Skip to content

Threat model an abstract enterprise supply chain #9

Description

@jonmuk

Create an enterprise architecture and accompanying threat model to identify the threats that we need to address as part of the "sterling toolchain" and validate existing standards.

High level goals include:

  • Define a high level architecture for an enterprise (NOTE: during initial meetings we were unable to identify participants to define a small or medium sized business)
  • Identify and describe threats to the confidentiality and integrity of proprietary software components produced with software development processes and infrastructures within architecture
  • Identify where existing OSSF standards and projects would align to mitigate the identified threats

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    help wantedExtra attention is needed

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions