diff options
| author | Rey Lejano <rlejano@gmail.com> | 2021-06-04 14:04:21 -0700 |
|---|---|---|
| committer | Rey Lejano <rlejano@gmail.com> | 2021-06-04 14:04:21 -0700 |
| commit | 90737e76d2a5a4a0aeee9e3175a775fe9a15b502 (patch) | |
| tree | 8cb329e6c8e8f6430b902b3d64b2bf240af67840 /sig-security | |
| parent | 7acd3af1aa175fe1f28f57f9791cdb281d3e19be (diff) | |
update answer to attack vector question
Diffstat (limited to 'sig-security')
| -rw-r--r-- | sig-security/security-audit-2021/RFP.md | 5 |
1 files changed, 2 insertions, 3 deletions
diff --git a/sig-security/security-audit-2021/RFP.md b/sig-security/security-audit-2021/RFP.md index d0ea8cb7..e754248c 100644 --- a/sig-security/security-audit-2021/RFP.md +++ b/sig-security/security-audit-2021/RFP.md @@ -162,9 +162,8 @@ The latest date to receive deliverables will be negotiated with the selected ven ### Which attack vectors are of most concern to the Working Group. 1. The attack vector most concerned about is unauthenticated access to a cluster resulting in compromise of the [components in-scope](#project_goals_and_scope) -2. Crossing cluster boundaries for multi-cluster configuration -3. Crossing namespace boundaries, an authenticated attacker being able to affect resources their credentials do not directly allow -4. Any other attack vector that exists against the components in scope +2. Crossing namespace boundaries, an authenticated attacker being able to affect resources their credentials do not directly allow +3. Any other attack vector that exists against the components in scope ### Is there flexibility to wait for staff to be available to work on the audit? |
