[Openstack-security] Where do we stand on formal process for classifying the severity of security bugs?

Sriram Subramanian sriram at sriramhere.com
Mon Aug 25 16:11:48 UTC 2014


thanks Thierry. That's my recollection too. Thanks!


On Mon, Aug 25, 2014 at 11:03 AM, Thierry Carrez <thierry at openstack.org>
wrote:

> Sriram Subramanian wrote:
> > I am at the OpenStack Ops Midcyle Meetup in San Antonio and asked to
> > moderate the Security session here (like how Bryan and I did in Atlanta).
> >
> > I am looking at feedback from Atlanta meetup and one of the feedback
> > from operators was regarding more clarity on the classification.
> >
> > I see some note saying "need to work on formal process'. What is our
> > current status on the same?
>
> Rob proposed something based on CVSS, but I've yet to see a process that
> we could include as part of the vulnerability management team processes.
>
> --
> Thierry Carrez (ttx)
>
> _______________________________________________
> Openstack-security mailing list
> Openstack-security at lists.openstack.org
> http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-security
>



-- 
Thanks,
-Sriram
425-610-8465
www.sriramhere.com | www.clouddon.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openstack.org/pipermail/openstack-security/attachments/20140825/c7bb6b74/attachment.html>


More information about the Openstack-security mailing list