[Fiware-security] TR: Apps/Services review by security chapter

BISSON Pascal pascal.bisson at thalesgroup.com
Wed Jul 20 17:01:20 CEST 2011


Dear All,

I'm forwarding you this email related to the review (Daniel and I) performed of the WP3 Chapter as per request of WP2 Lead.

To be also briefly discussed at our next audio conf (this Friday so 22/07/2011 10am-12am)

Regards,

Pascal

De : BISSON Pascal
Envoyé : mardi 19 juillet 2011 18:47
À : Friesen, Andreas
Cc : GIDOIN Daniel; TRABELSI, Slim; Juanjo Hierro; Leidig, Torsten; BISSON Pascal; SIEUX Corinne; LELEU Philippe
Objet : RE: Apps/Services review by security chapter
Importance : Haute

Dear Andreas,

Find attached to this email our (Thales) review of the Apps chapter. This review was performed by me and my colleague Daniel (in cc)

In complement of the review comments and/or suggested changes in the text of the document I added hereafter some more general comments we came up with.


·         Apps chapter has seriously improved (especially compared to previous version we went through when identifying security issues from WP8 perspective). So congratulations to you and the team for the work you achieved here.

·         Relationship with Cloud hosting team is rightly stressed. In the meantime relationship with other teams could be better stressed. This is especially true for what concerns Security team. So apart from Security issues reported by WP8 and integrated in Question mark section I would suggest to add a question mark to address this and stress from the WP3 perspective  how they envision to interact with the Security and why. Also stress its urgency.

·         There are very few question marks apart from the ones on Security. So would suggest to consider to add some new more. Especially for what concerns interaction with other teams (Security but also IoT) although not uniquely. This just because the reader would expect more once reading this chapter ...

·         References to contributing projects and/or products identified by the team should be kept for M5 update of this deliverable as initially announced. This is also something that can differentiate M5 deliverable from M2 deliverable.

·         Section with (major)  references is missing. Would suggest to add one to make things comparable to other chapters.

Hope it helps you to finalize your work on this Chapter.

Once more apologize in me sending you with a small delay our review comments but it took more time than expected.

Best Regards,

Pascal

PS: I put Slim in cc of this email since Slim is together with us in charge of monitoring WP3 activities and as such was involved in the identification of the Security issues coming from WP3 and reported in the Question marks. Slim can also support you in addressing some of our review comments.



De : Friesen, Andreas [mailto:andreas.friesen at sap.com]
Envoyé : lundi 18 juillet 2011 11:24
À : BISSON Pascal
Cc : GIDOIN Daniel; TRABELSI, Slim; Juanjo Hierro; Leidig, Torsten
Objet : RE: Apps/Services review by security chapter

Dear Pascal,

thanks for the info. Please take the newest version from FusionForge. It has been significantly reworked after the review from Junjo.

Best regards,
Andreas

From: BISSON Pascal [mailto:pascal.bisson at thalesgroup.com]
Sent: Montag, 18. Juli 2011 10:52
To: Friesen, Andreas
Cc: GIDOIN Daniel; BISSON Pascal; TRABELSI, Slim; Juanjo Hierro
Subject: RE: Apps/Services review by security chapter
Importance: High

Dear Andreas,

Back to you on this.

Due the fact Daniel and I were busy with some other stuff (not only addressing comments we got on Security chapter but also checking question marks on security issues of each other chapter) we were unable to perform the review of your Chapter according to the set deadline. Furthermore our Thales site was closed on July 14th and July 15th which prevented us also to work on the topic those days.

But we are back to work and will provide you with our review of your Chapter asap (my target here is by EOB today).

Once more my apologize and will do my utmost to provide with our comments asap.


Best Regards,

Pascal

De : Friesen, Andreas [mailto:andreas.friesen at sap.com]
Envoyé : mercredi 13 juillet 2011 17:55
À : BISSON Pascal
Objet : Apps/Services review by security chapter

Dear Pascal,

when can we count with the review of our chapter?

Thanks
Andreas

Dr. Andreas Friesen
Research Program Manager Service Science
SAP Research Center Karlsruhe
SAP AG
Vincenz-Priessnitz-Strasse 1
76131 Karlsruhe, Germany
T   + 49 6227 752 586
F   + 49 6227 78-43567
M   +49 171 8674630
mailto:andreas.friesen at sap.com
http://www.sap.com

Pflichtangaben/Mandatory Disclosure Statements: http://www.sap.com/company/legal/impressum.epx
Diese E-Mail kann Betriebs- oder Geschäftsgeheimnisse oder sonstige vertrauliche Informationen enthalten. Sollten Sie diese E-Mail irrtümlich erhalten haben, ist Ihnen eine Kenntnisnahme des Inhalts, eine Vervielfältigung oder Weitergabe der E-Mail ausdrücklich untersagt. Bitte benachrichtigen Sie uns und vernichten Sie die empfangene E-Mail. Vielen Dank.
This e-mail may contain trade secrets or privileged, undisclosed, or otherwise confidential information. If you have received this e-mail in error, you are hereby notified that any review, copying, or distribution of it is strictly prohibited. Please inform us immediately and destroy the original transmittal. Thank you for your cooperation.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.fiware.org/private/old-fiware-security/attachments/20110720/d76531d7/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: FI-WARE High-Level Description - Apps chapter - v1 0 20 - valid until 11-07-16-THA_review.doc
Type: application/msword
Size: 1761280 bytes
Desc: FI-WARE High-Level Description - Apps chapter - v1 0 20 - valid until 11-07-16-THA_review.doc
URL: <https://lists.fiware.org/private/old-fiware-security/attachments/20110720/d76531d7/attachment.doc>


More information about the Old-Fiware-security mailing list

You can get more information about our cookies and privacy policies clicking on the following links: Privacy policy   Cookies policy