Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Map controls to various frameworks #233

Open
pxp928 opened this issue Jun 1, 2022 · 2 comments
Open

Map controls to various frameworks #233

pxp928 opened this issue Jun 1, 2022 · 2 comments
Labels
enhancement New feature or request

Comments

@pxp928
Copy link
Member

pxp928 commented Jun 1, 2022

Current Behavior

Currently there is no mapping between the FRSCA and a specific framework such as SSDF. What controls are met by FRSCA and how can they be presented as evidence to an auditor

Expected Behavior

Create mapping for various relevant frameworks to FRSCA

@pxp928 pxp928 added the enhancement New feature or request label Jun 1, 2022
@JonZeolla
Copy link

JonZeolla commented Jun 2, 2022

@pxp928 What I was thinking was that FRSCA should standardize how evidence is stored and made available, with a goal of providing stable interfaces to automated assessment tools. This would then allow the mapping of a specific pipeline to arbitrary frameworks to happen outside of the FRSCA project itself - for instance, cncf/tag-security#845.

I think this is also related to #147. The evidence could leverage the Assessment Results Model which would point to specific Reviewed Controls, or similar.

@xee5ch
Copy link

xee5ch commented Jun 3, 2022

Howdy, member of the wider OSCAL community here. I see NIST has SSDF in Excel, but not OSCAL. I am trying to explore buidling a SSDF OSCAL catalog in oscal-club/examples#2. In terms of order of operations, that is likely super helpful to do before using SSDF as a basis for assessment plans and related assessments results in a structured way with observations. So maybe related to this and #147. Not sure if this work would be helpful to you all.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants