Skip to content

1B05H1N/software-approval-reference

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commit
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Software Approval Reference

Practical patterns for software intake, approval, inventory reconciliation, and ongoing oversight, using mostly open-source tooling. Built for teams that need a defensible workflow without buying a new platform first.

This repository is a companion to appsec-prodsec-reference: that repo skews toward software you build; this one skews toward software you bring in (installers, extensions, drivers, agents, images, IdP-registered SaaS clients, and similar).


Read first: disclaimer and limits

Start here: DISCLAIMER.md

In short:

  • This is independent reference material and a personal project - not an employer playbook, not a warranty, and not legal or compliance advice.
  • Nothing is guaranteed. You use documents and tools at your own risk; the author disclaims liability to the extent permitted by law.
  • Not one-size-fits-all. Adapt every workflow, field, and script to your sector, regulators, and internal approvals.
  • Get management and control-owner sign-off (Security, Risk, Legal, Procurement, and others as applicable) before you treat any of this as binding.

If any of the above is a problem for you, do not use this repository.


How to navigate (quick paths)

If you want to... Go to
Understand scope, limits, and philosophy Overview and scope
Stand up policy / standard / procedure language Governance: policy, standard, procedure
Design intake forms and risk tiers Intake and risk tiering
Run a technical review on a package IS technical review runbook
One-shot EXE / MSI / extension triage (scripts) tools/REVIEW-PACKAGE.md and tools/README.md
Hashes, TLS, signatures, key handling (concepts) Cryptography and integrity
Fill in records templates/ (see templates/README.md)

Suggested first read: Overview and scope, then Governance, then Intake and risk tiering. Everything else is reference you open when the request type needs it.


Program documents (by theme)

Foundation

Technical review lanes

Governance and inventory

Templates (narrative / catalog style)


Tools

Executable helpers live under tools/. They are reference scripts: read before you run, adapt to your environment, and follow DISCLAIMER.md.


Templates (forms and fields)

Structured blanks for tickets and systems: templates/. Index: templates/README.md.


Authoritative external sources (pointers only)

Citations are for your research, not a claim that this repo fully implements them:


Open-source tools mentioned in the docs

Paid tools are mentioned only where relevant; the narrative often assumes zero new license spend.


Publishing

For tags, a clean main history, and avoiding accidental secret commits, see PUBLISHING.md.


License

Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International (CC BY-NC-SA 4.0). See LICENSE. Tool scripts follow the same license unless a file says otherwise.


Contributions

Pull requests are welcome for clarity, factual fixes, and tooling that others can audit without a commercial license. By contributing, you agree your contribution can be licensed under the same terms.

About

Reference for enterprise software intake including some recommendations around stakeholder review, inventory, etc., with some policy-style docs, templates, and helper scripts. Not legal advice/see DISCLAIMER.

Topics

Resources

License

Stars

Watchers

Forks

Contributors