Skip to Content.
Sympa Menu

cacert-policy - Modification of SP

Subject: Policy-Discussion

List archive

Modification of SP


Chronological Thread 
  • From: Philipp Dunkel <p.dunkel AT cacert.org>
  • To: cacert-policy AT lists.cacert.org
  • Subject: Modification of SP
  • Date: Wed, 31 Mar 2010 17:55:22 +0200
  • Authentication-results: lists.cacert.org; dkim=pass (1024-bit key) header.i= AT cacert.org; dkim-asp=none

Hi all,
you will have indubitably noticed the veto of the CAcert Inc. board of the Security Policy.

In order to remedy the situation I would like to propose the following change to the WIP Security Policy:

alter 9.1.4.2 to read:

  • 9.1.4.2. Coverage
  • A background check is to be done for all critical roles. The background check should be done on all of:
    • Systems Administrator
    • Access Engineers
    • Software Assessor (including Application Engineer)
    • Support Engineer
    • Boardmembers that wish to part-take in decisions on granting access to data or other sensitive resources
this little change would give CAcert Inc. Board Members a choice of either undergoing a background check like every other security sensitive position, or alternatively not part-taking in certain decisions made by CAcert Inc. Due to the fact that it is now up to each member individually, and the CAcert Inc. membership is now free to vote anyone they choose onto the CAcert Inc. Board, the reason given for the veto would be remedied.

I would like to get a discussion on this started and see whether we can remedy the Security Policy and move it back into DRAFT. So please all take part and be merry.

Regards, Philipp

Attachment: smime.p7s
Description: S/MIME cryptographic signature




Archive powered by MHonArc 2.6.16.

Top of Page