Skip to content

Conversation

@Robert-MacWha
Copy link
Collaborator

@Robert-MacWha Robert-MacWha commented Nov 27, 2025

Add references to existing frameworks within cert controls where relevant.

Also took notes of all the areas that are distinctly missing refs, attached as a txt file since it's fairly long. We can create sub-issues for the most critical tasks.

  • Secure Development Environments #273
  • Comprehensive account / access control framework
    • Write a canonical section on account / access control for web2, EX account authorization (2fa, yubikey, single-sign-on, etc), password management, permission management (EX aws permissions) .
  • Comprehensive monitoring page
    • Write a canonical monitoring page. Probably need to split it by on-chain vs off-chain targets, with the on-chain one being more important imo (since it'll be the same minus implementation details across a wider set of topics, while off-chain is more reliant on implementation specifics).
  • Incident response for compromised multisig / treasury / wallet.
    • Referenced in both multisig + treasury op certs, and would be generally helpful. I'm sure it exists.
  • Workspace Security
    • Basically need to write the whole thing.

certs-notes.txt

@vercel
Copy link

vercel bot commented Nov 27, 2025

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Preview Comments Updated (UTC)
frameworks Error Error Dec 3, 2025 7:10pm

@mattaereal
Copy link
Collaborator

Can you pull from develop and resolve conflicts? Also @DicksonWu654 can you review this?

@cloudflare-workers-and-pages
Copy link

cloudflare-workers-and-pages bot commented Dec 1, 2025

Deploying frameworks with  Cloudflare Pages  Cloudflare Pages

Latest commit: 0a492cb
Status:🚫  Build failed.

View logs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants