diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index 9092663..cc64f89 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -53,15 +53,21 @@ jobs: file: Dockerfile platforms: linux/amd64,linux/arm64 tags: wurstbrot/dsomm-yaml-generation:${{ steps.get-version.outputs.version }},wurstbrot/dsomm-yaml-generation:latest - - name: Extract generated.yaml + build-args: | + DSOMM_VERSION=${{ steps.get-version.outputs.version }} + GITHUB_REPOSITORY=${{ github.repository }} + - name: Extract generated files from docker image run: | docker run -d --name=yaml --entrypoint="/bin/sleep" wurstbrot/dsomm-yaml-generation:${{ steps.get-version.outputs.version }} 60 - docker cp yaml:/var/www/html/src/assets/YAML/generated/generated.yaml src/assets/YAML/generated/generated.yaml - # Commit all changed files back to the repository - - uses: planetscale/ghcommit-action@v0.1.6 + docker cp yaml:/var/www/html/generated/model.yaml generated/model.yaml + docker cp yaml:/var/www/html/generated/dependency-tree.md generated/dependency-tree.md + - name: Force add ignored file + run: git add -f generated/model.yaml generated/dependency-tree.md + - name: Commit all changed files back to the repository + uses: planetscale/ghcommit-action@v0.1.6 with: - commit_message: "🤖 fmt" + commit_message: "🤖 push ${{ steps.get-version.outputs.version }}" repo: ${{ github.repository }} branch: ${{ github.head_ref || github.ref_name }} env: - GITHUB_TOKEN: ${{secrets.ACCESS_TOKEN}} \ No newline at end of file + GITHUB_TOKEN: ${{secrets.ACCESS_TOKEN}} diff --git a/.gitignore b/.gitignore index 70387d7..b4a1f7d 100644 --- a/.gitignore +++ b/.gitignore @@ -43,5 +43,10 @@ testem.log .DS_Store Thumbs.db /yaml-generation/vendor/ -# Generated YAML + + +# Generated /src/assets/YAML/generated/generated.yaml +/generated/model.yaml +/generated/dependency-tree.md +url-test-results.txt \ No newline at end of file diff --git a/.releaserc.json b/.releaserc.json index 759d39b..8ae6300 100644 --- a/.releaserc.json +++ b/.releaserc.json @@ -4,11 +4,7 @@ [ "@semantic-release/commit-analyzer", { - "preset": "angular", - "releaseRules": [ - {"breaking": true, "release": "minor"}, - {"tag": "Breaking", "release": "minor"} - ] + "preset": "angular" } ], "@semantic-release/release-notes-generator", diff --git a/CHANGELOG.md b/CHANGELOG.md index 23d1c69..61e7414 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,210 @@ +## [4.3.1](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v4.3.0...v4.3.1) (2026-04-27) + + +### Bug Fixes + +* correct typo in blue-green-deployment implementation key ([dc6af16](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/dc6af16d6aa497563c2f27110ed4308c20c363d7)), closes [#76](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/issues/76) + +# [4.3.0](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v4.2.0...v4.3.0) (2026-04-27) + + +### Features + +* add Canary deployment activity to Deployment dimension ([f889bca](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/f889bca3e8485a9bc67302d42b41d4ba4bbf1b23)) + +# [4.2.0](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v4.1.0...v4.2.0) (2026-01-28) + + +### Features + +* new version ([b971cb0](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/b971cb0d326ffe2630e932a915ff5288771dabb5)) + +# [4.1.0](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v4.0.0...v4.1.0) (2026-01-15) + + +### Features + +* trigger release ([e83e71f](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/e83e71f62e324abcbc4b1911af56e6ef5543d3af)) + +# [4.0.0](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.25.0...v1.26.0) (2026-01-05) + + +* enhance version number to 4 + + +### Bug Fixes + +* generated folder ([fd323eb](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/fd323ebfd1ef5483006ae2577e8d5742607aa7eb)) + +# [1.26.0](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.25.0...v1.26.0) (2026-01-05) + + +* fix\!: build ([b9eef67](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/b9eef67f450590e89d7b8763e453a712fb954075)) + + +### Bug Fixes + +* generated folder ([fd323eb](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/fd323ebfd1ef5483006ae2577e8d5742607aa7eb)) + + +### BREAKING CHANGES + +* Updated Docker build process and YAML generation structure + +🤖 Generated with [Claude Code](https://claude.ai/code) + +Co-Authored-By: Claude + +# [1.25.0](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.24.0...v1.25.0) (2025-12-15) + + +* feat!: new structure ([2766a0a](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/2766a0ac2ced849735e5d63f351bc85d5137a0af)) + + +### BREAKING CHANGES + +* generated moved to root with model.yaml instead of generated.yaml + +# [1.24.0](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.23.1...v1.24.0) (2025-12-15) + + +* feat!: new structure ([4fc201f](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/4fc201f9e7e6c8210670cad65d37d8b3d82b9c9c)) + + +### BREAKING CHANGES + +* generated moved to root with model.yaml instead of generated.yaml + +### Bug Fixes + +* Modify YAML generation to include version placeholder ([37958b5](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/37958b54e20b80b4401980a28b07616c964f35d5)) + +## [1.20.1](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.20.0...v1.20.1) (2025-11-24) + + +### Bug Fixes + +* Sort activities by level, within each sub-dimension ([e2aeba7](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/e2aeba77089d21f0e7c5ce5bf6612903efc1938f)) + +# [1.20.0](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.19.0...v1.20.0) (2025-11-18) + + +### Features + +* adopt changes to bat file ([796e1d2](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/796e1d27f682eb27b6de5c4b6c5969119caa5a2e)) +* install dep always ([0761ee3](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/0761ee35da67f843c68cbf413a04d365482ab879)) + +# [1.19.0](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.18.0...v1.19.0) (2025-11-17) + + +### Features + +* Improved start script ([18d6205](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/18d6205beb02b5c809b95dc15a76c9bcb803eb3d)) + +# [1.18.0](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.17.0...v1.18.0) (2025-11-06) + + +### Features + +* update SAMM mapping based on arams feedback ([532bb72](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/532bb72debcd93f98f07dc7d4b28d799da6e155d)) + +# [1.17.0](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.16.0...v1.17.0) (2025-09-15) + + +### Features + +* adjust mappings for SAMM Secure Build ([471c7fc](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/471c7fce17e02ef63675047a6620beaf5aa96d2c)) + +# [1.16.0](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.15.3...v1.16.0) (2025-06-04) + + +### Features + +* differenciate handling of findings ([b7620b7](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/b7620b7fc2c2306e08787657e1c1cf8af42ccda9)) + +## [1.15.3](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.15.2...v1.15.3) (2025-05-05) + + +### Bug Fixes + +* douplicate uuid ([84927c8](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/84927c85d3409c17a1e762db9fabfde96b7438fe)) + +## [1.15.2](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.15.1...v1.15.2) (2025-03-21) + + +### Bug Fixes + +* app logging does not depends on visualiziation ([ce1f8e0](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/ce1f8e0b519ac5a5967285ae9df6094ae6187f8b)) + +## [1.15.1](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.15.0...v1.15.1) (2025-03-20) + + +### Bug Fixes + +* dependsOn uuid ref ([943f10c](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/943f10cb6693af573d9f792f028e5da79797aa0a)) + +# [1.15.0](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.14.3...v1.15.0) (2025-02-23) + + +### Bug Fixes + +* add meta.yaml via download ([95d8577](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/95d8577b248fb7d56c1e49b7adbd49280255dd14)) + + +### Features + +* enhance descriptions ([2bc6246](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/2bc6246e0adb2db2ceb05ac8d975ac3be2418aeb)) + +# [1.14.0](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.13.0...v1.14.0) (2024-11-07) + + +### Features + +* replace acitivity uuids with activity names ([93aa2e9](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/93aa2e91f732f03d54c273e9bbd53a6e4a8a977b)) + +# [1.13.0](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.12.0...v1.13.0) (2024-10-15) + + +### Features + +* add office hours, vuln management tools, epss ([09b3e8a](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/09b3e8a69936aec7b10dbdb293cbe41fc864edfe)) + +# [1.12.0](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.11.1...v1.12.0) (2024-09-23) + + +### Bug Fixes + +* de-duplicate API design validation ([c6d8242](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/c6d82427ddc272f27afc5d7eee36d91e96face14)) + + +### Features + +* add dependsOn for new patching activities ([72e26ad](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/72e26ad825e4a8458e39e5e93814ebf3bcb9aa71)) +* add includes ([bfb9a99](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/bfb9a993e85cd6c88f79ca314c3cf34e03c1d7be)) +* add uuid: resolution to name ([a2a55b3](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/a2a55b363e2c50ef7af9eaca814ef9137f61835d)) +* add vuln ([70ffec4](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/70ffec4ddb3ddb2112190b5ca30f97e80eef2d64)) +* add vuln ([58e67b7](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/58e67b76c7f4457aac333900bf2430e487a72f2d)) +* enhance source control platform requirements ([e8c57ff](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/e8c57ffb898839c26927d0fc827623935e48c82a)) +* enhance source control platform requirements ([2049504](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/2049504bfab5d284ecba144814260cad10864e60)) + +## [1.11.1](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.11.0...v1.11.1) (2024-07-31) + + +### Bug Fixes + +* formatting ([4b37b45](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/4b37b45c9a5f40c2f739f0e8509b7d07fe736224)) + +# [1.11.0](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.10.1...v1.11.0) (2024-07-19) + + +### Features + +* add auto merge of PRs ([8f9ea61](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/8f9ea61b80c2dab6aea733e35da0ad665618ff44)) +* Add dep track to visualization ([162da73](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/162da7338f4e1ad690637122516fd1873147a9e0)) +* add patching ([7233396](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/7233396cfc8e8a72cc75f53bbe9067101178fdd2)) +* move SCA to level 2 ([11dafa2](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/11dafa271acff38c9c8ae2cca7c3a72022e9df7a)) +* move SCA to level 2 ([51b8cd1](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/51b8cd13daec712acee77ec3710557da95453dda)) + ## [1.10.1](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.10.0...v1.10.1) (2023-11-15) diff --git a/Dockerfile b/Dockerfile index 003460c..acd540f 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,11 @@ -FROM php:apache-buster +FROM php:apache-bullseye + +ARG DSOMM_VERSION=dev +ARG GITHUB_REPOSITORY=DevSecOpsMaturityModel-data + RUN apt-get update && apt-get -y install apt-utils libyaml-dev wget unzip && wget -O composer-setup.php https://getcomposer.org/installer && php composer-setup.php --install-dir=/usr/local/bin --filename=composer COPY yaml-generation /var/www/html/yaml-generation +COPY generated /var/www/html/generated COPY src /var/www/html/src RUN cd /var/www/html/yaml-generation && composer install \ --ignore-platform-reqs \ @@ -9,8 +14,8 @@ RUN cd /var/www/html/yaml-generation && composer install \ --no-scripts \ --prefer-dist - RUN pecl channel-update pecl.php.net && pecl install yaml && docker-php-ext-enable yaml -RUN cd /var/www/html && php yaml-generation/generateDimensions.php -workdir /var/www/html -CMD php yaml-generation/generateDimensions.php \ No newline at end of file +RUN cd /var/www/html && GITHUB_REPOSITORY="${GITHUB_REPOSITORY}" php /var/www/html/yaml-generation/generateDimensions.php && sed -i "s/__VERSION_PLACEHOLDER__/${DSOMM_VERSION}/g" /var/www/html/generated/model.yaml +WORKDIR /var/www/html + +CMD [ "php", "yaml-generation/generateDimensions.php" ] diff --git a/README.md b/README.md index a5a0366..7254906 100644 --- a/README.md +++ b/README.md @@ -1,10 +1,70 @@ # OWASP DevSecOps Maturity Model Data -Data for the OWASP DevSecOps Maturity Model. + +This GitHub project ([DevSecOps-MaturityModel-data](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data)) contains the source for the DSOMM *model*. The model is used by the DSOMM applciation [DevSecOps-MaturityModel](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel). + +The source files include dimensions, activities, descriptions, measures, and other model data used by the application. + + +## Contribution + +Contributions that improve the DSOMM model are welcome. Please edit the source files under `src/assets/YAML/default/*` and open a pull request. + + +### Testing + +After making changes, generate a new `model.yaml` and start a local DSOMM application to verify there are no technical issues. (See below.) + ## Usage -To test changes to the yaml-files, please run: -```bash -docker run -ti -v $(pwd)/src/assets/YAML/:/var/www/html/src/assets/YAML wurstbrot/dsomm-yaml-generation -# Afterwards, you can use the generated.yaml in a container -docker run -v $(pwd)/src/assets/YAML/generated/generated.yaml:/usr/share/nginx/html/assets/YAML/generated/generated.yaml -p 8080:8080 wurstbrot/dsomm -``` + +The script is executed using `docker` (or alternatively `podman`). +Depending on your platform use either `generateDimensions.bash` (Linux) or `generateDimensions.bat` (Windows). + +1. Clone the repo: + + `git clone https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data.git` + +2. Change directory: + + `cd yaml-generation` + +3. Generate `model.yaml`: + + `./generateDimensions.bash` + + + +### Starting a local DSOMM application + +To start a local DSOMM instance on http://localhost:8080, run: + + - `./generateDimensions.bash --start-dsomm` + + This will down the latest DSOMM docker image and spin it up as a docker container. + + +### Test referenced URLs + +To test all URLs referenced by `implementations.yaml` and save results to `url-test-results.txt`, run: + + - `./generateDimensions.bash --test-urls` + + +### Using Podman instead of Docker + +If you prefer Podman over Docker, set the environement variable `DOCKER_CMD` to `podman`, or edit the script for you operating system. + + +## Credits + +- The "Test and Verification" dimension is based on Christian Schneider's Security DevOps Maturity Model (SDOMM). +- Application and infrastructure tests were added by Timo Pagel. +- The "Process" sub-dimension was added after discussion with Francois Raynaud. +- Translations and edits were contributed by Claud Camerino. +- ISO 27001:2017 mapping by Andre Baumeier. +- Other inspirations and contributions are acknowledged in the original README. + + +## License + +See the `LICENSE` file in this repository for license details. diff --git a/generated/README.md b/generated/README.md new file mode 100644 index 0000000..8794d48 --- /dev/null +++ b/generated/README.md @@ -0,0 +1 @@ +GitHub Actions will update these generated files. \ No newline at end of file diff --git a/generated/dependency-tree.md b/generated/dependency-tree.md new file mode 100644 index 0000000..1c7aa3d --- /dev/null +++ b/generated/dependency-tree.md @@ -0,0 +1,271 @@ +## DSOMM Activity Dependencies + +The activities in this DSOMM Model have the following dependencies. + +```mermaid +graph LR + +0(L2 Pinning of artifacts) +1(L1 Defined build process) +2(L2 SBOM of components) +3(L3 Signing of code) +4(L5 Signing of artifacts) +5(L1 Automated deployment process) +6(L1 Defined deployment process) +7(L1 Version control) +8(L1 Inventory of production components) +9(L2 Inventory of production artifacts) +10(L3 Handover of confidential parameters) +11(L2 Environment depending configuration parameters secrets) +12(L3 Inventory of production dependencies) +13(L3 Rolling update