Skip to content

Commit 3b26cc4

Browse files
authored
Merge branch 'main' into feat/samm-aram
2 parents 140684a + 70fe439 commit 3b26cc4

File tree

10 files changed

+104
-8822
lines changed

10 files changed

+104
-8822
lines changed

CHANGELOG.md

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,10 @@
1+
# [1.17.0](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.16.0...v1.17.0) (2025-09-15)
2+
3+
4+
### Features
5+
6+
* adjust mappings for SAMM Secure Build ([471c7fc](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/471c7fce17e02ef63675047a6620beaf5aa96d2c))
7+
18
# [1.16.0](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.15.3...v1.16.0) (2025-06-04)
29

310

README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ To test changes to the yaml-files, please run:
77
docker run -ti -v $(pwd)/src/assets/YAML/default:/var/www/html/src/assets/YAML/default -v $(pwd)/src/assets/YAML/generated:/var/www/html/src/assets/YAML/generated -v $(pwd)/src/assets/YAML/schema:/var/www/html/src/assets/YAML/schema wurstbrot/dsomm-yaml-generation
88

99
# Afterwards, you can use the generated.yaml in a container
10-
docker run -v $(pwd)/src/assets/YAML/generated/generated.yaml:/usr/share/nginx/html/assets/YAML/generated/generated.yaml -p 8080:8080 wurstbrot/dsomm
10+
docker run -v $(pwd)/src/assets/YAML/generated/generated.yaml:/srv/assets/YAML/generated/generated.yaml -p 8080:8080 wurstbrot/dsomm
1111
```
1212

1313
## Credits

src/assets/YAML/default/Implementation/InfrastructureHardening.yaml

Lines changed: 4 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,6 @@ Implementation:
1717
usefulness: 4
1818
level: 1
1919
implementation:
20-
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/smartcard
2120
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/yubikey
2221
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/sms
2322
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/totp
@@ -54,7 +53,6 @@ Implementation:
5453
dependsOn:
5554
- MFA for admins
5655
implementation:
57-
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/smartcard
5856
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/yubikey
5957
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/sms
6058
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/totp
@@ -379,8 +377,8 @@ Implementation:
379377
usefulness: 4
380378
level: 2
381379
implementation:
382-
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/cis-kubernetes-bench
383-
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/cis-docker-bench-for
380+
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/cis-kubernetes-benchmark
381+
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/cis-docker-benchmark
384382
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/for-example-for-cont
385383
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/attack-matrix-cloud
386384
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/attack-matrix-containers
@@ -412,8 +410,8 @@ Implementation:
412410
usefulness: 3
413411
level: 4
414412
implementation:
415-
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/cis-kubernetes-bench
416-
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/cis-docker-bench-for
413+
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/cis-kubernetes-benchmark
414+
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/cis-docker-benchmark
417415
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/for-example-for-cont
418416
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/attack-matrix-cloud
419417
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/attack-matrix-containers

src/assets/YAML/default/InformationGathering/Logging.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ Information Gathering:
1616
time: 1
1717
resources: 1
1818
usefulness: 5
19-
level: 3
19+
level: 2
2020
dependsOn:
2121
- Alerting
2222
implementation: []
@@ -177,7 +177,7 @@ Information Gathering:
177177
time: 3
178178
resources: 3
179179
usefulness: 4
180-
level: 2
180+
level: 3
181181
dependsOn:
182182
- Centralized system logging
183183
- Centralized application logging

src/assets/YAML/default/TestAndVerification/Consolidation.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -196,7 +196,7 @@ Test and Verification:
196196
usefulness: 3
197197
level: 2
198198
dependsOn:
199-
- uuid:c1acc8af-312e-4503-a817-a26220c993a0 # Simple false positive treatment
199+
- c1acc8af-312e-4503-a817-a26220c993a0 # Simple false positive treatment
200200
implementation:
201201
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-defectdojo
202202
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/purify
@@ -341,8 +341,8 @@ Test and Verification:
341341
usefulness: 4
342342
level: 3
343343
dependsOn:
344-
- uuid:8f2b4d5a-3c1e-4b7a-9d8f-2e6c4a1b5d7f # Artifact-based false positive treatment
345-
- uuid:85ba5623-84be-4219-8892-808837be582d # Usage of a vulnerability management system
344+
- 8f2b4d5a-3c1e-4b7a-9d8f-2e6c4a1b5d7f # Artifact-based false positive treatment
345+
- 85ba5623-84be-4219-8892-808837be582d # Usage of a vulnerability management system
346346
implementation:
347347
references:
348348
samm2:

src/assets/YAML/default/implementations.yaml

Lines changed: 7 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -249,16 +249,16 @@ implementations:
249249
name: OWASP MASVS
250250
tags: []
251251
url: https://github.com/OWASP/owasp-masvs
252-
cis-kubernetes-bench:
252+
cis-kubernetes-benchmark:
253253
uuid: edaec98d-dac7-4dfd-8ab3-42c471d5b9ff
254-
name: CIS Kubernetes Bench for Security
254+
name: CIS Kubernetes Benchmark for Security
255255
tags: []
256-
url: https://www.cisecurity.org/cis-benchmarks/#
257-
cis-docker-bench-for:
256+
url: https://www.cisecurity.org/benchmark/kubernetes
257+
cis-docker-benchmark:
258258
uuid: 4dd23c4a-5a7e-4917-82cf-d00e0f04482f
259-
name: CIS Docker Bench for Security
259+
name: CIS Docker Benchmark for Security
260260
tags: []
261-
url: https://www.cisecurity.org/cis-benchmarks/
261+
url: https://www.cisecurity.org/benchmark/docker
262262
for-example-for-cont:
263263
uuid: f4d7c796-8574-4a88-ab00-98d245a115ef
264264
name: For example for Cont
@@ -355,14 +355,9 @@ implementations:
355355
uuid: cc55cba1-ea0a-466e-99c5-337c9da2b00e
356356
name: Plugins
357357
tags: []
358-
smartcard:
359-
uuid: e76a395a-8d6a-4e25-a175-6cf25409b755
360-
name: Smartcard
361-
tags: []
362-
url: https://d3fend.mitre.org/technique/d3f:Multi-factorAuthentication/#
363358
yubikey:
364359
uuid: d5981117-9bc2-45ed-b4a4-383135dc13d8
365-
name: YubiKey
360+
name: YubiKey - Smartcard
366361
tags: []
367362
url: https://d3fend.mitre.org/technique/d3f:Multi-factorAuthentication/
368363
sms:

0 commit comments

Comments
 (0)