Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Review current approaches to defining rules to confirm minimal data fields in rules-related models #1391

Open
3 tasks
Tracked by #1058
david-waltermire opened this issue Jul 28, 2022 · 6 comments
Labels
Aged A label for issues older than 2023-01-01

Comments

@david-waltermire
Copy link
Contributor

david-waltermire commented Jul 28, 2022

Review current approaches for security testing processes and tools, confirm we represent MVP data points for what a rule practically needs to encode.

Ideally, we would like to review the mechanics and characteristics of the different kinds of security testing tools.

@david-waltermire david-waltermire changed the title Review current approaches for security testing processes and tools, confirm we represent MVP data points for what a rule practically needs to encode Review current approaches to defining rules to confirm minimal data fields in rules-related models Jul 28, 2022
@aj-stein-nist
Copy link
Contributor

aj-stein-nist commented Jul 28, 2022

@david-waltermire-nist, I know this spike is about tool review. I am going to un-assign #1160 from this issue because the "update models' Metaschema and make content examples" is what we ended up doing towards the tail end of #1339 and is in flight, #1364.

@aj-stein-nist
Copy link
Contributor

Dave and I down-scoped which content examples we will look at for the two categories and sync back up to discuss my impressions in our next pairing session. Looking at the OCPv4 SCAP guides and OVAL profiles. Will prefer the CSA metrics over the MEDINA ones out of the interest of time if the latter are not currently public. The cloud-based API one is still TBD.

@aj-stein-nist
Copy link
Contributor

Added some sample data and will continue draft notes here until we are ready to publish in this issue, itemize next steps, and close this issue out.

https://hackmd.io/I_DdJG2RRtKuj39cvss1WA

@aj-stein-nist aj-stein-nist moved this from Todo to In Progress in NIST OSCAL Work Board Aug 4, 2022
@aj-stein-nist
Copy link
Contributor

We met today and planned to continue with this work in an afternoon pairing session tomorrow.

@aj-stein-nist aj-stein-nist linked a pull request Aug 31, 2022 that will close this issue
9 tasks
@aj-stein-nist aj-stein-nist moved this from In Progress to Todo in NIST OSCAL Work Board Oct 14, 2022
@aj-stein-nist
Copy link
Contributor

I am moving this to Sprint 61.

@aj-stein-nist
Copy link
Contributor

Not completed last sprint and not in scope for Sprint 63, moving to the backlog.

@aj-stein-nist aj-stein-nist removed their assignment Apr 6, 2023
@aj-stein-nist aj-stein-nist removed this from the v1.1.0 milestone Jul 27, 2023
@aj-stein-nist aj-stein-nist moved this from Todo to Needs Refinement in NIST OSCAL Work Board Sep 26, 2023
@Compton-US Compton-US added the Aged A label for issues older than 2023-01-01 label Nov 2, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Aged A label for issues older than 2023-01-01
Projects
Status: Needs Refinement
Development

Successfully merging a pull request may close this issue.

3 participants