Skip to content

Commit 85f5243

Browse files
authored
Update annual-report-2022.md
1 parent ad1bca2 commit 85f5243

File tree

1 file changed

+13
-9
lines changed

1 file changed

+13
-9
lines changed

wg-policy/annual-report-2022.md

Lines changed: 13 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -5,27 +5,31 @@
55
1. What work did the WG do this year that should be highlighted?
66
For example, artifacts, reports, white papers produced this year.
77

8-
-
9-
-
8+
- [Policy Whitepaper]()
9+
- [PolicyReport CRD]() Adapters, [list here]()
10+
- [Review of whether to KEP or not to KEP for Policy Report]()
1011
-
1112

1213
2. What initiatives are you working on that aren't being tracked in KEPs?
1314

14-
-
15-
-
16-
-
15+
- The main topic of discussion is now whether to KEP the PolicyReport, or just keep it in a sig (e.g. sig-auth)
16+
- Outside of that there has been a lot of community interest, and workgroup effort spent, on control mapping
17+
and control-as-code implementation, eg OSCAL, that might be better served moved into its own workgroup or a
18+
sandbox project
1719

1820
## Project health
1921

2022
1. What's the current roadmap until completion of the working group?
2123

22-
-
23-
-
24-
-
24+
- We intend to wrap up the workgroup once the KEP for PolicyReport is created OR sig-auth or another sig accepts it
25+
- Or if neither occurs
26+
- There is considerable interest in continuing the governance and assessment and lifecycle of policy and controls,
27+
however as these necessarily cross boundaries, it seems like something that should either be re-homed to sig-security,
28+
and/or hosted in a CNCF-level workgroup and/or moved into a relevant sandbox CNCF project, eg. [SLEDGEHammer]().
2529

2630
2. Does the group have contributors from multiple companies/affiliations?
2731

28-
-
32+
- Yes, RedHat, IBM, SunStone Secure, Nirmata, Google, ...
2933

3034
3. Are there ways end users/companies can contribute that they currently are not?
3135
If one of those ways is more full time support, what would they work on and why?

0 commit comments

Comments
 (0)