on deployment) +14(L4 Canary deployment) +15(L4 Same artifact for environments) +16(L4 Usage of feature toggles) +17(L5 Blue/Green Deployment) +18(L4 Smoke Test) +19(L2 Automated merge of automated PRs) +20(L1 Automated PRs for patches) +21(L3 Automated deployment of automated PRs) +22(L3 Creation of simple abuse stories) +23(L1 Conduction of simple threat modeling on technical level) +24(L3 Creation of threat modeling processes and standards) +25(L4 Conduction of advanced threat modeling) +26(L5 Creation of advanced abuse stories) +27(L2 Regular security training of security champions) +28(L2 Each team has a security champion) +29(L2 Determining the protection requirement) +30(L2 App. Hardening Level 1) +31(L1 App. Hardening Level 1 50%) +32(L3 App. Hardening Level 2 75%) +33(L4 App. Hardening Level 2) +34(L5 App. Hardening Level 3) +35(L3 Block force pushes) +36(L2 Require a PR before merging) +37(L3 Dismiss stale PR approvals) +38(L3 Require status checks to pass) +39(L2 Backup) +40(L2 MFA) +41(L1 MFA for admins) +42(L2 Usage of test and production environments) +43(L2 Virtual environments are limited) +44(L2 Applications are running in virtualized environments) +45(L3 Immutable infrastructure) +46(L3 Infrastructure as Code) +47(L3 Limitation of system events) +48(L3 Audit of system events) +49(L3 Usage of security by default for components) +50(L3 WAF baseline) +51(L1 Context-aware output encoding) +52(L4 Production near environments are used by developers) +53(L4 WAF medium) +54(L5 WAF Advanced) +55(L2 Centralized application logging) +56(L2 Alerting) +57(L3 Visualized logging) +58(L1 Centralized system logging) +59(L5 Correlation of security events) +60(L2 Visualized metrics) +61(L2 Monitoring of costs) +62(L1 Simple application metrics) +63(L1 Simple system metrics) +64(L3 Advanced availability and stability metrics) +65(L3 Deactivation of unused metrics) +66(L3 Targeted alerting) +67(L4 Advanced app. metrics) +68(L4 Coverage and control metrics) +69(L4 Defense metrics) +70(L3 Filter outgoing traffic) +71(L4 Screens with metric visualization) +72(L3 Grouping of metrics) +73(L5 Metrics are combined with tests) +74(L2 Patching mean time to resolution via PR) +75(L3 Generation of response statistics) +76(L3 Usage of a vulnerability management system) +77(L4 Patching mean time to resolution via production) +78(L2 Artifact-based false positive treatment) +79(L1 Simple false positive treatment) +80(L3 Fix based on accessibility) +81(L1 Treatment of defects with high or critical severity) +82(L3 Global false positive treatment) +83(L2 Exploit likelihood estimation) +84(L3 Office Hours) +85(L2 Coverage of client side dynamic components) +86(L2 Usage of different roles) +87(L2 Simple Scan) +88(L3 Coverage of hidden endpoints) +89(L3 Coverage of more input vectors) +90(L3 Coverage of sequential operations) +91(L4 Usage of multiple scanners) +92(L5 Coverage of service to service communication) +93(L2 Test for exposed services) +94(L2 Isolated networks for virtual environments) +95(L2 Test network segmentation) +96(L3 Test for unauthorized installation) +97(L2 Evaluation of the trust of used components) +98(L2 Software Composition Analysis server side) +99(L2 Test for Time to Patch) +100(L2 Test libyear) +101(L3 API design validation) +102(L3 Software Composition Analysis client side) +103(L3 Static analysis for important client side components) +104(L3 Static analysis for important server side components) +105(L3 Test for Patch Deployment Time) +106(L4 Static analysis for all self written components) +107(L4 Usage of multiple analyzers) +108(L5 Dead code elimination) +109(L5 Exclusion of source code duplicates) +110(L5 Static analysis for all components/libraries) +111(L4 Correlate known vulnerabilities in infrastructure with new image versions) +112(L2 Usage of a maximum lifetime for images) +113(L4 Test of infrastructure components for known vulnerabilities) + + +1 --> 0 +1 --> 2 +1 --> 3 +1 --> 4 +1 --> 5 +1 --> 6 +1 --> 15 +1 --> 49 +1 --> 87 +1 --> 98 +1 --> 100 +1 --> 102 +1 --> 103 +1 --> 104 +1 --> 105 +1 --> 108 +1 --> 109 +0 --> 4 +6 --> 5 +6 --> 39 +6 --> 42 +7 --> 6 +5 --> 8 +5 --> 9 +5 --> 13 +5 --> 14 +5 --> 52 +5 --> 18 +8 --> 9 +8 --> 29 +8 --> 80 +8 --> 98 +8 --> 101 +8 --> 102 +8 --> 103 +8 --> 104 +8 --> 106 +8 --> 110 +11 --> 10 +9 --> 12 +2 --> 12 +15 --> 16 +18 --> 17 +20 --> 19 +20 --> 74 +20 --> 77 +20 --> 99 +20 --> 105 +19 --> 21 +23 --> 22 +23 --> 24 +23 --> 25 +24 --> 22 +24 --> 25 +22 --> 26 +28 --> 27 +28 --> 76 +31 --> 30 +30 --> 32 +32 --> 33 +33 --> 34 +36 --> 35 +36 --> 37 +36 --> 38 +41 --> 40 +44 --> 43 +46 --> 45 +46 --> 52 +48 --> 47 +51 --> 50 +50 --> 53 +53 --> 54 +56 --> 55 +56 --> 59 +56 --> 66 +58 --> 57 +55 --> 57 +57 --> 59 +60 --> 56 +60 --> 64 +60 --> 48 +60 --> 65 +60 --> 67 +60 --> 68 +60 --> 69 +62 --> 61 +62 --> 60 +62 --> 64 +62 --> 67 +63 --> 61 +63 --> 60 +70 --> 69 +72 --> 71 +72 --> 73 +76 --> 75 +76 --> 82 +74 --> 77 +79 --> 78 +81 --> 80 +78 --> 82 +83 --> 76 +83 --> 102 +84 --> 76 +86 --> 85 +86 --> 88 +86 --> 89 +86 --> 90 +86 --> 91 +87 --> 86 +87 --> 92 +94 --> 93 +94 --> 95 +97 --> 96 +98 --> 83 +98 --> 107 +103 --> 106 +103 --> 110 +104 --> 106 +104 --> 110 +102 --> 107 +106 --> 107 +112 --> 111 +112 --> 113 + +O --> 1 +O --> 7 +O --> 11 +O --> 20 +O --> 23 +O --> 28 +O --> 31 +O --> 36 +O --> 41 +O --> 44 +O --> 46 +O --> 51 +O --> 58 +O --> 62 +O --> 