4 ms·
Not a complete nothing burger; a lot of people here work for companies that sell to the Feds or host FedRAMP-authorized SaaS solutions. There will definitely be
by sullivanmatt 4y ago
Not a complete nothing burger; a lot of people here work for companies that sell to the Feds or host FedRAMP-authorized SaaS solutions. There will definitely be private-sector impact from that risk framework, though I'm not saying that's necessarily a good or a bad thing.
- 9wzYQbTYsAIc 4y agoAdditionally, “The legislation also requires CISA to hire professionals with experience developing open source software to ensure that government and the community work hand-in-hand and are prepared to address incidents like the Log4j vulnerability.” So we should definitely expect at least some minute changes to the open source economy, itself.
- dimitrios1 4y agoThis is the worst part. "Experience developing open source software" is both entirely vague and specific at the same time, likely conjuring up an image of some developer with green boxes on a GitHub repo or something, which is terrible. This is going to force the creation of some sort of silly criteria for what constitutes that experience, of which suits in federal agencies, and the political pressure and politicians they are behest to, will likely have no concept of less-popular open source communities, which will detract from the ethos of open source and ultimately, and more importantly, freedom.
- tazjin 4y agoAnyone owning at least three Hacktoberfest t-shirts qualifies.
- cvoss 4y agoWhat criteria would you like to see here?
- kube-system 4y ago> "Experience developing open source software" is both entirely vague and specific at the same time Good. CISA is better equipped to be refining those specific requirements than Congress.
- themitigating 4y agoYou are focusing on the hiring requirements which is very vague. What would be a better way to define hiring requirements?