Jun 8, 2026, 10:06 AM
This commit is contained in:
@@ -7,3 +7,48 @@ Status: Active
|
||||
---
|
||||
|
||||
# Weekly Engineering & Operations Sync
|
||||
|
||||
|
||||
Meeting notes
|
||||
Patching strategy
|
||||
|
||||
The team decided to continue patching non-production and production environments during summer, except for production in Sweden, Denmark, Norway, and Finland due to current restrictions.
|
||||
Automation design
|
||||
|
||||
Leszek explained that a design change is needed in automation to allow stopping patching for specific markets, and confirmed it is achievable.
|
||||
Participants discussed the need for custom policies to be excluded or not set for certain countries, including dynamic and static policies.
|
||||
Operations optimization
|
||||
|
||||
The engineering and platform teams are working together to optimize certificate replacement across Europe, aiming to reduce operational workload as certificate validity periods decrease.
|
||||
System logging and GDPR
|
||||
|
||||
Participants discussed the implementation of system logging for all European services, with logs sent to Splunk and forwarded to security, except for GDPR-protected data.
|
||||
Oleksandr raised concerns about unclear plans for future log collection, noting that logs may be collected without proper verification, which could lead to GDPR compliance issues.
|
||||
Leszek emphasized that any changes to log collection affecting production should require a change request and include all affected configuration items due to GDPR implications.
|
||||
Participants discussed the need for a Europe-wide solution to ensure SecOps logging complies with GDPR, rather than handling exceptions on individual servers.
|
||||
Leszek confirmed that GDPR requirements and definitions are included in company security training, and participants suggested sharing relevant links or referring questions to Lars Gehring for clarification.
|
||||
Participants agreed that Lars will lead discussions with legal and compliance regarding GDPR-protected data in system logs, and any future changes to log collection should be approved by legal and compliance.
|
||||
Participants discussed the need to provide examples of GDPR-protected data lines and file names to help exclude sensitive information from logs, noting this is a manual task and should be coordinated with the relevant team.
|
||||
Network migration
|
||||
|
||||
Martin explained that the final batch of server networks connected to backend checkpoint firewalls will be migrated on Wednesday morning at 3am, marking significant progress toward closing down end-of-life firewalls by the end of June.
|
||||
Martin confirmed that Finland and Switzerland migrations are complete, and Sweden's backend firewalls will be migrated in this batch, with internet-facing firewalls scheduled for the first service window after the summer break.
|
||||
GDPR compliance
|
||||
|
||||
Participants agreed to discuss GDPR compliance and log collection approvals with Lars in a meeting scheduled for tomorrow, ensuring legal and compliance requirements are met before proceeding.
|
||||
Follow-up tasks
|
||||
|
||||
Task Assigned to Due date Bucket
|
||||
Submit vacation plans for the summer period (all participants)
|
||||
Implement a design change in automation to allow stopping patching for specific markets (Leszek)
|
||||
Exclude the Nordics from patching in July, while continuing patching in June and August as usual (all participants)
|
||||
Provide examples of GDPR-protected data found in system logs to Dima for security investigation (Oleksandr, all participants)
|
||||
Send specific examples of GDPR-protected data found in system logs to Dima for investigation (Oleksandr, all participants)
|
||||
Schedule meeting with Lars to review legal and compliance approvals for log collection changes (Kamil, TEAMS RM STO Quantum)
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user