Skip to content

Commit 66f7105

Browse files
authored
Merge pull request #44 from devsecopsmaturitymodel/feat/samm-aram
feat: update SAMM mapping based on @aramhovsepyan feedback
2 parents 70fe439 + 3b26cc4 commit 66f7105

20 files changed

+258
-9061
lines changed

src/assets/YAML/default/BuildAndDeployment/Build.yaml

Lines changed: 9 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ Build and Deployment:
3131
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/container-technologi
3232
references:
3333
samm2:
34-
- I-SB-2-A
34+
- I-SB-A-2
3535
iso27001-2017:
3636
- 14.2.6
3737
iso27001-2022:
@@ -72,7 +72,7 @@ Build and Deployment:
7272
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/container-technologi
7373
references:
7474
samm2:
75-
- I-SB-1-A
75+
- I-SB-A-1
7676
iso27001-2017:
7777
- 12.1.1
7878
- 14.2.2
@@ -105,14 +105,16 @@ Build and Deployment:
105105
resources: 2
106106
usefulness: 3
107107
level: 2
108+
tags:
109+
- inventory
108110
implementation:
109111
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/signing-of-containers
110112
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/immutable-images
111113
dependsOn:
112114
- Defined build process
113115
references:
114116
samm2:
115-
- I-SB-1-A
117+
- I-SB-B-1
116118
iso27001-2017:
117119
- 14.2.6
118120
iso27001-2022:
@@ -145,7 +147,8 @@ Build and Deployment:
145147
implementation: []
146148
references:
147149
samm2:
148-
- I-SB-1-A
150+
- I-SB-B-1
151+
- D-TA-A-1
149152
iso27001-2017:
150153
- 8.1
151154
- 8.2
@@ -183,7 +186,7 @@ Build and Deployment:
183186
- Pinning of artifacts
184187
references:
185188
samm2:
186-
- I-SB-1-A
189+
- I-SB-A-1
187190
iso27001-2017:
188191
- 14.2.6
189192
iso27001-2022:
@@ -210,7 +213,7 @@ Build and Deployment:
210213
- Defined build process
211214
references:
212215
samm2:
213-
- I-SB-2-A
216+
- I-SB-A-2
214217
iso27001-2017:
215218
- 14.2.6
216219
iso27001-2022:

src/assets/YAML/default/BuildAndDeployment/Deployment.yaml

Lines changed: 18 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ Build and Deployment:
2020
- Smoke Test
2121
references:
2222
samm2:
23-
- I-SD-2-A
23+
- I-SD-A-3
2424
iso27001-2017:
2525
- 17.2.1 # Availability of information processing facilities
2626
- 12.1.1 # Documented operational procedures
@@ -59,7 +59,7 @@ Build and Deployment:
5959
level: 2
6060
references:
6161
samm2:
62-
- O-OM-2-B
62+
- O-OM-B-2
6363
iso27001-2017:
6464
- 11.2.7
6565
iso27001-2022:
@@ -89,7 +89,7 @@ Build and Deployment:
8989
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/docker
9090
references:
9191
samm2:
92-
- I-SD-1-A
92+
- I-SD-A-1
9393
iso27001-2017:
9494
- 12.1.1
9595
- 14.2.2
@@ -120,7 +120,7 @@ Build and Deployment:
120120
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/hashicorp-vault
121121
references:
122122
samm2:
123-
- I-SD-1-B
123+
- I-SD-B-1
124124
iso27001-2017:
125125
- 9.4.5
126126
- 14.2.6
@@ -154,7 +154,7 @@ Build and Deployment:
154154
- Environment depending configuration parameters (secrets)
155155
references:
156156
samm2:
157-
- I-SD-2-B
157+
- I-SD-B-2
158158
iso27001-2017:
159159
- 14.1.3
160160
- 13.1.3
@@ -196,9 +196,9 @@ Build and Deployment:
196196
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/image-metadata-collector
197197
references:
198198
samm2:
199-
- I-SB-3-B
200-
- I-SB-2-B
201-
- I-SB-1-B
199+
- I-SB-B-3
200+
- I-SB-B-2
201+
- I-SB-B-1
202202
iso27001-2017:
203203
- 8.1
204204
- 8.2
@@ -230,7 +230,8 @@ Build and Deployment:
230230
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/image-metadata-collector
231231
references:
232232
samm2:
233-
- I-SB-1-B
233+
- I-SB-B-1
234+
- D-TA-B-1
234235
iso27001-2017:
235236
- 8.1
236237
- 8.2
@@ -261,7 +262,8 @@ Build and Deployment:
261262
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/image-metadata-collector
262263
references:
263264
samm2:
264-
- I-SB-1-B
265+
- I-SB-B-1
266+
- D-TA-B-1
265267
iso27001-2017:
266268
- 8.1
267269
- 8.2
@@ -288,7 +290,8 @@ Build and Deployment:
288290
- Defined deployment process
289291
references:
290292
samm2:
291-
- I-SD-1-A
293+
- I-SD-A-2
294+
- I-SD-A-3
292295
iso27001-2017:
293296
- 12.5.1
294297
- 14.2.2
@@ -320,7 +323,8 @@ Build and Deployment:
320323
- Defined build process
321324
references:
322325
samm2:
323-
- I-SD-2-A
326+
- I-SD-A-2
327+
- I-SD-A-3
324328
iso27001-2017:
325329
- 14.3.1
326330
- 14.2.8
@@ -353,7 +357,7 @@ Build and Deployment:
353357
- Same artifact for environments
354358
references:
355359
samm2:
356-
- I-SD-2-A
360+
- I-SD-A-2
357361
iso27001-2017:
358362
- 14.3.1
359363
- 14.2.8
@@ -387,7 +391,7 @@ Build and Deployment:
387391
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/packj
388392
references:
389393
samm2:
390-
- O-EM-1-A
394+
- O-EM-A-1
391395
iso27001-2017:
392396
- Not explicitly covered by ISO 27001 - too specific
393397
- 14.2.1

