Security Policies
This section contains the security policies governing SIROS ID development and operations. These policies formalize existing practices and establish minimum security requirements.
| Policy | Scope | Review Cycle |
|---|---|---|
| Secure Development Lifecycle | All sirosfoundation repos | Annual |
| Vulnerability Management SLA | Software, dependencies, infrastructure | Annual |
| SBOM Monitoring | Supply chain security | Annual |
Policy Governance
- Owner: Platform Team
- Approval: Tech Lead
- Review cycle: Annual (next review: April 2027)
- Change process: Policy changes follow the same PR-based review process as code changes
Related Documents
- Security Architecture — Technical architecture implementing these policies
- Controls — Individual security controls mapped to frameworks