Skip to content

Commit cd5f4e2

Browse files
Merge pull request #1 from matthiaskunkel/matthiaskunkel-securitypolicy
Update security.md
2 parents fbf7ea6 + 3aef226 commit cd5f4e2

1 file changed

Lines changed: 20 additions & 13 deletions

File tree

docs/development/security.md

Lines changed: 20 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -14,11 +14,19 @@
1414
## About this Document
1515
[//]: # (BEGIN about)
1616
This document describes the cybersecurity policy for the core of the open source
17-
learning management system ILIAS. The document provides information on how security
18-
issues and incidents should be reported and how they are handled by the responsible
19-
team, the ILIAS Security Group.
17+
learning management system ILIAS.
2018

21-
This document is not a guideline on how to set up and operate an ILIAS installation
19+
* This policy is to foster the development of a secure product.
20+
* It outlines how vulnerabilities should be handled by developers.
21+
* This policy outlines how security issues and incidents should be reported effectively and
22+
how they are handled by the responsible team, the ILIAS Security Group.
23+
* It includes aspects of documenting, adressing and remediating vulnerabilities and promotes
24+
the sharing of information concerning vulnerabilities
25+
26+
This document is NOT a guideline on how to set up and operate an ILIAS installation
27+
securely.
28+
29+
This document is NOT a guideline on how to set up and operate an ILIAS installation
2230
securely. Such instructions can be found in [docs/configuration/secure.md](../configuration/secure.md).
2331

2432
[//]: # (END about)
@@ -66,10 +74,10 @@ to everyone (full disclosure about one week after the new release is published).
6674
You will receive an automatic e-mail as confirmation of this.
6775
3. In the next step, the ILIAS Security Group will assign an issue manager.
6876
4. The issue manager will look into the issue and try to reproduce the problem.
69-
5. In accordance with the CRA's guidelines, the issue manager gives an early warning
70-
about an actively exploited vulnerability and/or severe incident to ENISA's single
71-
reporting platform within 24 hours of becoming aware of it.
72-
6. In case of questions, the issue manager will contact you on behalf of the ILIAS
77+
5. In case of an actively exploited vulnerability and/or severe incident, the issue
78+
manager gives an early warning to ENISA's single reporting platform within 24 hours
79+
of becoming aware of it as required by the CRA regulations.
80+
7. In case of questions, the issue manager will contact you on behalf of the ILIAS
7381
association by email. We are grateful for any further help/information you can
7482
provide during the analysis and bugfixing process.
7583

@@ -98,15 +106,14 @@ possible.
98106
provides general information and an initial assessment to ENISA.
99107
4. Depending on the severity and impact of the reported and fixed issues, the
100108
ILIAS release manager will build a new release or continue with the default roadmap.
101-
5. In case of a vulnerability that has been reported to ENISA, the Security Group
102-
provides a final report to ENISA no later than 14 days after the security bugfix
103-
release has been made available.
109+
5. In case of an actively exploited vulnerability that has been reported to ENISA,
110+
the Security Group provides a final report to ENISA no later than 14 days after the
111+
security bugfix release has been made available.
104112
6. In case of a reported severe incident, the Security Group will provide a final report
105113
to ENISA within one month after the severe incident notification.
106114

107115
[//]: # (END addressing)
108116

109-
110117
## Process for Fixing Security Issues
111118
[//]: # (BEGIN fixing)
112119
The following process MUST be followed to hand in a fix for a security issue. These
@@ -205,8 +212,8 @@ which provides more details on affected and fixed versions of ILIAS.
205212
* Tim Bongers, CaT Concepts and Training GmbH, Cologne, Germany
206213
* Alex Hartwig, Qualitus GmbH, Cologne, Germany
207214
* Matthias Kunkel, ILIAS open source e-Learning e.V., Cologne, Germany
208-
* André Schweigert, FAU Kompetenzzentrum Lehre, Fürth, Germany
209215
* Lukas Scharmer, Databay AG, Würselen, Germany
216+
* André Schweigert, FAU Kompetenzzentrum Lehre, Fürth, Germany
210217
* David Tokar, WEKA Media GmbH & Co. KG, Kissing, Germany
211218
* Guido Vollbach, Databay AG, Würselen, Germany
212219

0 commit comments

Comments
 (0)