Skip to main content

Security Policies

This section contains the security policies governing SIROS ID development and operations. These policies formalize existing practices and establish minimum security requirements.

PolicyScopeReview Cycle
Secure Development LifecycleAll sirosfoundation reposAnnual
Vulnerability Management SLASoftware, dependencies, infrastructureAnnual
SBOM MonitoringSupply chain securityAnnual

Policy Governance

  • Owner: Platform Team
  • Approval: Tech Lead
  • Review cycle: Annual (next review: April 2027)
  • Change process: Policy changes follow the same PR-based review process as code changes