| <?php |
| |
| /** |
| * Copyright (c) 2023 Eclipse Foundation. |
| * |
| * This program and the accompanying materials are made |
| * available under the terms of the Eclipse Public License 2.0 |
| * which is available at /legal/epl-2.0/ |
| * |
| * Contributors: |
| * Olivier Goulet <olivier.goulet@eclipse-foundation.org> |
| * |
| * SPDX-License-Identifier: EPL-2.0 |
| */ |
| ?> |
| |
| <div id="maincontent"> |
| <div id="midcolumn"> |
| <h1> |
| <?php print $pageTitle; ?> |
| </h1> |
| <p>Draft - Not Yet Approved</p> |
| <p>Version 0.1 - Revision history at end of document</p> |
| |
| <section id="vision-and-scope"> |
| <h2>Vision and Scope</h2> |
| <p> |
| The mission of the Eclipse Cyber Risk Initiative Working Group ("ECRI") is to |
| ensure the security and integrity of Eclipse Foundation's community, projects, |
| systems, and data by implementing the industry's best practices and standards |
| for software production, risk management and incident response. Our goal is to |
| ensure that our community, projects, systems and data are protected against |
| potential threats and vulnerabilities, and that we are able to respond promptly |
| and effectively in the event of a security incident. |
| </p> |
| <p> |
| Our vision is to have the Eclipse Foundation be recognized across the industry |
| as a leading security organization, known for our ability to proactively |
| identify and mitigate risks, and effectively respond to incidents. We strive to |
| create a culture of security and to be a trusted advisor to our stakeholders on |
| all matters related to security. This includes providing guidance and expertise |
| on security best practices to ensure that the Eclipse community, projects, |
| systems, and data are protected to the highest degree possible. |
| </p> |
| <p> |
| Based on the above, the Eclipse Cyber Risk Initiative Working Group |
| ("ECRI") will fund, collaborate on, and prioritize enhancements to our |
| security-related processes and infrastructure. The prioritization of |
| security-related initiatives will be the responsibility of the working group |
| Steering Committee via its annual strategy setting and program plan processes. |
| </p> |
| <p>The Working Group will:</p> |
| <ul> |
| <li> |
| Drive improvements to the Eclipse Foundation's security policies and |
| processes for all projects. |
| </li> |
| <li> |
| Drive improvements to the Eclipse Foundation's infrastructure that |
| supports our open source projects. |
| </li> |
| <li> |
| Drive improvements to the security of our projects by providing services to |
| them including assistance in supporting our improved processes, external |
| security audits, and dependency analyses to mitigate for known vulnerabilities. |
| </li> |
| <li> |
| Help our committers and contributors improve their skills through training. |
| </li> |
| <li> |
| Promote the Eclipse project community's ability to deliver supply chain |
| secure open source components, frameworks, and runtimes. |
| </li> |
| <li> |
| Engage with government policy discussions related to open source supply |
| chain security to promote the interests of the Eclipse Foundation's open source |
| projects and community. |
| </li> |
| <li> |
| Manage the overall technical and business strategies with respect to |
| security risk mitigation and responsiveness for select open source |
| projects and participate in the same for select non-Eclipse open source |
| projects. |
| </li> |
| <li> |
| Establish and drive a funding model that enables this working group |
| and its community to operate on a sustainable basis. |
| </li> |
| </ul> |
| </section> |
| <section id="governance-and-precedence"> |
| <h2>Governance and Precedence</h2> |
| |
| <h3>Applicable Documents</h3> |
| <p> |
| The following governance documents are applicable to this charter, each |
| of which can be found on the <a href="/org/documents/">Eclipse Foundation Governance Documents</a> |
| page or the <a href="/legal/">Eclipse Foundation Legal Resources</a> page: |
| </p> |
| <ul> |
| <li>Eclipse Foundation Bylaws</li> |
| <li>Eclipse Foundation Working Group Process</li> |
| <li>Eclipse Foundation Working Group Operations Guide</li> |
| <li>Eclipse Foundation Code of Conduct</li> |
| <li>Eclipse Foundation Communication Channel Guidelines</li> |
| <li>Eclipse Foundation Membership Agreement</li> |
| <li>Eclipse Foundation Intellectual Property Policy</li> |
