File tree Expand file tree Collapse file tree 8 files changed +400
-182
lines changed
Expand file tree Collapse file tree 8 files changed +400
-182
lines changed Original file line number Diff line number Diff line change @@ -105,14 +105,16 @@ Build and Deployment:
105105 resources : 2
106106 usefulness : 3
107107 level : 2
108+ tags :
109+ - inventory
108110 implementation :
109111 - $ref : src/assets/YAML/default/implementations.yaml#/implementations/signing-of-containers
110112 - $ref : src/assets/YAML/default/implementations.yaml#/implementations/immutable-images
111113 dependsOn :
112114 - Defined build process
113115 references :
114116 samm2 :
115- - I-SB-1-A
117+ - I-SB-1-B
116118 iso27001-2017 :
117119 - 14.2.6
118120 iso27001-2022 :
@@ -145,7 +147,8 @@ Build and Deployment:
145147 implementation : []
146148 references :
147149 samm2 :
148- - I-SB-1-A
150+ - I-SB-1-B
151+ - D-TA-1-A
149152 iso27001-2017 :
150153 - 8.1
151154 - 8.2
Original file line number Diff line number Diff line change @@ -20,7 +20,7 @@ Build and Deployment:
2020 - Smoke Test
2121 references :
2222 samm2 :
23- - I-SD-2 -A
23+ - I-SD-3 -A
2424 iso27001-2017 :
2525 - 17.2.1 # Availability of information processing facilities
2626 - 12.1.1 # Documented operational procedures
@@ -231,6 +231,7 @@ Build and Deployment:
231231 references :
232232 samm2 :
233233 - I-SB-1-B
234+ - D-TA-1-B
234235 iso27001-2017 :
235236 - 8.1
236237 - 8.2
@@ -262,6 +263,7 @@ Build and Deployment:
262263 references :
263264 samm2 :
264265 - I-SB-1-B
266+ - D-TA-1-B
265267 iso27001-2017 :
266268 - 8.1
267269 - 8.2
@@ -288,7 +290,8 @@ Build and Deployment:
288290 - Defined deployment process
289291 references :
290292 samm2 :
291- - I-SD-1-A
293+ - I-SD-2-A
294+ - I-SD-3-A
292295 iso27001-2017 :
293296 - 12.5.1
294297 - 14.2.2
@@ -321,6 +324,7 @@ Build and Deployment:
321324 references :
322325 samm2 :
323326 - I-SD-2-A
327+ - I-SD-3-A
324328 iso27001-2017 :
325329 - 14.3.1
326330 - 14.2.8
Original file line number Diff line number Diff line change @@ -93,7 +93,7 @@ Build and Deployment:
9393 implementation : []
9494 references :
9595 samm2 :
96- - O-EM-1 -B
96+ - O-EM-2 -B
9797 iso27001-2017 :
9898 - 12.6.1
9999 iso27001-2022 :
Original file line number Diff line number Diff line change @@ -71,7 +71,8 @@ Culture and Organization:
7171 implementation : []
7272 references :
7373 samm2 :
74- - D-TA-2-B
74+ - D-TA-1-B
75+ - D-TA-2-A
7576 iso27001-2017 :
7677 - Not explicitly covered by ISO 27001
7778 - May be part of risk assessment
@@ -185,6 +186,7 @@ Culture and Organization:
185186 references :
186187 samm2 :
187188 - D-TA-2-B
189+ - V-RT-B-2
188190 iso27001-2017 :
189191 - Not explicitly covered by ISO 27001
190192 - May be part of project management
@@ -257,6 +259,7 @@ Culture and Organization:
257259 references :
258260 samm2 :
259261 - D-TA-3-B
262+ - D-TA-2-B
260263 iso27001-2017 :
261264 - Not explicitly covered by ISO 27001
262265 - May be part of risk assessment
@@ -288,7 +291,7 @@ Culture and Organization:
288291 implementation : []
289292 references :
290293 samm2 :
291- - G-PS-2
294+ - G-SM-2-A
292295 iso27001-2017 :
293296 - 5.1.1
294297 - 7.2.1
Original file line number Diff line number Diff line change @@ -143,6 +143,7 @@ Culture and Organization:
143143 references :
144144 samm2 :
145145 - G-EG-2-A
146+ - G-EG-2-B
146147 iso27001-2017 :
147148 - Mutual review of source code is not explicitly required in ISO 27001 may
148149 be
@@ -201,6 +202,7 @@ Culture and Organization:
201202 references :
202203 samm2 :
203204 - G-EG-2-A
205+ - O-IM-B-2
204206 iso27001-2017 :
205207 - War games are not explicitly required in ISO 27001 may be
