security-baseline icon indicating copy to clipboard operation
security-baseline copied to clipboard

Add threats to catalog

Open funnelfiasco opened this issue 2 months ago • 2 comments

Similar to the FINOS Common Cloud Controls, we should add a catalog of threats that we tie Baseline controls to. From there, we can validate the applicability of controls, including controls that are missing, extraneous, or misaligned.

(Assigning to Eddie for overall coordination, but there's a lot of work to share among the team)

funnelfiasco avatar Oct 14 '25 19:10 funnelfiasco

love the idea. patches welcome to get this rolling. i'll tinker with it once I get the new regs mapped and proposed for merge

SecurityCRob avatar Nov 17 '25 17:11 SecurityCRob

Met with @funnelfiasco and @evankanderson last week to make sure that everyone is familiar with how Gemara layer2 threats are cataloged.

eddie-knight avatar Nov 17 '25 17:11 eddie-knight