security-baseline icon indicating copy to clipboard operation
security-baseline copied to clipboard

Revisit Control Objectives to separate from assessment criteria

Open evankanderson opened this issue 1 month ago • 1 comments

From the 2025-11-25 meeting:

@eddie-knight would like control objectives to focus more on objectives and less on defining requirements. Example:

"Ensure that there is no MITM modification of assets distributed by the project" (proposed)

vs

"All official project URIs MUST be delivered using encrypted channels" (current)

evankanderson avatar Nov 25 '25 21:11 evankanderson

Thanks for tracking this for me! I'll work to re-draft all of the objective statements before the end of the month.

eddie-knight avatar Dec 01 '25 15:12 eddie-knight