OSCAL icon indicating copy to clipboard operation
OSCAL copied to clipboard

Review current approaches to defining rules to confirm minimal data fields in rules-related models

Open david-waltermire opened this issue 2 years ago • 4 comments

Review current approaches for security testing processes and tools, confirm we represent MVP data points for what a rule practically needs to encode.

Ideally, we would like to review the mechanics and characteristics of the different kinds of security testing tools.

david-waltermire avatar Jul 28 '22 17:07 david-waltermire

@david-waltermire-nist, I know this spike is about tool review. I am going to un-assign #1160 from this issue because the "update models' Metaschema and make content examples" is what we ended up doing towards the tail end of #1339 and is in flight, #1364.

aj-stein-nist avatar Jul 28 '22 18:07 aj-stein-nist

Dave and I down-scoped which content examples we will look at for the two categories and sync back up to discuss my impressions in our next pairing session. Looking at the OCPv4 SCAP guides and OVAL profiles. Will prefer the CSA metrics over the MEDINA ones out of the interest of time if the latter are not currently public. The cloud-based API one is still TBD.

aj-stein-nist avatar Aug 02 '22 18:08 aj-stein-nist

Added some sample data and will continue draft notes here until we are ready to publish in this issue, itemize next steps, and close this issue out.

https://hackmd.io/I_DdJG2RRtKuj39cvss1WA

aj-stein-nist avatar Aug 03 '22 09:08 aj-stein-nist

We met today and planned to continue with this work in an afternoon pairing session tomorrow.

aj-stein-nist avatar Aug 15 '22 17:08 aj-stein-nist

I am moving this to Sprint 61.

aj-stein-nist avatar Dec 05 '22 22:12 aj-stein-nist

Not completed last sprint and not in scope for Sprint 63, moving to the backlog.

aj-stein-nist avatar Feb 06 '23 16:02 aj-stein-nist