63 +O --> 70 +O --> 72 +O --> 79 +O --> 81 +O --> 84 +O --> 94 +O --> 97 +O --> 112 +``` diff --git a/src/assets/YAML/generated/generated.yaml b/generated/model.yaml similarity index 50% rename from src/assets/YAML/generated/generated.yaml rename to generated/model.yaml index 105d6c1..53ab713 100644 --- a/src/assets/YAML/generated/generated.yaml +++ b/generated/model.yaml @@ -1,29 +1,48 @@ --- +meta: + version: 4.3.1 + released: "2026-06-05" + publisher: https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data +--- Build and Deployment: Build: - Building and testing of artifacts in virtual environments: - uuid: a340f46b-6360-4cb8-847b-a0d3483d09d3 - description: |- - While building and testing artifacts, third party systems, application frameworks - and 3rd party libraries are used. These might be malicious as a result of - vulnerable libraries or because they are altered during the delivery phase. - risk: |- - While building and testing artifacts, third party systems, application frameworks - and 3rd party libraries are used. These might be malicious as a result of - vulnerable libraries or because they are altered during the delivery phase. - measure: Each step during within the build and testing phase is performed in - a separate virtual environments, which is destroyed afterward. - meta: - implementationGuide: Depending on your environment, usage of virtual machines - or container technology is a good way. After the build, the filesystem should - not be used again in other builds. + Defined build process: + uuid: f6f7737f-25a9-4317-8de2-09bf59f29b5b + description: | + A *build process* includes more than just compiling your source code. It also covers: + - Managing (third party) dependencies + - Environment configuration + - Running unit and integration tests + - Security scanning and compliance checks + - Artifact creation and storage + - Deployment preparation + + Basing the build process on human memory may lead to inconsistencies and security misconfigurations. + + A *defined build process* can automate these steps to ensure consistency, avoiding accidental omissions or misconfigurations. Use tools such as Jenkins, GitHub Actions, GitLab CI, or Maven to codify the process. + + A simplified, but still a *defined build process*, may be a checklist of the steps to be performed. + risk: Without a defined and automated build process the risk increase for accidental + mistakes, forgetting test activities, and insecure misconfigurations. + measure: Find a tool that suits your environment. Add your manual build steps, + include steps for running tests, scanning and preparation for deployment. + assessment: | + - Show your build pipeline configuration (e.g., Jenkinsfile, GitHub Actions workflow) and an exemplary job (build + test + security scan). + level: 1 difficultyOfImplementation: knowledge: 2 - time: 2 + time: 3 resources: 2 - usefulness: 2 - level: 2 + usefulness: 4 implementation: + - uuid: 42ddb49f-48f2-4a3a-b76a-e73104ac6971 + name: Jenkins + tags: [] + url: https://www.jenkins.io/ + - uuid: eb6de6b9-e060-4902-ae6f-604ffc386b63 + name: Maven + tags: [] + url: https://maven.apache.org/ - uuid: b4bfead3-5fb6-4dd0-ba44-5da713bd22e4 name: CI/CD tools tags: @@ -36,38 +55,42 @@ Build and Deployment: url: https://d3fend.mitre.org/dao/artifact/d3f:ContainerOrchestrationSoftware/ references: samm2: - - I-SB-2-A + - I-SB-A-1 iso27001-2017: - - 14.2.6 + - 12.1.1 + - 14.2.2 iso27001-2022: - - 8.31 + - 5.37 + - 8.32 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Build/subsection/Defined%20build%20process isImplemented: false evidence: "" comments: "" tags: - none - Defined build process: - uuid: f6f7737f-25a9-4317-8de2-09bf59f29b5b - risk: Performing builds without a defined process is error prone; for example, - as a result of incorrect security related configuration. - measure: A well defined build process lowers the possibility of errors during - the build process. - description: | - Sample evidence as an attribute in the yaml: The build process is defined in [REPLACE-ME Pipeline](https://replace-me/jenkins/job) - in the folder _vars_. Projects are using a _Jenkinsfile_ to use the - defined process. + Building and testing of artifacts in virtual environments: + uuid: a340f46b-6360-4cb8-847b-a0d3483d09d3 + description: |- + While building and testing artifacts, third party systems, application frameworks + and 3rd party libraries are used. These might be malicious as a result of + vulnerable libraries or because they are altered during the delivery phase. + risk: |- + While building and testing artifacts, third party systems, application frameworks + and 3rd party libraries are used. These might be malicious as a result of + vulnerable libraries or because they are altered during the delivery phase. + measure: Each step during within the build and testing phase is performed in + a separate virtual environments, which is destroyed afterward. + meta: + implementationGuide: Depending on your environment, usage of virtual machines + or container technology is a good way. After the build, the filesystem should + not be used again in other builds. difficultyOfImplementation: knowledge: 2 - time: 3 + time: 2 resources: 2 - usefulness: 4 - level: 1 - assessment: | - - Show your build pipeline and an exemplary job (build + test). - - Show that every team member has access. - - Show that failed jobs are