Skip to content

Commit

Permalink
cybersecurity: add 20240216_Cybersecurity_MOM.md
Browse files Browse the repository at this point in the history
Signed-off-by: Eloi Bail <[email protected]>
  • Loading branch information
ebail committed Mar 14, 2024
1 parent 175915c commit 3c6a35d
Show file tree
Hide file tree
Showing 2 changed files with 44 additions and 0 deletions.
44 changes: 44 additions & 0 deletions Cybersecurity_Minutes/20240216_Cybersecurity_MOM.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@
# SEAPATH - Cybersecurity Meeting

* Date: 16th February 2024
* Attendees:
- Eloi Bail (Savoir-faire Linux)
- Florent Calvi (RTE)
- Justin Dides (Schneider)
- Jan Hille (Welotec)
- Adam Korczynski (Adalogics)
- Amir Montazery (Ostif)

# Agenda

- Cybersecurity auditing

## Discussion

- Cybersecurity auditing
- Presentation by Adam
- SEAPATH should cover IEC62443-4 only
- 62443-4-1: Secure product dev lifecycle requirements
1. Dev process:
- Note: Some work is done by LFEnergy (ex: usage of openssf)
- document that in the wiki
2. product security context
- thread model
3. Secure design principles
- design checking
4. Security implementation review
5. Securty verification and validation testing
6. Security disclosure
7. Security update Management

- SEPATH should cover 1) 2) 3) 4) 6) 7) and 5) be done by third-party (Ada Logics)
- 62443-4-2: Secure product dev lifecycle requirements
- Technical security requirements

- Adam will send requirements for most of the part and SEAPATH team will send documentations
- Eloi: check with LFEnergy team where we could store that
- How to communicate securely
- Eloi will check if we should publicly share the documents

# Next Meeting
- 01 March 2024 (might be moved)
Binary file not shown.

0 comments on commit 3c6a35d

Please sign in to comment.