|
14 | 14 | ## About this Document |
15 | 15 | [//]: # (BEGIN about) |
16 | 16 | This document describes the cybersecurity policy for the core of the open source |
17 | | -learning management system ILIAS. The document provides information on how security |
18 | | -issues and incidents should be reported and how they are handled by the responsible |
19 | | -team, the ILIAS Security Group. |
| 17 | +learning management system ILIAS. |
20 | 18 |
|
21 | | -This document is not a guideline on how to set up and operate an ILIAS installation |
| 19 | +* This policy is to foster the development of a secure product. |
| 20 | +* It outlines how vulnerabilities should be handled by developers. |
| 21 | +* This policy outlines how security issues and incidents should be reported effectively and |
| 22 | +how they are handled by the responsible team, the ILIAS Security Group. |
| 23 | +* It includes aspects of documenting, adressing and remediating vulnerabilities and promotes |
| 24 | +the sharing of information concerning vulnerabilities |
| 25 | + |
| 26 | +This document is NOT a guideline on how to set up and operate an ILIAS installation |
| 27 | +securely. |
| 28 | + |
| 29 | +This document is NOT a guideline on how to set up and operate an ILIAS installation |
22 | 30 | securely. Such instructions can be found in [docs/configuration/secure.md](../configuration/secure.md). |
23 | 31 |
|
24 | 32 | [//]: # (END about) |
@@ -66,10 +74,10 @@ to everyone (full disclosure about one week after the new release is published). |
66 | 74 | You will receive an automatic e-mail as confirmation of this. |
67 | 75 | 3. In the next step, the ILIAS Security Group will assign an issue manager. |
68 | 76 | 4. The issue manager will look into the issue and try to reproduce the problem. |
69 | | -5. In accordance with the CRA's guidelines, the issue manager gives an early warning |
70 | | -about an actively exploited vulnerability and/or severe incident to ENISA's single |
71 | | -reporting platform within 24 hours of becoming aware of it. |
72 | | -6. In case of questions, the issue manager will contact you on behalf of the ILIAS |
| 77 | +5. In case of an actively exploited vulnerability and/or severe incident, the issue |
| 78 | +manager gives an early warning to ENISA's single reporting platform within 24 hours |
| 79 | +of becoming aware of it as required by the CRA regulations. |
| 80 | +7. In case of questions, the issue manager will contact you on behalf of the ILIAS |
73 | 81 | association by email. We are grateful for any further help/information you can |
74 | 82 | provide during the analysis and bugfixing process. |
75 | 83 |
|
@@ -98,15 +106,14 @@ possible. |
98 | 106 | provides general information and an initial assessment to ENISA. |
99 | 107 | 4. Depending on the severity and impact of the reported and fixed issues, the |
100 | 108 | ILIAS release manager will build a new release or continue with the default roadmap. |
101 | | -5. In case of a vulnerability that has been reported to ENISA, the Security Group |
102 | | -provides a final report to ENISA no later than 14 days after the security bugfix |
103 | | -release has been made available. |
| 109 | +5. In case of an actively exploited vulnerability that has been reported to ENISA, |
| 110 | +the Security Group provides a final report to ENISA no later than 14 days after the |
| 111 | +security bugfix release has been made available. |
104 | 112 | 6. In case of a reported severe incident, the Security Group will provide a final report |
105 | 113 | to ENISA within one month after the severe incident notification. |
106 | 114 |
|
107 | 115 | [//]: # (END addressing) |
108 | 116 |
|
109 | | - |
110 | 117 | ## Process for Fixing Security Issues |
111 | 118 | [//]: # (BEGIN fixing) |
112 | 119 | The following process MUST be followed to hand in a fix for a security issue. These |
@@ -205,8 +212,8 @@ which provides more details on affected and fixed versions of ILIAS. |
205 | 212 | * Tim Bongers, CaT Concepts and Training GmbH, Cologne, Germany |
206 | 213 | * Alex Hartwig, Qualitus GmbH, Cologne, Germany |
207 | 214 | * Matthias Kunkel, ILIAS open source e-Learning e.V., Cologne, Germany |
208 | | -* André Schweigert, FAU Kompetenzzentrum Lehre, Fürth, Germany |
209 | 215 | * Lukas Scharmer, Databay AG, Würselen, Germany |
| 216 | +* André Schweigert, FAU Kompetenzzentrum Lehre, Fürth, Germany |
210 | 217 | * David Tokar, WEKA Media GmbH & Co. KG, Kissing, Germany |
211 | 218 | * Guido Vollbach, Databay AG, Würselen, Germany |
212 | 219 |
|
|
0 commit comments