fixed. - - Credits: AppSecure-nrw [Security Belts](https://github.com/AppSecure-nrw/security-belts/) + usefulness: 2 + level: 2 implementation: - uuid: b4bfead3-5fb6-4dd0-ba44-5da713bd22e4 name: CI/CD tools @@ -81,13 +104,13 @@ Build and Deployment: url: https://d3fend.mitre.org/dao/artifact/d3f:ContainerOrchestrationSoftware/ references: samm2: - - I-SB-1-A + - I-SB-A-2 iso27001-2017: - - 12.1.1 - - 14.2.2 + - 14.2.6 iso27001-2022: - - 5.37 - - 8.32 + - 8.31 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Build/subsection/Building%20and%20testing%20of%20artifacts%20in%20virtual%20environments isImplemented: false evidence: "" comments: "" @@ -114,25 +137,41 @@ Build and Deployment: resources: 2 usefulness: 3 level: 2 + tags: + - inventory implementation: - - Container technology automatically creates a hash for images, which can be - used. - - Immutable images are an other way, e.g. by using a registry, which doesn't - allow overriding of images. + - uuid: 9368abfb-cf37-477a-9091-a804d2de9148 + name: Signing of containers + tags: + - signing + - container + - build + url: https://www.aquasec.com/cloud-native-academy/supply-chain-security/container-image-signing/ + description: Container technology automatically creates a hash for images, + which can be used. + - uuid: 638b3691-c9a5-45fa-9ba8-e40aeea32766 + name: Immutable images + tags: + - deployment + - container + - build + url: https://kubernetes.io/blog/2022/09/29/enforce-immutability-using-cel/#immutablility-after-first-modification + description: Immutable images are an other way, e.g. by using a registry, + which doesn't allow overriding of images. dependsOn: - - Defined build process + - f6f7737f-25a9-4317-8de2-09bf59f29b5b # Defined build process references: samm2: - - I-SB-1-A + - I-SB-B-1 iso27001-2017: - 14.2.6 iso27001-2022: - 8.31 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Build/subsection/Pinning%20of%20artifacts isImplemented: false evidence: "" comments: "" - tags: - - none SBOM of components: uuid: 2858ac12-0179-40d9-9acf-1b839c030473 description: |- @@ -146,22 +185,79 @@ Build and Deployment: measure: Creation of an SBOM of components (e.g. application and container image content) during build. dependsOn: - - Defined build process + - f6f7737f-25a9-4317-8de2-09bf59f29b5b # Defined build process difficultyOfImplementation: knowledge: 2 time: 2 resources: 3 usefulness: 3 level: 2 - implementation: [] + implementation: + - uuid: 7f500e95-2110-44c4-a1f8-cd7ef5d9eb6b + name: Trivy + tags: [] + url: https://github.com/aquasecurity/trivy + - uuid: 7543a6f2-3850-47a9-bb2f-0987e2af6f6a + name: Syft + tags: + - sbom + - dependency + url: https://github.com/anchore/syft references: - samm2: [] + samm2: + - I-SB-B-1 + - D-TA-A-1 iso27001-2017: - 8.1 - 8.2 iso27001-2022: - 5.9 - 5.12 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Build/subsection/SBOM%20of%20components + isImplemented: false + tags: + - inventory + - scanning + - sca + evidence: "" + comments: "" + Signing of code: + uuid: 9f107927-61e9-4574-85ad-3f2b4bca8665 + risk: Execution or usage of malicious code or data e.g. via executables, libraries + or container images. + measure: Digitally signing commits helps to prevent unauthorized manipulation + of source code. + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 2 + usefulness: 3 + level: 3 + implementation: + - uuid: d6d755d3-b9f1-4942-a084-e62b266541df + name: Signing of commits + tags: + - signing + url: https://git-scm.com/book/en/v2/Git-Tools-Signing-Your-Work + description: Signing of commits in git + - uuid: 86c6bdba-73c0-4c99-bbda-81b85c9fe2a4 + name: Enforcement of commit signing + tags: + - signing + url: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/managing-a-branch-protection-rule + description: Usage of branch protection rules + dependsOn: + - f6f7737f-25a9-4317-8de2-09bf59f29b5b # Defined build process + references: + samm2: + - I-SB-A-2 + iso27001-2017: + - 14.2.6 + iso27001-2022: + - 8.31 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Build/subsection/Signing%20of%20code isImplemented: false evidence: "" comments: "" @@ -173,20 +269,19 @@ Build and Deployment: or container images. measure: Digitally signing artifacts for all steps during the build and especially docker images, helps to ensure their integrity and authenticity. - description: "### GitHub Authentication and Commit Signing \n To perform a - push to a GitHub repository, you must be authenticated. It's important to - note that GitHub does not verify if the authenticated user's email address - matches the one in the commit.\n To clearly identify the author of a commit - for reviewers, commit signing is recommended.\n\n GitHub actions such as - [semantic-release-action](https://github.com/cycjimmy/semantic-release-action) - do not automatically sign commits and may encounter issues as a result. \n\n - \ To address this, you can refer to a working configuration example in the - [workflow folder](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel/blob/master/.github/workflows/main.yml) + description: "To perform a push to a GitHub repository, you must be authenticated. + It's important to note that GitHub does not verify if the authenticated user's + email address matches the one in the commit.\nTo clearly identify the author + of a commit for reviewers, commit signing is recommended.