| <li>Eclipse Foundation Antitrust Policy</li> |
| <li>Eclipse Foundation Development Process</li> |
| <li>Eclipse Foundation Trademark Usage Guidelines</li> |
| </ul> |
| <p> |
| All Members must be parties to the Eclipse Foundation Membership |
| Agreement, including the requirement set forth in Section 2.2 to abide |
| by and adhere to the Bylaws and then-current policies of the Eclipse |
| Foundation, including but not limited to the Intellectual Property and |
| Antitrust Policies. |
| </p> |
| <p> |
| In the event of any conflict between the terms set forth in this |
| working group's charter and the Eclipse Foundation Bylaws, Membership |
| Agreement, Development Process, Specification Process, Working Group |
| Process or any policies of the Eclipse Foundation, the terms of the |
| respective Eclipse Foundation Bylaws, Membership Agreement, process or |
| policy shall take precedence. |
| </p> |
| </section> |
| <section id="membership"> |
| <h2>Membership</h2> |
| <p> |
| With the exception of Guest members as described below, an entity must |
| be at least a <a href="/membership/become_a_member/membershipTypes.php#contributingions">Contributing Member</a> |
| of the Eclipse Foundation, have executed the ECRI working group |
| participation agreement once defined and adhere to the requirements set |
| forth in this Charter to participate. |
| </p> |
| <p> |
| The participation fees associated with each of these membership classes |
| are shown in the Annual Participation Fees section. These are annual |
| fees, and are established by the ECRI Steering Committee, and will be |
| updated in this charter document accordingly. |
| </p> |
| <p> |
| The fees associated with membership in the Eclipse Foundation are |
| separate from any Working Group membership fees, and are decided as |
| described in the Eclipse Foundation Bylaws and detailed in the Eclipse |
| Foundation Membership Agreement. |
| </p> |
| <p> |
| There are 3 classes of ECRI working group membership - Strategic, |
| Participant, and Guest. |
| </p> |
| </section> |
| <section id="classes-of-membership"> |
| <h2>Classes of Membership</h2> |
| |
| <h3>Strategic Members</h3> |
| <p> |
| Strategic Members are organizations that view the activities of the |
| ECRI to improve the overall security posture of the Eclipse Foundation |
| projects, community, and infrastructure as strategic to their |
| organization and are investing significant resources to sustain and |
| shape the activities of this working group. Strategic Members of this |
| working group must be at least a Contributing Member of the Eclipse |
| Foundation. |
| </p> |
| |
| <h3>Participant Members</h3> |
| <p> |
| Participant Members are typically organizations that derive value from |
| the activities of the ECRI to improve the overall security posture of |
| the Eclipse Foundation projects, community, and infrastructure. These |
| organizations want to participate in the development and direction of |
| an open ecosystem related to this working group. Participant Members of |
| this working group must be at least a Contributing Member of the |
| Eclipse Foundation. |
| </p> |
| |
| <h3>Guest Members</h3> |
| <p> |
| Guest Members are organizations which are Associate members of the Eclipse |
| Foundation. Typical guests include R&D partners, universities, academic |
| research centers, etc. Guests may be invited to participate in committee |
| meetings at the invitation of the respective committee, but under no |
| circumstances do Guest members have voting rights. Guest members are required |
| to execute the Working Group's Participation Agreement. |
| </p> |
| </section> |
| <section id="membership-summary"> |
| <h2>Membership Summary</h2> |
| <table class="table"> |
| <thead> |
| <tr> |
| <th>Committee Representation</th> |
| <th>Strategic Member</th> |
| <th>Participant Member</th> |
| <th>Guest Member</th> |
| </tr> |
| </thead> |
| <tbody> |
| <tr> |
| <td>Steering Committee</td> |
| <td>Appointed</td> |
| <td>Elected</td> |
| <td>N/A</td> |
| </tbody> |
| </table> |
| </section> |
| <section id="special-interest-groups"> |
| <h2>Special Interest Groups</h2> |
| <p> |
| A Special Interest Group (SIG) is a lightweight structure formed within |
| the Working Group with a focus to collaborate around a particular topic |
| or domain of direct interest to the working group. SIGs are designed to |