206208 - 7.2.2
@@ -301,7 +303,7 @@ Culture and Organization:
301303 - $ref : src/assets/YAML/default/implementations.yaml#/implementations/owasp-cheatsheet-series
302304 references :
303305 samm2 :
304- - G-EG-3 -A
306+ - G-EG-2 -A
305307 iso27001-2017 :
306308 - 7.2.2
307309 iso27001-2022 :
@@ -424,6 +426,7 @@ Culture and Organization:
424426 references :
425427 samm2 :
426428 - G-EG-1-A
429+ - G-EG-1-B
427430 iso27001-2017 :
428431 - security consulting is missing in ISO 27001 may be
429432 - 6.1.1
@@ -453,6 +456,7 @@ Culture and Organization:
453456 implementation : []
454457 references :
455458 samm2 :
459+ - G-EG-3-B
456460 - O-IM-3-B
457461 iso27001-2017 :
458462 - 16.1.6
@@ -493,7 +497,7 @@ Culture and Organization:
493497 - $ref : src/assets/YAML/default/implementations.yaml#/implementations/damn-vulnerable-web
494498 references :
495499 samm2 :
496- - G-EG-1 -A
500+ - G-EG-2 -A
497501 iso27001-2017 :
498502 - 7.2.2
499503 iso27001-2022 :
Original file line number Diff line number Diff line change @@ -196,7 +196,7 @@ Test and Verification:
196196 usefulness : 3
197197 level : 2
198198 dependsOn :
199- - uuid : c1acc8af-312e-4503-a817-a26220c993a0 # Simple false positive treatment
199+ - uuid:c1acc8af-312e-4503-a817-a26220c993a0 # Simple false positive treatment
200200 implementation :
201201 - $ref : src/assets/YAML/default/implementations.yaml#/implementations/owasp-defectdojo
202202 - $ref : src/assets/YAML/default/implementations.yaml#/implementations/purify
@@ -341,8 +341,8 @@ Test and Verification:
341341 usefulness : 4
342342 level : 3
343343 dependsOn :
344- - uuid : 8f2b4d5a-3c1e-4b7a-9d8f-2e6c4a1b5d7f # Artifact-based false positive treatment
345- - uuid : 85ba5623-84be-4219-8892-808837be582d # Usage of a vulnerability management system
344+ - uuid:8f2b4d5a-3c1e-4b7a-9d8f-2e6c4a1b5d7f # Artifact-based false positive treatment
345+ - uuid:85ba5623-84be-4219-8892-808837be582d # Usage of a vulnerability management system
346346 implementation :
347347 references :
348348 samm2 :
Original file line number Diff line number Diff line change @@ -179,7 +179,7 @@ implementations:
179179 url : https://www.owasp.org/index.php/Agile_Software_Development
180180 description :
181181 " [Do not Forget EVIL User Stories](https://www.owasp.org/index.php/Agile_Software_Development:_Don%27t_Forget_EVIL_User_Stories)\
182- \ and [Practical Security Stories and Security Tasks for Agile Development Environments](http ://safecode.org/publication/SAFECode_Agile_Dev_Security0712.pdf)"
182+ \ and [Practical Security Stories and Security Tasks for Agile Development Environments](https ://safecode.org/publication/SAFECode_Agile_Dev_Security0712.pdf)"
183183 libyear :
184184 uuid : 2fff917f-205e-4eab-2e0e-1fab8c04bf33
185185 name : libyear
@@ -253,7 +253,7 @@ implementations:
253253 uuid : edaec98d-dac7-4dfd-8ab3-42c471d5b9ff
254254 name : CIS Kubernetes Bench for Security
255255 tags : []
256- url : https://www.cisecurity.org/cis-benchmarks/
256+ url : https://www.cisecurity.org/cis-benchmarks/#
257257 cis-docker-bench-for :
258258 uuid : 4dd23c4a-5a7e-4917-82cf-d00e0f04482f
259259 name : CIS Docker Bench for Security
@@ -359,7 +359,7 @@ implementations:
359359 uuid : e76a395a-8d6a-4e25-a175-6cf25409b755
360360 name : Smartcard
361361 tags : []
362- url : https://d3fend.mitre.org/technique/d3f:Multi-factorAuthentication/
362+ url : https://d3fend.mitre.org/technique/d3f:Multi-factorAuthentication/#
363363 yubikey :
364364 uuid : d5981117-9bc2-45ed-b4a4-383135dc13d8
365365 name : YubiKey
You can’t perform that action at this time.
0 commit comments