Speaking of incident procedures. If you can point me to specific well documented pubic incident reporting procedures, I'd gladly take a look at them as a reference for Fedora's. I know Debian had an intrusion in 2004, and did a very good job of dealing with it. But its not clear if the Debian people were working from an established process or just winging it. Does Debian have a publicly communicated process on how intrusions are to be handled and communicated when they occur? If they do I'd love to read over it.