Feature #15097

Risk analysis on our infrastructure

Added by groente 2017-12-23 12:03:11 . Updated 2019-08-09 15:22:51 .

Status:
Confirmed
Priority:
Normal
Assignee:
groente
Category:
Infrastructure
Target version:
Start date:
2017-12-23
Due date:
% Done:

0%

Feature Branch:
Type of work:
Sysadmin
Blueprint:

Starter:
Affected tool:
Deliverable for:

Description

Analyse the risks the project is facing and prioritise mitigations.
Loosely based on OCTAVE/Allegro, this would involve:

  • identifying assets and their criteria (confidentiality/availability/integrity)
  • establishing threat trees
  • calculate risks as the product of probability and impact of threat scenario’s
  • identify possible mitigations and their cost
  • prioritise mitigations as a function of risk-reduction and cost

Subtasks


Related issues

Blocks Tails - Feature #13284: Core work: Sysadmin (Adapt our infrastructure) Confirmed 2017-06-30
Blocked by Tails - Feature #15096: Create high level documentation for our infrastructure Confirmed 2017-12-23
Blocks Tails - Feature #9802: Design a process to deal with signing key compromise Confirmed 2015-07-24
Blocks Tails - Bug #16956: Make our infrastructure more redundant Confirmed

History

#1 Updated by groente 2017-12-23 12:37:29

Note that this is a public issue!

Discussing this issue can easily entail sensitive information, please ensure you use the appropriate communication channels.

#2 Updated by emmapeel 2017-12-23 16:19:38

  • Status changed from New to Confirmed

#3 Updated by intrigeri 2018-04-08 13:09:49

  • blocks Feature #13284: Core work: Sysadmin (Adapt our infrastructure) added

#4 Updated by intrigeri 2018-04-08 13:10:29

  • Subject changed from Risk analysis to Risk analysis on our infrastructure
  • Description updated

#5 Updated by intrigeri 2018-04-08 13:11:01

  • blocked by Feature #15096: Create high level documentation for our infrastructure added

#6 Updated by CyrilBrulebois 2018-12-16 14:07:03

  • Target version changed from Tails_3.11 to Tails_3.12

#7 Updated by anonym 2019-01-30 11:59:24

  • Target version changed from Tails_3.12 to Tails_3.13

#8 Updated by intrigeri 2019-03-07 15:30:51

  • blocks Feature #9802: Design a process to deal with signing key compromise added

#9 Updated by CyrilBrulebois 2019-03-20 14:34:09

  • Target version changed from Tails_3.13 to Tails_3.14

#10 Updated by CyrilBrulebois 2019-05-23 21:23:25

  • Target version changed from Tails_3.14 to Tails_3.15

#11 Updated by CyrilBrulebois 2019-07-10 10:34:04

  • Target version changed from Tails_3.15 to Tails_3.16

#12 Updated by intrigeri 2019-08-09 15:22:51

  • Target version deleted (Tails_3.16)

(As per today’s sysadmin team meeting.)

#13 Updated by intrigeri 2019-08-09 16:49:11

  • blocks Bug #16956: Make our infrastructure more redundant added