Security/Program Management: Difference between revisions

From MozillaWiki
Jump to navigation Jump to search
(Creating Security Program Management wiki page)
 
No edit summary
Line 28: Line 28:
** [[Security/Origin|Origin header]]
** [[Security/Origin|Origin header]]
* Drive implementation of security features, contributing to implementation where possible
* Drive implementation of security features, contributing to implementation where possible
== New product and feature tracking ==
* Track new products and new product features to ensure they are reviewed
* Manage internal and external testing schedules

Revision as of 23:57, 11 November 2009

This document describes the Security Program Management function at Mozilla. If you have questions, please contact Brandon Sterne, the Security Program Manager.

External Communications

  • Ensure responses are sent to inquiries made to security@mozilla.org
    • Researchers reporting vulnerabilities
    • Users reporting security problems with Mozilla products
  • Help Mozilla Press produce responses to security-related questions from the media

Security Metrics

  • Raise awareness within the organization of key product security metrics

Security Releases

  • Help release drivers triage bugs needed on the stable branches
  • Publish advisories for the security bugs fixed in each release
  • Support Release Drivers, QA, and Release Engineering teams during out-of-band "firedrill" releases

Secure Development Lifecycle

  • Develop material to increase awareness of and utilization of security best practices by Mozilla developers
  • Deliver security training sessions to developers and QA engineers

Security Feature Development

New product and feature tracking

  • Track new products and new product features to ensure they are reviewed
  • Manage internal and external testing schedules