diff --git a/journals/2026-06-08.md b/journals/2026-06-08.md index ab3bdb0..8288c2b 100644 --- a/journals/2026-06-08.md +++ b/journals/2026-06-08.md @@ -7,3 +7,48 @@ Status: Active --- # Weekly Engineering & Operations Sync + + +Meeting notes +Patching strategy + +The team decided to continue patching non-production and production environments during summer, except for production in Sweden, Denmark, Norway, and Finland due to current restrictions. +Automation design + +Leszek explained that a design change is needed in automation to allow stopping patching for specific markets, and confirmed it is achievable. +Participants discussed the need for custom policies to be excluded or not set for certain countries, including dynamic and static policies. +Operations optimization + +The engineering and platform teams are working together to optimize certificate replacement across Europe, aiming to reduce operational workload as certificate validity periods decrease. +System logging and GDPR + +Participants discussed the implementation of system logging for all European services, with logs sent to Splunk and forwarded to security, except for GDPR-protected data. +Oleksandr raised concerns about unclear plans for future log collection, noting that logs may be collected without proper verification, which could lead to GDPR compliance issues. +Leszek emphasized that any changes to log collection affecting production should require a change request and include all affected configuration items due to GDPR implications. +Participants discussed the need for a Europe-wide solution to ensure SecOps logging complies with GDPR, rather than handling exceptions on individual servers. +Leszek confirmed that GDPR requirements and definitions are included in company security training, and participants suggested sharing relevant links or referring questions to Lars Gehring for clarification. +Participants agreed that Lars will lead discussions with legal and compliance regarding GDPR-protected data in system logs, and any future changes to log collection should be approved by legal and compliance. +Participants discussed the need to provide examples of GDPR-protected data lines and file names to help exclude sensitive information from logs, noting this is a manual task and should be coordinated with the relevant team. +Network migration + +Martin explained that the final batch of server networks connected to backend checkpoint firewalls will be migrated on Wednesday morning at 3am, marking significant progress toward closing down end-of-life firewalls by the end of June. +Martin confirmed that Finland and Switzerland migrations are complete, and Sweden's backend firewalls will be migrated in this batch, with internet-facing firewalls scheduled for the first service window after the summer break. +GDPR compliance + +Participants agreed to discuss GDPR compliance and log collection approvals with Lars in a meeting scheduled for tomorrow, ensuring legal and compliance requirements are met before proceeding. +Follow-up tasks + +Task Assigned to Due date Bucket +Submit vacation plans for the summer period (all participants) +Implement a design change in automation to allow stopping patching for specific markets (Leszek) +Exclude the Nordics from patching in July, while continuing patching in June and August as usual (all participants) +Provide examples of GDPR-protected data found in system logs to Dima for security investigation (Oleksandr, all participants) +Send specific examples of GDPR-protected data found in system logs to Dima for investigation (Oleksandr, all participants) +Schedule meeting with Lars to review legal and compliance approvals for log collection changes (Kamil, TEAMS RM STO Quantum) + + + + + + +