blob: 5d5f67d7ec20d54566d51e4195a39680c05d0444 [file]
<?php
/**
* Copyright (c) 2023 Eclipse Foundation.
*
* This program and the accompanying materials are made
* available under the terms of the Eclipse Public License 2.0
* which is available at /legal/epl-2.0/
*
* Contributors:
* Olivier Goulet <olivier.goulet@eclipse-foundation.org>
*
* SPDX-License-Identifier: EPL-2.0
*/
?>
<div id="maincontent">
<div id="midcolumn">
<h1>
<?php print $pageTitle; ?>
</h1>
<p>Draft - Not Yet Approved</p>
<p>Version 0.1 - Revision history at end of document</p>
<section id="vision-and-scope">
<h2>Vision and Scope</h2>
<p>
The mission of the Eclipse Cyber Risk Initiative Working Group ("ECRI") is to
ensure the security and integrity of Eclipse Foundation's community, projects,
systems, and data by implementing the industry's best practices and standards
for software production, risk management and incident response. Our goal is to
ensure that our community, projects, systems and data are protected against
potential threats and vulnerabilities, and that we are able to respond promptly
and effectively in the event of a security incident.
</p>
<p>
Our vision is to have the Eclipse Foundation be recognized across the industry
as a leading security organization, known for our ability to proactively
identify and mitigate risks, and effectively respond to incidents. We strive to
create a culture of security and to be a trusted advisor to our stakeholders on
all matters related to security. This includes providing guidance and expertise
on security best practices to ensure that the Eclipse community, projects,
systems, and data are protected to the highest degree possible.
</p>
<p>
Based on the above, the Eclipse Cyber Risk Initiative Working Group
("ECRI") will fund, collaborate on, and prioritize enhancements to our
security-related processes and infrastructure. The prioritization of
security-related initiatives will be the responsibility of the working group
Steering Committee via its annual strategy setting and program plan processes.
</p>
<p>The Working Group will:</p>
<ul>
<li>
Drive improvements to the Eclipse Foundation's security policies and
processes for all projects.
</li>
<li>
Drive improvements to the Eclipse Foundation's infrastructure that
supports our open source projects.
</li>
<li>
Drive improvements to the security of our projects by providing services to
them including assistance in supporting our improved processes, external
security audits, and dependency analyses to mitigate for known vulnerabilities.
</li>
<li>
Help our committers and contributors improve their skills through training.
</li>
<li>
Promote the Eclipse project community's ability to deliver supply chain
secure open source components, frameworks, and runtimes.
</li>
<li>
Engage with government policy discussions related to open source supply
chain security to promote the interests of the Eclipse Foundation's open source
projects and community.
</li>
<li>
Manage the overall technical and business strategies with respect to
security risk mitigation and responsiveness for select open source
projects and participate in the same for select non-Eclipse open source
projects.
</li>
<li>
Establish and drive a funding model that enables this working group
and its community to operate on a sustainable basis.
</li>
</ul>
</section>
<section id="governance-and-precedence">
<h2>Governance and Precedence</h2>
<h3>Applicable Documents</h3>
<p>
The following governance documents are applicable to this charter, each
of which can be found on the <a href="/org/documents/">Eclipse Foundation Governance Documents</a>
page or the <a href="/legal/">Eclipse Foundation Legal Resources</a> page:
</p>
<ul>
<li>Eclipse Foundation Bylaws</li>
<li>Eclipse Foundation Working Group Process</li>
<li>Eclipse Foundation Working Group Operations Guide</li>
<li>Eclipse Foundation Code of Conduct</li>
<li>Eclipse Foundation Communication Channel Guidelines</li>
<li>Eclipse Foundation Membership Agreement</li>
<li>Eclipse Foundation Intellectual Property Policy</li>
<li>Eclipse Foundation Antitrust Policy</li>
<li>Eclipse Foundation Development Process</li>
<li>Eclipse Foundation Trademark Usage Guidelines</li>
</ul>
<p>
All Members must be parties to the Eclipse Foundation Membership
Agreement, including the requirement set forth in Section 2.2 to abide
by and adhere to the Bylaws and then-current policies of the Eclipse
Foundation, including but not limited to the Intellectual Property and
Antitrust Policies.
</p>
<p>
In the event of any conflict between the terms set forth in this
working group's charter and the Eclipse Foundation Bylaws, Membership
Agreement, Development Process, Specification Process, Working Group
Process or any policies of the Eclipse Foundation, the terms of the
respective Eclipse Foundation Bylaws, Membership Agreement, process or
policy shall take precedence.
