Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[10k]: Security approval for static site launch #53

Closed
8 tasks done
Tracked by #373 ...
widal001 opened this issue Jun 28, 2023 · 1 comment
Closed
8 tasks done
Tracked by #373 ...

[10k]: Security approval for static site launch #53

widal001 opened this issue Jun 28, 2023 · 1 comment
Labels
deliverable: 10k ft Product deliverables described at 10k feet project: grants.gov Grants.gov Modernization tickets topic: backend Backend development tickets

Comments

@widal001
Copy link
Collaborator

widal001 commented Jun 28, 2023

Description

Jacob, our security officer, has confirmed that we expect all planned public deployment of services to fall under a security approval for beta.grants.gov. Review final proposal with Jacob or relevant security partner to ensure acceptance of our initial plan and we receive security approval to release the static site.

Outcome

  • Acceptance of proposal that indicates our environment(s) meet the controls
  • Our environment adheres to the SSP within the existing Grants.gov ATO

Dependencies

Risks and Mitigations

Risk:

  • Time to receive ATO is unknown and can be lengthy. The ATO process at HHS is new to the team. Team is unsure about the ATO process and who needs to be involved.

Mitigation:

  • Start the process early, regular check ins with security partner to show progress and get input
  • Get clarification early on who needs to be involved, set check ins with security partner to ensure the team is on the right track.

Sub-Tasks

Below are dependent on the SIA:

Out-of-scope but will need the following for prod:

Definition of Done

  • Acceptance of proposal that indicates our environment(s) meet the controls and adheres to the SSP/SIA for the beta launch in September
@widal001 widal001 converted this from a draft issue Jun 28, 2023
@widal001 widal001 added topic: frontend topic: backend Backend development tickets labels Jun 28, 2023
@widal001 widal001 modified the milestones: Authority to Operate (ATO), Static Site Launch with NOFO Content Jun 29, 2023
@widal001 widal001 added project: grants.gov Grants.gov Modernization tickets deliverable: 10k ft Product deliverables described at 10k feet labels Jul 14, 2023
@widal001 widal001 changed the title Milestone: Authority to Operate (ATO) [Epic]: Authority to Operate (ATO) Aug 28, 2023
@widal001 widal001 moved this from Prioritized to Planning in Simpler.Grants.gov Product Roadmap Aug 29, 2023
@sumiat sumiat moved this from Planning to Executing in Simpler.Grants.gov Product Roadmap Aug 29, 2023
@sumiat sumiat changed the title [Epic]: Authority to Operate (ATO) [Epic]: Security approval for static site Aug 29, 2023
@sumiat
Copy link
Contributor

sumiat commented Aug 29, 2023

Update on status: Meeting with security on 8/31 to discuss requirements for static site launch.

@sumiat sumiat changed the title [Epic]: Security approval for static site [Epic]: Security approval for static site launch Sep 5, 2023
@widal001 widal001 removed this from the FY23 Q4: Static Site Launch milestone Sep 18, 2023
@widal001 widal001 changed the title [Epic]: Security approval for static site launch [10k]: Security approval for static site launch Oct 12, 2023
@sumiat sumiat closed this as completed Oct 12, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
deliverable: 10k ft Product deliverables described at 10k feet project: grants.gov Grants.gov Modernization tickets topic: backend Backend development tickets
Projects
Development

No branches or pull requests

2 participants