| drive the objectives of a subset of the Members of the Working Group in |
| helping them achieve a dedicated set of goals and objectives. The scope |
| of the SIG must be consistent with the scope of the Working Group |
| Charter. |
| </p> |
| <p> |
| The creation of a SIG requires approval of the Steering Committee. Each |
| SIG may be either temporary or a permanent structure within the working |
| group. SIGs can be disbanded at any time by self selection presenting |
| reasons to and seek approval from the Steering Committee. Steering |
| Committees may disband a SIG at any time for being inactive or non |
| compliant with the Working Group's Charter, or by request of the SIG |
| itself. SIGs operate as a non-governing Body of the Working Group. |
| There are no additional annual fees to Members for participation in a |
| SIG. |
| </p> |
| </section> |
| <section> |
| <h2 id="sponsorship">Sponsorship</h2> |
| <p> |
| Sponsors are companies or individuals who provide money or services to |
| the working group on an ad hoc basis to support the activities of the |
| Working Group. Money or services provided by sponsors are used as set |
| forth in the working group annual budget. The working group is free to |
| determine whether and how those contributions are recognized. Under no |
| condition are sponsorship monies refunded. |
| </p> |
| <p> |
| Sponsors need not be members of the Eclipse Foundation or of the |
| Working Group. |
| </p> |
| </section> |
| <section> |
| <h2 id="Governance">Governance</h2> |
| <p>This ECRI working group is designed as:</p> |
| <ul> |
| <li> |
| a vendor-neutral, member-driven organization, |
| </li> |
| <li> |
| a means to foster a vibrant and sustainable community of security |
| practitioners at the Eclipse Foundation to support its projects, |
| community, and infrastructure, |
| </li> |
| <li> |
| a means to organize the Eclipse Foundation project community so that |
| users and developers can deliver on the mission and vision of the |
| ECRI. |
| </li> |
| </ul> |
| </section> |
| <section> |
| <h2 id="Governing Bodies">Governing Bodies</h2> |
| |
| <h3>Steering Committee</h3> |
| |
| <h4>Powers and Duties</h4> |
| <p>Steering Committee members are required to:</p> |
| <ul> |
| <li> |
| Define and manage the strategy of the working group. |
| </li> |
| <li> |
| Define and manage which Eclipse Foundation projects are included |
| within the scope of this working group. |
| </li> |
| <li> |
| Ensure the consistency of logo usage and other marketing materials. |
| </li> |
| <li> |
| Define and manage the technical roadmap. |
| </li> |
| <li> |
| Review and approve this charter. |
| </li> |
| <li> |
| Define the annual fees for all classes of the working group members. |
| </li> |
| <li> |
| Establish an annual program plan. |
| </li> |
| <li> |
| Approve the annual budget based upon funds received through fees. |
| </li> |
| <li> |
| Provide input and guidance on Eclipse Foundation activities related |
| to government policy discussions related to open source supply chain |
| security. |
| </li> |
| <li> |
| Approve the creation of subcommittees and define the purpose, scope, |
| and membership of each such subcommittee. |
| </li> |
| <li> |
| Approve the creation and retirement of Special Interest Groups |
| (SIGs). |
| </li> |
| <li> |
| Review and make recommendations regarding modifications to the |
| <a href="/security/policy.php">Eclipse Foundation Security Policy</a>. |
| </li> |
| </ul> |
| |
| <h4>Composition</h4> |
| <p> |
| Each Strategic Member of the working group is entitled to a seat on the |
| Steering Committee. |
| </p> |
| <p> |
| One seat is allocated to Participant Members via election. The |
| Participant Member seat is allocated following the Eclipse "Single |
| Transferable Vote", as defined in the Eclipse Foundation Bylaws. |
| </p> |
| <p> |
| The Eclipse Foundation's Head of Security is an ex officio member of |
| the Steering Committee. |
| </p> |
| <p> |
| The Committee elects a chair of the Steering Committee. This chair is |
| elected among the members of the Committee. They will serve for a 12 |
| month period or until their successor is elected and qualified, or as |
| otherwise provided for in this Charter. There is no limit on the number |
| of terms the chair may serve. |
| </p> |
| |
| <h4>Meeting Management</h4> |
| <p>The Steering Committee meets at least twice a year.</p> |
| </section> |
