google.com/document/d/1aywYhAxj6k6X3G3xuMf7wFWYq6jSftgsjDGEmWOmvTo/edit
This is a draft policy for Core Committers - that word "draft" is important, it's by no means official at this stage.
Please read through it and suggest any changes you think are appropriate (more detail, additional sections, ask for clarification, etc).
My primary concern while writing this has been the principle of least privilege - not giving admin access to everyone when nobody is really using it, but still keeping access to the wealth of knowledge of the core committers and doing what we can to ensure the community at large has some amount of say in the future of Silverstripe CMS
PRs
The current thinking is that once a year, Core Committers should submit a PR updating the below and update the date by their name, indicating that they have read the linked pages.
The product owner will be responsible for sending an annual reminder.