\n\nGitHub actions + such as [semantic-release-action](https://github.com/cycjimmy/semantic-release-action) + do not automatically sign commits and may encounter issues as a result. \n\nTo + address this, you can refer to a working configuration example in the [workflow + folder](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel/blob/master/.github/workflows/main.yml) of DSOMM, which demonstrates how to use semantic release action in conjunction - with [planetscale/ghcommit-action](https://github.com/planetscale/ghcommit-action).\n - \ For added security, consider using [Fine-grained personal access tokens](https://github.blog/2022-10-18-introducing-fine-grained-personal-access-tokens-for-github/) + with [planetscale/ghcommit-action](https://github.com/planetscale/ghcommit-action).\nFor + added security, consider using [Fine-grained personal access tokens](https://github.blog/2022-10-18-introducing-fine-grained-personal-access-tokens-for-github/) provided by your organization for a specific repository. Store the Personal - Access Token (PAT) as a secret in your project.\n" + Access Token (PAT) as a secret in your project." difficultyOfImplementation: knowledge: 2 time: 2 @@ -203,101 +298,170 @@ Build and Deployment: tags: [] url: https://in-toto.github.io/ dependsOn: - - Defined build process - - Pinning of artifacts + - f6f7737f-25a9-4317-8de2-09bf59f29b5b # Defined build process + - f3c4971e-9f4d-4e59-8ed0-f0bdb6262477 # Pinning of artifacts references: samm2: - - I-SB-1-A + - I-SB-A-1 iso27001-2017: - 14.2.6 iso27001-2022: - 8.31 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Build/subsection/Signing%20of%20artifacts isImplemented: false evidence: "" comments: "" tags: - none - Signing of code: - uuid: 9f107927-61e9-4574-85ad-3f2b4bca8665 - risk: Execution or usage of malicious code or data e.g. via executables, libraries - or container images. - measure: Digitally signing commits helps to prevent unauthorized manipulation - of source code. + Deployment: + Automated deployment process: + uuid: 67e1a9aa-9fbf-4ec5-a2de-400f01960c51 + description: | + An *automated deployment process* implements the defined deployment steps using automation tools, ensuring consistency, auditability, and minimizing the risk of human errors or unauthorized changes. + risk: Deployments relying on manual routines increase the risk of errors, insecure + configurations, or deploying malfunctioning artifacts. + measure: Automating the deployment process enforces predefined criteria for + security, compliance, and performance, ensuring reliable artifact delivery. + assessment: | + - Deployment process is documented and available to relevant staff + - All deployment steps are automated + - Provide audit logs or evidence of deployments + level: 1 difficultyOfImplementation: knowledge: 2 time: 2 resources: 2 - usefulness: 3 - level: 3 + usefulness: 4 + dependsOn: + - f6f7737f-25a9-4317-8de2-09bf59f29b5b # Defined build process + - 74938a3f-1269-49b9-9d0f-c43a79a1985a # Defined deployment process implementation: - - uuid: d6d755d3-b9f1-4942-a084-e62b266541df - name: Signing of commits - tags: - - signing - url: https://git-scm.com/book/en/v2/Git-Tools-Signing-Your-Work - description: Signing of commits in git - - uuid: 86c6bdba-73c0-4c99-bbda-81b85c9fe2a4 - name: Enforcement of commit signing + - uuid: b4bfead3-5fb6-4dd0-ba44-5da713bd22e4 + name: CI/CD tools tags: - - signing - url: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/defining-the-mergeability-of-pull-requests/managing-a-branch-protection-rule - description: Usage of branch protection rules - dependsOn: - - Defined build process + - ci-cd + url: https://martinfowler.com/articles/continuousIntegration.html + description: CI/CD tools such as jenkins, gitlab-ci or github-actions + - uuid: 42ddb49f-48f2-4a3a-b76a-e73104ac6971 + name: Jenkins + tags: [] + url: https://www.jenkins.io/ + - uuid: cc47b2e3-6ee5-4926-af3a-d418ef91c8ba + name: Docker + url: https://github.com/moby/moby + tags: [] references: samm2: - - I-SB-2-A + - I-SD-A-1 iso27001-2017: - - 14.2.6 + - 12.1.1 + - 14.2.2 iso27001-2022: - - 8.31 - isImplemented: false - evidence: "" - comments: "" + - 5.37 + - 8.32 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Deployment/subsection/Automated%20deployment%20process tags: - none - Deployment: - Blue/Green Deployment: - uuid: 0cb2626b-fb0d-4a0f-9688-57f787310d97 - risk: A new artifact's version can have unknown defects. - measure: |- - Using a blue/green deployment strategy increases application availability - and reduces deployment risk by simplifying the rollback process if a deployment fails. + Defined deployment process: + uuid: 74938a3f-1269-49b9-9d0f-c43a79a1985a + description: | + A *defined deployment process* is a documented and standardized procedure for releasing software into production, ensuring consistency and reducing the risk of errors. + risk: Deployments relying on human memory are prone to errors, making experienced + long-ter staff critical. + measure: Establish a written deployment process documented in README files, + wikis, or implemented as executable scripts and automated steps. + assessment: | + - Deployment process is documented and available to relevant staff + - Logs of deployments are documented and availabe to relevant staff + level: 1 difficultyOfImplementation: knowledge: 1 - time: 2 + time: 1 resources: 1 - usefulness: 2 - level: 5 - implementation: - - uuid: 