| <section> |
| <h2 id="common-dispositions">Common Dispositions</h2> |
| <p> |
| The dispositions below apply to all governance bodies for this working |
| group, unless otherwise specified. For all matters related to |
| membership action, including without limitation: meetings, quorum, |
| voting, vacancy, resignation or removal, the respective terms set forth |
| in the Eclipse Foundation Bylaws apply. |
| </p> |
| <p> |
| Appointed representatives on the Body may be replaced by the Member |
| organization they are representing at any time by providing written |
| notice to the Steering Committee. In the event a Body member is |
| unavailable to attend or participate in a meeting of the Body, they may |
| be represented by another Body member by providing written proxy to the |
| Body's mailing list in advance. As per the Eclipse Foundation Bylaws, a |
| representative shall be immediately removed from the Body upon the |
| termination of the membership of such representative's Member |
| organization. |
| </p> |
| |
| <h3>Voting</h3> |
| |
| <h4>Simple Majority</h4> |
| <p> |
| Excepting the actions specified below for which a Super Majority is |
| required, votes of the Body are determined by a simple majority of the |
| representatives represented at a committee meeting at which a quorum is |
| present. |
| </p> |
| |
| <h4>Super Majority</h4> |
| <p> |
| For actions (i) requesting that the Eclipse Foundation Board of |
| Directors approve a specification license; (ii) approving |
| specifications for adoption; (iii) modifying the working group charter; |
| (iv) approving or changing the name of the working group; and (v) |
| approving changes to annual Member contribution requirements; any such |
| actions must be approved by no less than two-thirds (2/3) of the |
| representatives represented at a committee meeting at which a quorum is |
| present. |
| </p> |
| |
| <h3>Term and Dates of Elections</h3> |
| <p>This section only applies to the Steering Committee.</p> |
| <p> |
| All representatives shall hold office until their respective successors |
| are appointed or elected, as applicable. There shall be no prohibition |
| on re-election or re-designation of any representative following the |
| completion of that representative's term of office. |
| </p> |
| |
| <h3>Strategic Members</h3> |
| <p> |
| Strategic Members Representatives shall serve in such capacity on |
| committees until the earlier of their removal by their respective |
| appointing Member organization or as otherwise provided for in this |
| Charter. |
| </p> |
| |
| <h3>Elected Representatives</h3> |
| <p> |
| Elected representatives shall each serve one-year terms and shall be |
| elected to serve for a 12 month term or until their respective |
| successors are elected and qualified, or as otherwise provided for in |
| this Charter. Procedures governing elections of Representatives may be |
| established pursuant to resolutions of the Steering Committee provided |
| that such resolutions are not inconsistent with any provision of this |
| Charter. |
| </p> |
| |
| <h3>Meetings Management</h3> |
| <p> |
| As prescribed in the Eclipse Foundation Working Group Process, all |
| meetings related to the working group will follow a prepared agenda and |
| minutes are distributed two weeks after the meeting and approved at the |
| next meeting at the latest, and shall in general conform to the Eclipse |
| Foundation Antitrust Policy. |
| </p> |
| |
| <h4>Meeting Frequency</h4> |
| <p> |
| Each governing body meets at least twice a year. All meetings may be |
| held at any place that has been designated from time-to-time by |
| resolution of the corresponding Body. All meetings may be held remotely |
| using phone calls, video calls, or any other means as designated from |
| time-to-time by resolution of the corresponding Body. |
| </p> |
| |
| <h4>Place of Meetings</h4> |
| <p> |
| All meetings may be held at any place that has been designated from |
| time-to-time by resolution of the corresponding body. All meetings may |
| be held remotely using phone calls, video calls, or any other means as |
| designated from time-to-time by resolution of the corresponding body. |
| </p> |
| |
| <h4>Regular Meetings</h4> |
| <p> |
| No Body meeting will be deemed to have been validly held unless a |
| notice of same has been provided to each of the representatives at |
