Multiple security proposals are being introduced piecemeal; the Arbitrum DAO should not rush into anything but work together on an inclusive RFP framework.
The security of smart contracts is of utmost importance in the Arbitrum ecosystem. To ensure the highest level of security, we propose implementing an RFP structure for smart contract security auditors. This proposal aims to establish a process for onboarding security service providers and then selecting them on a per-project basis in a transparent, fair, and efficient manner. The process will be open to all security engineers, researchers, and organizations.
The Arbitrum DAO shall issue an RFP for security services. The RFP will outline the requirements for security professionals, including their experience, qualifications, and methodology. The RFP will also specify the scope of the security services needed, the timeline, and the compensation rates for various project categories. [RFP Details TBD]
The selection process will be based on the following criteria:
Experience and Qualifications: Security researchers must have a proven track record of conducting smart contract security audits and/or tooling development. They must have experience with the Arbitrum ecosystem and be familiar with its unique features.
Methodology: Security researchers must have a rigorous audit and tooling SDLC methodology. They must be able to identify vulnerabilities and provide recommendations for remediation.
Price: Auditors must provide a competitive price for their services. [Standarized Metrics for rates TBD]
The selection process will be overseen by a committee of experts appointed by the Arbitrum DAO. The committee will review the proposals submitted by auditors and select the most qualified candidate based on the abovementioned criteria.
Implementing an RFP structure for security services will ensure the Arbitrum ecosystem remains secure and resilient. By establishing a transparent and fair service provider onboarding and project selection process, we can attract the best professionals and ensure they are compensated fairly for their services. We urge the Arbitrum DAO to consider this proposal and participate in the conversation, as the current state of the proposals is unmanageable, rushed, and exclusive.
For: Yes, invite security orgs to collaborate with the DAO on a RFP. Against: No, each security org should create its own proposal.
Please join the discussion on the Arbitrum Forums