[ Accepted by -core February 2002 ]
The FreeBSD Security Officer's mission is to protect the FreeBSD user community by keeping the community informed of bugs, exploits, popular attacks, and other risks; by acting as a liaison on behalf of the FreeBSD Project with external organizations regarding sensitive, non-public security issues; and by promoting the distribution of information needed to safely run FreeBSD systems, such as system administration and programming tips.
The responsibilities of the Security Officer include:
The FreeBSD Core Team has delegated authority to the Security Officer in matters of security, and the Security Officer is accountable to the Core Team in the use of this authority. He is expected to act with common sense and use appropriate discretion when using any of the appointed powers. Any actions that conflict with the committers' guidelines require particularly careful judgment.
Specifically, subject to the accountability constraints, the Security Officer is granted the following powers:
A new Security Officer is appointed by the previous Security Officer and ratified by the Core Team. The Security Officer is accountable to the Core Team.
The Security Officer Team members are selected by the Security Officer, and they are accountable to the Security Officer and to the Core Team. Security Officer Team members are expected to assist the Security Officer in fulfilling his responsibilities and otherwise participate in protecting the FreeBSD user community.