Hi, We have been reviewing the CII badging procedures and plan to make a proposal to the TSC regarding these (next week). Information can be found at:
* https://github.com/linuxfoundation/cii-best-practices-badge/blob/master/doc/criteria.md * https://github.com/linuxfoundation/cii-best-practices-badge/blob/master/doc/other.md There are 3 levels, basic, +1 (sliver) and +2 (gold). We felt that for critical infrastructure software, security will be of high importance hence the idea would be to aim for the (+2 gold) level. This badging process has aspects other than security, however as it addresses security and someone should consider it from an ONAP perspective, we thought that we would. In our proposal we expect to indicate to start with one project to develop the skills and competence and spread from there, but we thought that this should also relate to release where we would expect the ONAP projects producing code to obtain the +2(gold) badge. We'll request an information presentation from the subject experts on this. I would also like to remind you that we are looking for candidates for the vulnerability management team as well. Best Regards, Steve. [Ericsson]<http://www.ericsson.com/> STEPHEN TERRILL Technology Specialist DUIC, Systems and Technology Development Unit IP & Cloud Business Unit, IT & Cloud Products Ericsson Ericsson R&D Center, via de los Poblados 13 28033, Madrid, Spain Phone +34 339 3005 Mobile +34 609 168 515 [email protected] www.ericsson.com [http://www.ericsson.com/current_campaign]<http://www.ericsson.com/current_campaign> Legal entity: Ericsson EspaƱa S.A, compay registration number ESA288568603. This Communication is Confidential. We only send and receive email on the basis of the terms set out at www.ericsson.com/email_disclaimer<http://www.ericsson.com/email_disclaimer>
_______________________________________________ ONAP-TSC mailing list [email protected] https://lists.onap.org/mailman/listinfo/onap-tsc