</p>
</section>
<section id="membership">
<h2>Membership</h2>
<p>
With the exception of Guest members as described below, an entity must
be at least a <a href="/membership/become_a_member/membershipTypes.php#contributingions">Contributing Member</a>
of the Eclipse Foundation, have executed the ECRI working group
participation agreement once defined and adhere to the requirements set
forth in this Charter to participate.
</p>
<p>
The participation fees associated with each of these membership classes
are shown in the Annual Participation Fees section. These are annual
fees, and are established by the ECRI Steering Committee, and will be
updated in this charter document accordingly.
</p>
<p>
The fees associated with membership in the Eclipse Foundation are
separate from any Working Group membership fees, and are decided as
described in the Eclipse Foundation Bylaws and detailed in the Eclipse
Foundation Membership Agreement.
</p>
<p>
There are 3 classes of ECRI working group membership - Strategic,
Participant, and Guest.
</p>
</section>
<section id="classes-of-membership">
<h2>Classes of Membership</h2>
<h3>Strategic Members</h3>
<p>
Strategic Members are organizations that view the activities of the
ECRI to improve the overall security posture of the Eclipse Foundation
projects, community, and infrastructure as strategic to their
organization and are investing significant resources to sustain and
shape the activities of this working group. Strategic Members of this
working group must be at least a Contributing Member of the Eclipse
Foundation.
</p>
<h3>Participant Members</h3>
<p>
Participant Members are typically organizations that derive value from
the activities of the ECRI to improve the overall security posture of
the Eclipse Foundation projects, community, and infrastructure. These
organizations want to participate in the development and direction of
an open ecosystem related to this working group. Participant Members of
this working group must be at least a Contributing Member of the
Eclipse Foundation.
</p>
<h3>Guest Members</h3>
<p>
Guest Members are organizations which are Associate members of the Eclipse
Foundation. Typical guests include R&D partners, universities, academic
research centers, etc. Guests may be invited to participate in committee
meetings at the invitation of the respective committee, but under no
circumstances do Guest members have voting rights. Guest members are required
to execute the Working Group's Participation Agreement.
</p>
</section>
<section id="membership-summary">
<h2>Membership Summary</h2>
<table class="table">
<thead>
<tr>
<th>Committee Representation</th>
<th>Strategic Member</th>
<th>Participant Member</th>
<th>Guest Member</th>
</tr>
</thead>
<tbody>
<tr>
<td>Steering Committee</td>
<td>Appointed</td>
<td>Elected</td>
<td>N/A</td>
</tbody>
</table>
</section>
<section id="special-interest-groups">
<h2>Special Interest Groups</h2>
<p>
A Special Interest Group (SIG) is a lightweight structure formed within
the Working Group with a focus to collaborate around a particular topic
or domain of direct interest to the working group. SIGs are designed to
drive the objectives of a subset of the Members of the Working Group in
helping them achieve a dedicated set of goals and objectives. The scope
of the SIG must be consistent with the scope of the Working Group
Charter.
</p>
<p>
The creation of a SIG requires approval of the Steering Committee. Each
SIG may be either temporary or a permanent structure within the working
group. SIGs can be disbanded at any time by self selection presenting
reasons to and seek approval from the Steering Committee. Steering
Committees may disband a SIG at any time for being inactive or non
compliant with the Working Group's Charter, or by request of the SIG
itself. SIGs operate as a non-governing Body of the Working Group.
There are no additional annual fees to Members for participation in a
SIG.
</p>
</section>
<section>
<h2 id="sponsorship">Sponsorship</h2>
<p>
Sponsors are companies or individuals who provide money or services to
the working group on an ad hoc basis to support the activities of the
Working Group. Money or services provided by sponsors are used as set
forth in the working group annual budget. The working group is free to
determine whether and how those contributions are recognized. Under no
condition are sponsorship monies refunded.
</p>
<p>
Sponsors need not be members of the Eclipse Foundation or of the
Working Group.
</p>
</section>
<section>
<h2 id="Governance">Governance</h2>
<p>This ECRI working group is designed as:</p>
<ul>
<li>
a vendor-neutral, member-driven organization,
</li>
<li>
a means to foster a vibrant and sustainable community of security
practitioners at the Eclipse Foundation to support its projects,
community, and infrastructure,
</li>
<li>
a means to organize the Eclipse Foundation project community so that
users and developers can deliver on the mission and vision of the
ECRI.
</li>
</ul>
</section>
<section>
<h2 id="Governing Bodies">Governing Bodies</h2>
<h3>Steering Committee</h3>
<h4>Powers and Duties</h4>
<p>Steering Committee members are required to:</p>
<ul>
<li>
Define and manage the strategy of the working group.
