DACI Decision
Tips and info
Recommendations
Contributors
Contributors: I am seeking the right people to get involved in the decision. Add your comments to this page, let's get the conversation started.
Please add:
- The people directly impacted by this so we can include them.
- Any references to previous work and investigations that we can leverage.
- Any constraints and challenges we need to consider to make this decision and following action plan.
Impact rating
Background
The application code developed for Lab Booster (DataLab) includes 3rd party libraries that are widely used in the industry but may still include vulnerabilities. Also the business logic within the code along with the application design may itself create vulnerabilities that could expose the Syensqo systems and data to potential bad actors. Including security tools as part of the application code build, and the development practice itself can significantly reduce this risk.
Current state
No standardized security tools are used.
Data for decision support
Options considered
| Option 1: Do nothing | Option 2: Aikido | Option 3: Snyk | Option 4: SonarQube | Option 5: HCL AppScan | |
|---|---|---|---|---|---|
Description | https://snyk.io/ | https://www.sonarsource.com/ | https://www.hcl-software.com/appscan | ||
Rollout plan | |||||
| Pros and cons |
|
|
|
|
|
Risks | New product and community knowledge/skills/support may be limited AI classification may not be very accurate | May not address all use cases | High cost and complexity to maintain | ||
Estimated cost and effort | From € 299/mo for 10 users | $25 per dev/product/month (minimum 5 devs / $1,375 annually) | Limited functionality for free Developer license $160/year | On demand, not publicly shared |
FAQ
Q1.
A1.
References
Follow-up action items
Learn more: https://www.atlassian.com/team-playbook/plays/daci
Copyright © 2016 Atlassian
This work is licensed under a Creative Commons Attribution-Non Commercial-Share Alike 4.0 International License.
