1 of 13

CNCF Security SIG�Status: 21 May 2019

Sarah Allen & Jeyappragash JJ • 21.05.2019�Tuesday, May 21 • 15:55 - 16:30

2 of 13

Overview

Focus areas

  • Protection of cloud native* systems, �while providing needed access
  • Common understanding and common tooling to help developers meet security requirements
  • Common tooling for audit and reasoning about system properties.

* cloud native adj.

heterogeneous, distributed and fast changing systems

3 of 13

Overview

Focus areas

  • Protection of cloud native* systems, �while providing needed access
  • Common understanding and common tooling to help developers meet security requirements
  • Common tooling for audit and reasoning about system properties.

* cloud native adj.

heterogeneous, distributed and fast changing systems

4 of 13

Dec 2017

Started socializing at Kubecon Austin

13 Mar 2018

Initial Commit for SAFE repo

21 Aug 2018

Policy WG merged with SAFE�

15 Apr 2019

PR created for �CNCF consideration

7 May 2019

Rename to �CNCF SIG-Security

10 Aug 2018

Updated Charter and Governance

5 of 13

6 of 13

Landscape

What got done

CNCF Landscape review

Categories drafted

Approach to mapping to categories identified

567 open source projects

40 security-related

Progress

7 of 13

Landscape

What got done

CNCF Landscape review

Categories drafted

Approach to mapping to categories identified

Things to do

Validate categories & approach

Map existing projects to categories

Want to help? ⇒ issue#124

Progress

8 of 13

Security Assessments

What got done

Initial Guidelines PR#125

Issue Template

Wed, May 22�14:00 - 14:35�Inside CNCF Project �Security Reviews sched.co/MPdf

Progress

9 of 13

Security Assessments

What got done

Initial Guidelines PR#125

Issue Template

In Progress

In-toto

�OPA

🤔@SantiagoTorres�Santiago Torres-Arias

🤔@ashutosh-narkar�Ash Narkar

Wed, May 22�14:00 - 14:35�Inside CNCF Project �Security Reviews sched.co/MPdf

Progress

10 of 13

Security Assessments

What got done

Initial Guidelines PR#125

Issue Template

In Progress

In-toto

�OPA

Next steps

Expand the security review team…

Want to help? ⇒ shout out� on mailing list or slack!

🤔@SantiagoTorres�Santiago Torres-Arias

security review team

🕵️‍♀️ @JustinCappos�Justin Cappos

🕵️‍♀️ @ultrasaurus�Sarah Allen

🕵️‍♀️ @lumjjb�Brendan Lum

🕵️‍♀️@justincormack Justin Cormack

🤔@ashutosh-narkar�Ash Narkar

Wed, May 22�14:00 - 14:35�Inside CNCF Project �Security Reviews sched.co/MPdf

Progress

11 of 13

Coming up...

12 of 13

2019 Roadmap

  • Security overview �White paper - issue#138
  • Policy white paper�
  • Security assessments�First 5 - issue#167
    • in-toto
    • OPA
    • Falco
    • Keycloak
    • TBD

13 of 13

learn more…

Wed, May 22�

11:05 - 11:40

Deep Dive: CNCF Security SIG � Justin Cappos, NYUZhipeng Huang, Huawei

sched.co/Oscd

14:00 - 14:35�Inside CNCF Project Security Reviews Justin Cormack, Docker� Justin Cappos, NYU� sched.co/MPdf

github.com/cncf/sig-security