</li>
<li>
Define and manage which Eclipse Foundation projects are included
within the scope of this working group.
</li>
<li>
Ensure the consistency of logo usage and other marketing materials.
</li>
<li>
Define and manage the technical roadmap.
</li>
<li>
Review and approve this charter.
</li>
<li>
Define the annual fees for all classes of the working group members.
</li>
<li>
Establish an annual program plan.
</li>
<li>
Approve the annual budget based upon funds received through fees.
</li>
<li>
Provide input and guidance on Eclipse Foundation activities related
to government policy discussions related to open source supply chain
security.
</li>
<li>
Approve the creation of subcommittees and define the purpose, scope,
and membership of each such subcommittee.
</li>
<li>
Approve the creation and retirement of Special Interest Groups
(SIGs).
</li>
<li>
Review and make recommendations regarding modifications to the
<a href="/security/policy.php">Eclipse Foundation Security Policy</a>.
</li>
</ul>
<h4>Composition</h4>
<p>
Each Strategic Member of the working group is entitled to a seat on the
Steering Committee.
</p>
<p>
One seat is allocated to Participant Members via election. The
Participant Member seat is allocated following the Eclipse "Single
Transferable Vote", as defined in the Eclipse Foundation Bylaws.
</p>
<p>
The Eclipse Foundation's Head of Security is an ex officio member of
the Steering Committee.
</p>
<p>
The Committee elects a chair of the Steering Committee. This chair is
elected among the members of the Committee. They will serve for a 12
month period or until their successor is elected and qualified, or as
otherwise provided for in this Charter. There is no limit on the number
of terms the chair may serve.
</p>
<h4>Meeting Management</h4>
<p>The Steering Committee meets at least twice a year.</p>
</section>
<section>
<h2 id="common-dispositions">Common Dispositions</h2>
<p>
The dispositions below apply to all governance bodies for this working
group, unless otherwise specified. For all matters related to
membership action, including without limitation: meetings, quorum,
voting, vacancy, resignation or removal, the respective terms set forth
in the Eclipse Foundation Bylaws apply.
</p>
<p>
Appointed representatives on the Body may be replaced by the Member
organization they are representing at any time by providing written
notice to the Steering Committee. In the event a Body member is
unavailable to attend or participate in a meeting of the Body, they may
be represented by another Body member by providing written proxy to the
Body's mailing list in advance. As per the Eclipse Foundation Bylaws, a
representative shall be immediately removed from the Body upon the
termination of the membership of such representative's Member
organization.
</p>
<h3>Voting</h3>
<h4>Simple Majority</h4>
<p>
Excepting the actions specified below for which a Super Majority is
required, votes of the Body are determined by a simple majority of the
representatives represented at a committee meeting at which a quorum is
present.
</p>
<h4>Super Majority</h4>
<p>
For actions (i) requesting that the Eclipse Foundation Board of
Directors approve a specification license; (ii) approving
specifications for adoption; (iii) modifying the working group charter;
(iv) approving or changing the name of the working group; and (v)
approving changes to annual Member contribution requirements; any such
actions must be approved by no less than two-thirds (2/3) of the
representatives represented at a committee meeting at which a quorum is
present.
</p>
<h3>Term and Dates of Elections</h3>
<p>This section only applies to the Steering Committee.</p>
<p>
All representatives shall hold office until their respective successors
are appointed or elected, as applicable. There shall be no prohibition
on re-election or re-designation of any representative following the
completion of that representative's term of office.
</p>
<h3>Strategic Members</h3>
<p>
Strategic Members Representatives shall serve in such capacity on
committees until the earlier of their removal by their respective
appointing Member organization or as otherwise provided for in this
Charter.
</p>
<h3>Elected Representatives</h3>
<p>
Elected representatives shall each serve one-year terms and shall be
elected to serve for a 12 month term or until their respective
successors are elected and qualified, or as otherwise provided for in
this Charter. Procedures governing elections of Representatives may be
established pursuant to resolutions of the Steering Committee provided
that such resolutions are not inconsistent with any provision of this
Charter.
</p>
<h3>Meetings Management</h3>
<p>
As prescribed in the Eclipse Foundation Working Group Process, all
meetings related to the working group will follow a prepared agenda and
minutes are distributed two weeks after the meeting and approved at the
next meeting at the latest, and shall in general conform to the Eclipse
Foundation Antitrust Policy.
</p>
<h4>Meeting Frequency</h4>
<p>
Each governing body meets at least twice a year. All meetings may be
held at any place that has been designated from time-to-time by
resolution of the corresponding Body. All meetings may be held remotely
using phone calls, video calls, or any other means as designated from
time-to-time by resolution of the corresponding Body.
