Skip to content

Security: judeper/FSI-AgentGov

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this framework or its templates, please report it responsibly.

How to Report

  1. Do NOT open a public GitHub issue for security vulnerabilities
  2. Use GitHub's private vulnerability reporting (Security tab → Report a vulnerability), or contact the maintainers directly with:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

What to Expect

  • Acknowledgment within 48 hours
  • Status update within 7 days
  • Coordinated disclosure after fix is available

Scope

This security policy covers:

  • Documentation content that could lead to insecure implementations
  • Template files (Excel) containing sensitive formulas or macros
  • Example configurations that could expose systems

Best Practices

When implementing this framework:

  • Review all controls with your security team
  • Validate configurations in non-production environments
  • Follow your organization's change management processes
  • Maintain audit trails for all implementations

FSI Agent Governance Framework v1.0 Beta

There aren’t any published security advisories