src/assets/YAML/default/BuildAndDeployment/PatchManagement.yaml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ Build and Deployment:
1717
implementation: []
1818
references:
1919
samm2:
20-
- O-EM-1-B
20+
- O-EM-B-1
2121
iso27001-2017:
2222
- 12.6.1
2323
- 12.5.1
@@ -58,7 +58,7 @@ Build and Deployment:
5858
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/renovate
5959
references:
6060
samm2:
61-
- O-EM-1-B
61+
- O-EM-B-1
6262
iso27001-2017:
6363
- 12.6.1
6464
- 14.2.5
@@ -93,7 +93,7 @@ Build and Deployment:
9393
implementation: []
9494
references:
9595
samm2:
96-
- O-EM-1-B
96+
- O-EM-B-2
9797
iso27001-2017:
9898
- 12.6.1
9999
iso27001-2022:
@@ -129,7 +129,7 @@ Build and Deployment:
129129
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/distroless-usage
130130
references:
131131
samm2:
132-
- I-SB-2
132+
- I-SB-B-2
133133
iso27001-2017:
134134
- hardening is missing in ISO 27001
135135
- 14.2.1
@@ -169,7 +169,7 @@ Build and Deployment:
169169
implementation: []
170170
references:
171171
samm2:
172-
- O-EM-1-B
172+
- O-EM-B-1
173173
iso27001-2017:
174174
- 12.6.1
175175
iso27001-2022:
@@ -204,7 +204,7 @@ Build and Deployment:
204204
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/sample-concept-1
205205
references:
206206
samm2:
207-
- O-EM-2-B
207+
- O-EM-B-2
208208
iso27001-2017:
209209
- 12.6.1
210210
iso27001-2022:
@@ -237,7 +237,7 @@ Build and Deployment:
237237
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/renovate
238238
references:
239239
samm2:
240-
- O-EM-2-B
240+
- O-EM-B-2
241241
iso27001-2017:
242242
- 12.6.1
243243
iso27001-2022:

src/assets/YAML/default/CultureAndOrganization/Design.yaml

Lines changed: 10 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,7 @@ Culture and Organization:
4040
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/threat-matrix-for-storage
4141
references:
4242
samm2:
43-
- D-TA-2-B
43+
- D-TA-B-2
4444
iso27001-2017:
4545
- Not explicitly covered by ISO 27001
4646
- May be part of risk assessment
@@ -71,7 +71,8 @@ Culture and Organization:
7171
implementation: []
7272
references:
7373
samm2:
74-
- D-TA-2-B
74+
- D-TA-B-1
75+
- D-TA-A-2
7576
iso27001-2017:
7677
- Not explicitly covered by ISO 27001
7778
- May be part of risk assessment
@@ -151,7 +152,7 @@ Culture and Organization:
151152
Source: OWASP Project Integration Project
152153
references:
153154
samm2:
154-
- D-TA-2-B
155+
- D-TA-B-2
155156
iso27001-2017:
156157
- Not explicitly covered by ISO 27001
157158
- May be part of risk assessment
@@ -184,7 +185,8 @@ Culture and Organization:
184185
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/don-t-forget-evil-user-stories
185186
references:
186187
samm2:
187-
- D-TA-2-B
188+
- D-TA-B-2
189+
- V-RT-B-2
188190
iso27001-2017:
189191
- Not explicitly covered by ISO 27001
190192
- May be part of project management
@@ -219,7 +221,7 @@ Culture and Organization:
219221
- Creation of threat modeling processes and standards
220222
references:
221223
samm2:
222-
- D-TA-2-B
224+
- D-TA-B-2
223225
iso27001-2017:
224226
- Not explicitly covered by ISO 27001
225227
- May be part of project management
@@ -256,7 +258,8 @@ Culture and Organization:
256258
- Conduction of simple threat modeling on technical level
257259
references:
258260
samm2:
259-
- D-TA-3-B
261+
- D-TA-B-3
262+
- D-TA-B-2
260263
iso27001-2017:
261264
- Not explicitly covered by ISO 27001
262265
- May be part of risk assessment
@@ -288,7 +291,7 @@ Culture and Organization:
288291
implementation: []
289292
references:
290293
samm2:
291-
- G-PS-2
294+
- G-SM-A-2
292295
iso27001-2017:
293296
- 5.1.1
294297
- 7.2.1

0 commit comments

Comments
 (0)