</p>
<h4>Place of Meetings</h4>
<p>
All meetings may be held at any place that has been designated from
time-to-time by resolution of the corresponding body. All meetings may
be held remotely using phone calls, video calls, or any other means as
designated from time-to-time by resolution of the corresponding body.
</p>
<h4>Regular Meetings</h4>
<p>
No Body meeting will be deemed to have been validly held unless a
notice of same has been provided to each of the representatives at
least fifteen (15) calendar days prior to such meeting, which notice
will identify all potential actions to be undertaken by the Body at the
Body meeting. No representative will be intentionally excluded from
Body meetings and all representatives shall receive notice of the
meeting as specified above; however, Body meetings need not be delayed
or rescheduled merely because one or more of the representatives cannot
attend or participate so long as at least a quorum of the Body is
represented at the Body meeting.
</p>
<h4>Actions</h4>
<p>
The body may undertake an action only if it was identified in a body
meeting notice or otherwise identified in a notice of special meeting.
</p>
<h4>Invitations</h4>
<p>
The Body may invite any member to any of its meetings. These invited
attendees have no right to vote.
</p>
</section>
<section>
<h2 id="working-group-annual-participation-fees-schedule-a">
Working Group Annual Participation Fees Schedule A
</h2>
<h3>ECRI Strategic Member Annual Participation Fees</h3>
<p>
Strategic members are required to execute the ECRI Working Group
Participation Agreement. NOTE: No Participation Fees are charged in
2023. All Members who join prior to January 1, 2024 agree to begin
paying the full Annual Participation Fees beginning January 1, 2024,
and each January 1st thereafter. All Members who join on or after
January 1, 2024 agree to pay the Annual Participation Fees upon
joining, and on their subsequent anniversary date of joining.
</p>
<table class="table">
<thead>
<tr>
<th>Corporate Revenue</th>
<th>Annual Fees</th>
</tr>
</thead>
<tbody>
<tr>
<td>
Annual Corporate Revenues greater than &euro;1 billion
</td>
<td>
&euro;200 000
</td>
</tr>
<tr>
<td>
Annual Corporate Revenues greater than &euro;500 million but less
than or equal to &euro;1 billion
</td>
<td>
&euro;150 000
</td>
</tr>
<tr>
<td>
Annual Corporate Revenues greater than &euro;100 million but less
than or equal to &euro;500 million
</td>
<td>
&euro;125 000
</td>
</tr>
<tr>
<td>
Annual Corporate Revenues greater than &euro;10 million but less
than or equal to &euro;100 million
</td>
<td>
&euro;75 000
</td>
</tr>
<tr>
<td>
Annual Corporate Revenues less than or equal to &euro;10 million
</td>
<td>
&euro;50 000
</td>
</tr>
</tbody>
</table>
<h3>ECRI Participant Member Annual Participation Fees</h3>
<p>
Participant members are required to execute the ECRI Working Group
Participation Agreement. NOTE: No Participation Fees are charged in
2023. All Members who join prior to January 1, 2024 agree to begin
paying the full Annual Participation Fees beginning January 1, 2024 and
each January 1st thereafter. All Members who join on or after January
1, 2024 agree to pay the Annual Participation Fees upon joining and on
their subsequent anniversary date of joining.
</p>
<table class="table">
<thead>
<tr>
<th>Corporate Revenue</th>
<th>Annual Fees</th>
</tr>
</thead>
<tbody>
<tr>
<td>
Annual Corporate Revenues greater than &euro;1 billion
</td>
<td>
&euro;50 000
</td>
</tr>
<tr>
<td>
Annual Corporate Revenues greater than &euro;500 million but less
than or equal to &euro;1 billion
</td>
<td>
&euro;40 000
</td>
</tr>
<tr>
<td>
Annual Corporate Revenues greater than &euro;100 million but less
than or equal to &euro;500 million
</td>
<td>
&euro;30 000
</td>
</tr>
<tr>
<td>
Annual Corporate Revenues greater than &euro;10 million but less
than or equal to &euro;100 million
</td>
<td>
&euro;20 000
</td>
</tr>
<tr>
<td>
Annual Corporate Revenues less than or equal to &euro;10 million
</td>
<td>
&euro;10 000
</td>
</tr>
</tbody>
</table>
<h3>ECRI Guest Member Annual Participation Fees</h3>
<p>
Guest members pay no annual fees, but are required to execute the ECRI
Working Group Participation Agreement.
</p>
</section>
<section class="margin-top-20">
<p>
<strong>Charter History</strong>
</p>
<ul>
<li>v0.1 proposed draft May 24, 2023</li>
</ul>
</section>
</div>
</div>