| least fifteen (15) calendar days prior to such meeting, which notice |
| will identify all potential actions to be undertaken by the Body at the |
| Body meeting. No representative will be intentionally excluded from |
| Body meetings and all representatives shall receive notice of the |
| meeting as specified above; however, Body meetings need not be delayed |
| or rescheduled merely because one or more of the representatives cannot |
| attend or participate so long as at least a quorum of the Body is |
| represented at the Body meeting. |
| </p> |
| |
| <h4>Actions</h4> |
| <p> |
| The body may undertake an action only if it was identified in a body |
| meeting notice or otherwise identified in a notice of special meeting. |
| </p> |
| |
| <h4>Invitations</h4> |
| <p> |
| The Body may invite any member to any of its meetings. These invited |
| attendees have no right to vote. |
| </p> |
| </section> |
| <section> |
| <h2 id="working-group-annual-participation-fees-schedule-a"> |
| Working Group Annual Participation Fees Schedule A |
| </h2> |
| |
| <h3>ECRI Strategic Member Annual Participation Fees</h3> |
| <p> |
| Strategic members are required to execute the ECRI Working Group |
| Participation Agreement. NOTE: No Participation Fees are charged in |
| 2023. All Members who join prior to January 1, 2024 agree to begin |
| paying the full Annual Participation Fees beginning January 1, 2024, |
| and each January 1st thereafter. All Members who join on or after |
| January 1, 2024 agree to pay the Annual Participation Fees upon |
| joining, and on their subsequent anniversary date of joining. |
| </p> |
| <table class="table"> |
| <thead> |
| <tr> |
| <th>Corporate Revenue</th> |
| <th>Annual Fees</th> |
| </tr> |
| </thead> |
| <tbody> |
| <tr> |
| <td> |
| Annual Corporate Revenues greater than €1 billion |
| </td> |
| <td> |
| €200 000 |
| </td> |
| </tr> |
| <tr> |
| <td> |
| Annual Corporate Revenues greater than €500 million but less |
| than or equal to €1 billion |
| </td> |
| <td> |
| €150 000 |
| </td> |
| </tr> |
| <tr> |
| <td> |
| Annual Corporate Revenues greater than €100 million but less |
| than or equal to €500 million |
| </td> |
| <td> |
| €125 000 |
| </td> |
| </tr> |
| <tr> |
| <td> |
| Annual Corporate Revenues greater than €10 million but less |
| than or equal to €100 million |
| </td> |
| <td> |
| €75 000 |
| </td> |
| </tr> |
| <tr> |
| <td> |
| Annual Corporate Revenues less than or equal to €10 million |
| </td> |
| <td> |
| €50 000 |
| </td> |
| </tr> |
| </tbody> |
| </table> |
| |
| <h3>ECRI Participant Member Annual Participation Fees</h3> |
| <p> |
| Participant members are required to execute the ECRI Working Group |
| Participation Agreement. NOTE: No Participation Fees are charged in |
| 2023. All Members who join prior to January 1, 2024 agree to begin |
| paying the full Annual Participation Fees beginning January 1, 2024 and |
| each January 1st thereafter. All Members who join on or after January |
| 1, 2024 agree to pay the Annual Participation Fees upon joining and on |
| their subsequent anniversary date of joining. |
| </p> |
| |
| <table class="table"> |
| <thead> |
| <tr> |
| <th>Corporate Revenue</th> |
| <th>Annual Fees</th> |
| </tr> |
| </thead> |
| <tbody> |
| <tr> |
| <td> |
| Annual Corporate Revenues greater than €1 billion |
| </td> |
| <td> |
| €50 000 |
| </td> |
| </tr> |
| <tr> |
| <td> |
| Annual Corporate Revenues greater than €500 million but less |
| than or equal to €1 billion |
| </td> |
| <td> |
| €40 000 |
| </td> |
| </tr> |
| <tr> |
| <td> |
| Annual Corporate Revenues greater than €100 million but less |
| than or equal to €500 million |
| </td> |
| <td> |
| €30 000 |
| </td> |
| </tr> |
| <tr> |
| <td> |
| Annual Corporate Revenues greater than €10 million but less |
| than or equal to €100 million |
| </td> |
| <td> |
| €20 000 |
| </td> |
| </tr> |
| <tr> |
| <td> |
| Annual Corporate Revenues less than or equal to €10 million |
| </td> |
| <td> |
| €10 000 |
| </td> |
| </tr> |
| </tbody> |
| </table> |
| |
| <h3>ECRI Guest Member Annual Participation Fees</h3> |
| <p> |
| Guest members pay no annual fees, but are required to execute the ECRI |
| Working Group Participation Agreement. |
| </p> |
| </section> |
| <section class="margin-top-20"> |
| <p> |
| <strong>Charter History</strong> |
| </p> |
| <ul> |
| <li>v0.1 proposed draft May 24, 2023</li> |
| </ul> |
| </section> |
| </div> |
| </div> |