Skip to content

Considerations for projects that dont fit modern repo management practices #23

@TheFoxAtWork

Description

@TheFoxAtWork

In Risk Management, we occasionally need to apply tailored controls or compensating mechanisms that achieve or partially meet the desired outcome. This could be the result of technical limitations, design, or other factors that impact or block security outcomes.

In the course of this group's work, should we consider development of guidance for adopters where projects, by design or technical limitation, cannot provide metadata to align with the metric? Should we guide projects on compensating mechanisms that offset risk their project may present to potential adopters?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions