@@ -388,7 +388,7 @@ Build and Deployment:
388
388
usefulness : 4
389
389
level : 1
390
390
dependsOn :
391
- - Continuous Integration
391
+ - Defined build process
392
392
implementation :
393
393
- uuid : b4bfead3-5fb6-4dd0-ba44-5da713bd22e4
394
394
name : CI/CD tools
@@ -564,7 +564,7 @@ Build and Deployment:
564
564
exists (gathered manually or automatically).
565
565
dependsOn :
566
566
- Defined deployment process
567
- - 2a44b708-734f-4463-b0cb-86dc46344b2f
567
+ - Inventory of production components
568
568
difficultyOfImplementation :
569
569
knowledge : 2
570
570
time : 2
@@ -690,7 +690,7 @@ Build and Deployment:
690
690
measure : A documented inventory of dependencies used in artifacts like container
691
691
images and containers exists.
692
692
dependsOn :
693
- - 83057028-0b77-4d2e-8135-40969768ae88
693
+ - Inventory of production artifacts
694
694
- SBOM of components
695
695
difficultyOfImplementation :
696
696
knowledge : 2
@@ -2492,7 +2492,7 @@ Culture and Organization:
2492
2492
usefulness : 3
2493
2493
level : 2
2494
2494
dependsOn :
2495
- - 2a44b708-734f-4463-b0cb-86dc46344b2f
2495
+ - Inventory of production components
2496
2496
implementation :
2497
2497
- uuid : 227d786c-dd76-4b81-b0b2-62389ab8f0fb
2498
2498
name : OWASP DefectDojo
@@ -3100,7 +3100,7 @@ Implementation:
3100
3100
usefulness : 3
3101
3101
level : 3
3102
3102
dependsOn :
3103
- - e7598ac4-b082-4e56-b7df-e2c6b426a5e2
3103
+ - Require a PR before merging
3104
3104
implementation :
3105
3105
- uuid : b1b88bc5-5a22-4888-a27b-acce3d9fe29a
3106
3106
name : Improve code quality with branch policies
@@ -3146,7 +3146,7 @@ Implementation:
3146
3146
usefulness : 4
3147
3147
level : 3
3148
3148
dependsOn :
3149
- - e7598ac4-b082-4e56-b7df-e2c6b426a5e2
3149
+ - Require a PR before merging
3150
3150
implementation :
3151
3151
- uuid : b1b88bc5-5a22-4888-a27b-acce3d9fe29a
3152
3152
name : Improve code quality with branch policies
@@ -3288,7 +3288,7 @@ Implementation:
3288
3288
usefulness : 4
3289
3289
level : 3
3290
3290
dependsOn :
3291
- - e7598ac4-b082-4e56-b7df-e2c6b426a5e2
3291
+ - Require a PR before merging
3292
3292
implementation :
3293
3293
- uuid : b1b88bc5-5a22-4888-a27b-acce3d9fe29a
3294
3294
name : Improve code quality with branch policies
@@ -5489,7 +5489,7 @@ Information Gathering:
5489
5489
usefulness : 3
5490
5490
level : 2
5491
5491
dependsOn :
5492
- - 8ae0b92c-10e0-4602-ba22-7524d6aed488
5492
+ - Automated PRs for patches
5493
5493
implementation : []
5494
5494
references :
5495
5495
samm2 :
@@ -5526,8 +5526,8 @@ Information Gathering:
5526
5526
usefulness : 3
5527
5527
level : 4
5528
5528
dependsOn :
5529
- - 86d490b9-d798-4a5b-a011-ab9688014c46
5530
- - 8ae0b92c-10e0-4602-ba22-7524d6aed488
5529
+ - Patching mean time to resolution via PR
5530
+ - Automated PRs for patches
5531
5531
implementation : []
5532
5532
references :
5533
5533
samm2 :
@@ -5831,8 +5831,8 @@ Test and Verification:
5831
5831
- The number of network hops required to reach the asset (recommended)
5832
5832
- Authentication requirements for access (recommended)
5833
5833
dependsOn :
5834
- - 44f2c8a9-4aaa-4c72-942d-63f78b89f385
5835
- - 2a44b708-734f-4463-b0cb-86dc46344b2f
5834
+ - Treatment of defects with severity high or higher
5835
+ - Inventory of production components
5836
5836
implementation : ~
5837
5837
references :
5838
5838
samm2 :
@@ -6322,9 +6322,9 @@ Test and Verification:
6322
6322
resources : 2
6323
6323
usefulness : 2
6324
6324
dependsOn :
6325
- - f2f0f274-c1a0-4501-92fe-7fc4452bc8ad
6326
- - 6217fe11-5ed7-4cf4-9de4-555bcfa6fe87
6327
- - 185d5a74-19dc-4422-be07-44ea35226783
6325
+ - Exploit likelihood estimation
6326
+ - Each team has a security champion
6327
+ - Office Hours
6328
6328
level : 3
6329
6329
description : " For known vulnerabilities a processes to estimate the exploit
6330
6330
ability of a vulnerability is recommended.\n\n To implement a security culture
@@ -6946,7 +6946,7 @@ Test and Verification:
6946
6946
tags : []
6947
6947
url : https://github.com/controlplaneio/netassert
6948
6948
dependsOn :
6949
- - Segmented networks for virtual environments
6949
+ - Isolated networks for virtual environments
6950
6950
references :
6951
6951
samm2 :
6952
6952
- V-ST-2-A
@@ -7104,7 +7104,7 @@ Test and Verification:
7104
7104
- https://www.opencre.org/rest/v1/standard/DevSecOps+Maturity+Model+(DSOMM)/Static
7105
7105
depth for applications/017d9e26-42b5-49a4-b945-9f59b308fb99
7106
7106
dependsOn :
7107
- - 2a44b708-734f-4463-b0cb-86dc46344b2f
7107
+ - Inventory of production components
7108
7108
tags :
7109
7109
- none
7110
7110
teamsImplemented :
@@ -7199,7 +7199,7 @@ Test and Verification:
7199
7199
usefulness : 4
7200
7200
level : 3
7201
7201
dependsOn :
7202
- - d918cd44-a972-43e9-a974-eff3f4a5dcfe
7202
+ - Software Composition Analysis (server side)
7203
7203
implementation :
7204
7204
- uuid : aa507341-9531-42cd-95cf-d7b51af47086
7205
7205
name : Known Exploited Vulnerabilities
@@ -7303,8 +7303,8 @@ Test and Verification:
7303
7303
level : 3
7304
7304
dependsOn :
7305
7305
- Defined build process
7306
- - 2a44b708-734f-4463-b0cb-86dc46344b2f
7307
- - f2f0f274-c1a0-4501-92fe-7fc4452bc8ad
7306
+ - Inventory of production components
7307
+ - Exploit likelihood estimation
7308
7308
implementation :
7309
7309
- uuid : aa54a82c-d628-4d42-9bc8-1aa269cd91c7
7310
7310
name : retire.js
@@ -7369,7 +7369,7 @@ Test and Verification:
7369
7369
level : 2
7370
7370
dependsOn :
7371
7371
- Defined build process
7372
- - 2a44b708-734f-4463-b0cb-86dc46344b2f
7372
+ - Inventory of production components
7373
7373
implementation :
7374
7374
- uuid : 06334caf-8be6-487a-96b1-d41c7ed5f207
7375
7375
name : OWASP Dependency Check
@@ -7441,7 +7441,7 @@ Test and Verification:
7441
7441
dependsOn :
7442
7442
- Static analysis for important client side components
7443
7443
- Static analysis for important server side components
7444
- - 2a44b708-734f-4463-b0cb-86dc46344b2f
7444
+ - Inventory of production components
7445
7445
implementation : []
7446
7446
references :
7447
7447
samm2 :
@@ -7505,7 +7505,7 @@ Test and Verification:
7505
7505
dependsOn :
7506
7506
- Static analysis for important client side components
7507
7507
- Static analysis for important server side components
7508
- - 2a44b708-734f-4463-b0cb-86dc46344b2f
7508
+ - Inventory of production components
7509
7509
references :
7510
7510
samm2 :
7511
7511
- V-ST-2-A
@@ -7572,7 +7572,7 @@ Test and Verification:
7572
7572
- sast
7573
7573
dependsOn :
7574
7574
- Defined build process
7575
- - 2a44b708-734f-4463-b0cb-86dc46344b2f
7575
+ - Inventory of production components
7576
7576
references :
7577
7577
samm2 :
7578
7578
- V-ST-2-A
@@ -7634,7 +7634,7 @@ Test and Verification:
7634
7634
- sast
7635
7635
dependsOn :
7636
7636
- Defined build process
7637
- - 2a44b708-734f-4463-b0cb-86dc46344b2f
7637
+ - Inventory of production components
7638
7638
references :
7639
7639
samm2 :
7640
7640
- V-ST-2-A
0 commit comments