-
Notifications
You must be signed in to change notification settings - Fork 2
Description
While the Overview and Background sections help establish the core features of the project, the Goals section should describe what the project intends to accomplish. This includes both the end user value and the security goals for the project.
Here’s an easy way to get started considering what your security goals might be. Think about areas where your software will do any of the following:
Touch the internet
Receive untrusted input
Handle sensitive data
In all likelihood, your list of goals will be much larger than the following example. Consider using a list or H4 headings to segment points as needed (we provide an example in the Non-goals section, if you want to skip ahead to see that).
### Goals
The Privateer project intends to create an ecosystem of post-deployment validation tools that can be easily incorporated into any automation pipeline.
In order to mitigate the risk of compromised open source dependencies, Privateer ensures that sensitive information stored within a configuration may be fully isolated between plugins ("Raids") when multiple implementations are executed simultaneously.Note
This can be drafted in google drive before being moved into the assessment markdown doc