Used for live incident reporting only. Reaches incident
response teams at all sites. Designated security contacts or alternates
only should post to this list for confirmed incidents. Must not
be used for discussion or follow up (see next list below). Subjects
must classify content as HIGH, MEDIUM or LOW impact.
Used for incident followup, discussion and informational alerts.
Reaches registered site security contacts for all sites. Designated
security contacts or alternates only should post to this list. Subject
should suggest classification i.e. INFORMATIONAL
Used for general GSVG discussion. Use the reporting list given
above to report vulnerabilities.
Operations
Reaches ROC security contacts of the OSCT - Operational Security
Coordination Team. Used for operational security issues including
security tickets from GGUS security
management unit and advisories from the GSVG
Operational Security Coordination Team internal discussion list.
The OSCT defines the implementation of operational security processes.
Manages
implementation
of operational
security policies as promoted by JSPG. Reaches ROC security contacts,
security activity sub-groups and volunteers.
The LCG/EGEE Project Security Officer works within the Grid Deployment
Group with responsibility for coordinating operational security
activities.
Middleware Security Group. The MSWG coordinates the capture and
definition of security requirements to the gLite development process.
The European Grid Policy Management
Authority controls the Certification Authorities issuing authentication
tokens trusted in the LCG/EGEE infrastructure. A list of CA
contact points is maintained here.