wiki: sync 2026-07-30 13:16 UTC — 5 file(s) updated
This commit is contained in:
@@ -22,12 +22,13 @@
|
||||
| ACT-14 | Organize scanning of AWS organization — spun up using DPVP, then scanned by Atea | 🔵 Active | 2026-07-27 |
|
||||
| ACT-15 | DPVP Platform Phase 2 opportunity — scope, prioritise, estimate, and define delivery/commercial approach | 🟡 Opportunity | 2026-07-29 |
|
||||
| ACT-16 | Make merge-request approvals mandatory in the staging environment | 🔵 Active | 2026-07-29 |
|
||||
| ACT-17 | Check with Atea about role assumption for TFE OIDC setup | 🔵 Active | 2026-07-30 |
|
||||
|
||||
## DPVP Platform — Phase 2 Opportunity
|
||||
|
||||
### Executive Summary
|
||||
|
||||
DPVP Phase 2 is an opportunity to expand the platform across four areas: the operator portal, backend execution, VSSA on-premises onboarding, and complex hybrid services.
|
||||
DPVP Phase 2 is an opportunity to expand the platform across five areas: the operator portal, backend execution, VSSA on-premises onboarding, complex hybrid services, and multi-cloud organization scanning.
|
||||
|
||||
The proposed scope below contains only the capabilities currently identified for discussion.
|
||||
|
||||
@@ -80,6 +81,16 @@ Introduce complex DPVP services covering:
|
||||
- cloud-based disaster recovery; and
|
||||
- a cloud observability toolkit connected to on-premises environments.
|
||||
|
||||
### 5. Multi-Cloud Organization Scanning Service
|
||||
|
||||
Introduce an organization scanning service covering:
|
||||
|
||||
- Amazon Web Services (AWS);
|
||||
- Microsoft Azure; and
|
||||
- Google Cloud Platform (GCP).
|
||||
|
||||
The scan types, security/compliance baselines, authorization and access model, reporting, remediation workflow, execution frequency, and acceptance criteria remain to be defined. This is proposed Phase 2 scope, not an approved testing authorization.
|
||||
|
||||
### Opportunity Qualification — Open
|
||||
|
||||
- [ ] Confirm opportunity owner and Atea/VSSA stakeholders.
|
||||
@@ -88,6 +99,7 @@ Introduce complex DPVP services covering:
|
||||
- [ ] Define dependencies, acceptance criteria, and target dates.
|
||||
- [ ] Select/evaluate backend execution approach: web server or cloud functions.
|
||||
- [ ] Define the delivery and commercial/procurement approach.
|
||||
- [ ] Define authorized assets, scan types/baselines, access, reporting, remediation workflow, frequency, and acceptance criteria for the AWS/Azure/GCP organization scanning service.
|
||||
|
||||
## Completed
|
||||
|
||||
|
||||
Reference in New Issue
Block a user