Security/RiskRatings: Difference between revisions

Jump to navigation Jump to search
m (→‎Calculating Risk Ratings: fix tag closing order)
Line 65: Line 65:
|Review Type || Group (Scheduled on SecReview Calendar) || Group (Scheduled on SecReview Calendar) || Individual Reviewer || Individual Reviewer
|Review Type || Group (Scheduled on SecReview Calendar) || Group (Scheduled on SecReview Calendar) || Individual Reviewer || Individual Reviewer
|-
|-
|Required Documents from development team
|Artefacts Required  
|
{| border="1"
{| border="1"
|Architecture Diagram
|Architecture Diagram
Line 74: Line 75:
|-
|-
|Threat Model
|Threat Model
|-
|Testing Plan Required
|}
|}
|  
|
{| border="1"
{| border="1"
|Required at input
|Architecture Diagram
|-
|-
|Required at input
|Application Diagram,
|-
|-
|Required at input
|Data Flow Enumeration,
|-
|-
|Created During review with Security Lead
|Threat Model
|-
|Testing Plan Required
|}
|}
|
|
{| border="1"
{| border="1"
|Created during review
|Architecture Diagram attached to bug
|-
|-
|Created during review
|Testing Plan Required
|}
|
{| border="1"
|Architecture Diagram attached to bug if more than one system is involved.
|-
|-
|Created during review
|Testing Plan Required
|-
|Created during review 
|}
|}
|
None required,
but may speed review
|
None required,
but may speed review
|-
|-
| How Documented || SecReview Wiki || SecReview Wiki || SecReview Wiki -or- in Secreview bug (with indidication of no-wiki) || In SecReview Bug
| How Documented || SecReview Wiki || SecReview Wiki || SecReview Wiki -or- in Secreview bug (with indidication of no-wiki) || In SecReview Bug
Confirmed users
180

edits

Navigation menu