Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Programmatic Help with Standardization #337

Open
hepwori opened this issue May 28, 2024 · 1 comment
Open

Programmatic Help with Standardization #337

hepwori opened this issue May 28, 2024 · 1 comment
Labels
Content Updates/additions to TAC content/process. Must include a changelog entry. Needs 3 approvals. documentation Improvements or additions to documentation enhancement New feature or request

Comments

@hepwori
Copy link

hepwori commented May 28, 2024

A number of WGs have interest in formal standardization efforts.

One good example reviewed in this the TAC call earlier today was S2C2F:

  1. S2C2F is working with LF's OpenChain on alignment within ISO 18974.
  2. S2C2F itself would like to become an ISO standard, and is starting to engage LF's JDF (https://jointdevelopment.org/) to work through the PAS process.

De jure standardization is complex, nuanced, political, specialized, and time consuming. Rather than requiring each WG, and OpenSSF collaborators in general, to become familiar with operating ISO's machinery — the TAC might instead explore setting up some kind of advisory or consultative center of expertise for WGs to leverage.

As a WG chair I'd love to be able to be able to lean on such a group to navigate the process end to end. In this model, SCI WG would bring supply chain expertise, the standards task force would bring standardization expertise, and between us we'd land some supply chain standards.

@SecurityCRob SecurityCRob added documentation Improvements or additions to documentation enhancement New feature or request Content Updates/additions to TAC content/process. Must include a changelog entry. Needs 3 approvals. labels Jun 5, 2024
@sevansdell
Copy link
Contributor

sevansdell commented Jun 6, 2024

Standards get used by regulators to drive change. Relationships with public policy teams and regulators to drive better security through standards is part of the OpenSSF Mission, Vision, Values https://openssf.org/about/ in the Strategy section: "Advocacy and policy: Advocate for policies and practices that promote OSS security, working with governments, industry bodies, and other relevant organizations." In our last TAC meeting, I recall hearing the GM articulate that S2C2F becoming a standard could help with the implementation of the Cyber Resiliency Act (CRA).

My question is if all WG could leverage the LF JDF, and when one-time technical writing needs come up during that process, do individual TI funding requests? Perhaps TAC could take the action item to document that process out on our github as a value for Incubating and Graduated projects?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Content Updates/additions to TAC content/process. Must include a changelog entry. Needs 3 approvals. documentation Improvements or additions to documentation enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

4 participants
@hepwori @SecurityCRob @sevansdell and others