-
Notifications
You must be signed in to change notification settings - Fork 293
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Create SECURITY.md #1278
base: main
Are you sure you want to change the base?
Create SECURITY.md #1278
Conversation
Hello. I guess that the people here are all newbies to ISO/IEC 27001. I guess you refer to the 2022 version. What is "8.28"? What means "Supported"? Reporting a vulnerability is the same as reporting anything, could you propose a more complete text? Could you provide a guide about what ISO/IEC 27001 2022 requires from a software? (Web site or book). Thank you. |
Hello, In this case, that means that if we introduce Security.md, there will be an overview of all fixed vulnerabilities |
Before proposing anything, we need some reference documentation about the exact requirements defined in ISO/IEC 27001. The access to these standards is not free if I understand well. Here's an excerpt from the book "ISO 27001 Controls: A Guide to Implementing and Auditing", Second Edition, Publisher: IT Governance © 2024, By: Bridget Kenyon, I can't paste all due to the Copyright, but I can see in the book that if we want to support ISO/IEC 27001, it's not only providing a point of contact and a list of vulnerability fixes, but also a whole security process to adopt, and should be audited to be compliant with ISO/IEC 27001 too:
I don't know ISO/IEC 27001, but maybe for now we can add the document you propose, and we'll see next if you need other compliance stuff. |
Also adding here what ChatGPT says about "what are the detailed guidelines for third-party components indicated in the control 8.25 of ISO/IEC 27002:2022":
|
so because of these two points we need the security.md Security issues can be checked and made available via these points. In addition to the watch security alerts |
hello,
it is important for our or other company that we have a list of safety related issues. this is required for iso 27001 8.28