4fb3d95c-07c0-4cbb-b396-5054aba751c2 - name: Blue/Green Deployments - tags: [] - url: https://martinfowler.com/bliki/BlueGreenDeployment.html + usefulness: 1 dependsOn: - - Smoke Test + - f6f7737f-25a9-4317-8de2-09bf59f29b5b # Defined build process + - 066084c6-1135-4635-9cc5-9e75c7c5459f # Version control + implementation: ~ references: samm2: - - TODO + - I-SD-A-1 iso27001-2017: - - 17.2.1 - 12.1.1 - - 12.1.2 - - 12.1.4 - - 12.5.1 - - 14.2.9 + - 14.2.2 iso27001-2022: - - 8.14 - 5.37 - - 8.31 - 8.32 - - 8.19 - - 8.29 - isImplemented: false - evidence: "" - comments: "" + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Deployment/subsection/Defined%20deployment%20process tags: - none + Inventory of production components: + uuid: 2a44b708-734f-4463-b0cb-86dc46344b2f + description: | + An inventory of production components is a complete, up-to-date list of all applications running in production. This enables effective vulnerability management, incident response, and compliance. Without it, organizations risk running unmaintained or unauthorized software. + risk: An organization is unaware of components like applications in production. + Not knowing existing applications in production leads to not assessing it. + measure: |- + A documented inventory of components in production exists (gathered manually or automatically). For example a manually created document with applications in production. + In a kubernetes cluster, namespaces can be automatically gathered and documented, e.g. in a JSON in a S3 bucket/git repository, dependency track. + assessment: | + - Inventory of all production applications with application name, owner, and date of last review + - Inventory is accessible to development, security and operations teams + dependsOn: + - 67e1a9aa-9fbf-4ec5-a2de-400f01960c51 # Automated deployment process + level: 1 + difficultyOfImplementation: + knowledge: 1 + time: 1 + resources: 1 + usefulness: 4 + implementation: + - uuid: 2210e02b-a856-4da4-8732-5acd77e20fca + name: Backstage + tags: + - documentation + - inventory + url: https://github.com/backstage/backstage + description: | + Backstage is an open-source platform designed to create developer portals. At its core is a centralized software catalog that brings organization to your microservices and infrastructure. + - uuid: 500399bd-7dfc-47fd-99d8-b55cefb760a9 + name: Dependency-Track + description: | + Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track takes a unique and highly beneficial approach by leveraging the capabilities of Software Bill of Materials (SBOM). + url: https://github.com/DependencyTrack/dependency-track + tags: + - sca + - inventory + - OpenSource + - Supply Chain + - vulnerability + - inventory + - uuid: 879bd03f-8de1-43d6-b492-d974181bfa6c + name: Image Metadata Collector + tags: + - documentation + - inventory + - kubernetes + url: https://github.com/SDA-SE/image-metadata-collector/ + description: | + Collects namespaces and namespaces including responsible team and contact info through annotations/labels from Kubernetes clusters. Results are available in JSON and can be uploaded to S3, github and an API. + references: + samm2: + - I-SB-B-1 + - D-TA-B-1 + iso27001-2017: + - 8.1 + - 8.2 + iso27001-2022: + - 5.9 + - 5.12 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Deployment/subsection/Inventory%20of%20production%20components + tags: + - inventory Defined decommissioning process: uuid: da4ff665-dcb9-4e93-9d20-48cdedc50fc2 description: |- @@ -308,7 +472,9 @@ Build and Deployment: risk: Unused applications are not maintained and may contain vulnerabilities. Once exploited they can be used to attack other applications or to perform lateral movements within the organization. - measure: A clear decommissioning process ensures the removal of unused applications. + measure: A clear decommissioning process ensures the removal of unused applications + from the `Inventory of production components` and if implemented from `Inventory + of production artifacts`. difficultyOfImplementation: knowledge: 1 time: 2 @@ -317,50 +483,13 @@ Build and Deployment: level: 2 references: samm2: - - O-OM-2-B + - O-OM-B-2 iso27001-2017: - 11.2.7 iso27001-2022: - 7.14 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Defined deployment process: - uuid: 74938a3f-1269-49b9-9d0f-c43a79a1985a - risk: Deployment of insecure or malfunctioning artifacts. - measure: Defining a deployment process ensures that there are established criteria - in terms of functionalities, security, compliance, and performance, and that - the artifacts meet them. - difficultyOfImplementation: - knowledge: 2 - time: 2 - resources: 1 - usefulness: 4 - level: 1 - dependsOn: - - Continuous Integration - implementation: - - uuid: b4bfead3-5fb6-4dd0-ba44-5da713bd22e4 - name: CI/CD tools - tags: - - ci-cd - url: https://martinfowler.com/articles/continuousIntegration.html - description: CI/CD tools such as jenkins, gitlab-ci or github-actions - - uuid: cc47b2e3-6ee5-4926-af3a-d418ef91c8ba - name: Docker - url: https://github.com/moby/moby - tags: [] - references: - samm2: - - I-SD-1-A - iso27001-2017: - - 12.1.1 - - 14.2.2 - iso27001-2022: - - 5.37 - - 8.32 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Deployment/subsection/Defined%20decommissioning%20process isImplemented: false evidence: "" comments: "" @@ -380,1087 +509,19 @@ Build and Deployment: usefulness: 4 level: 2 implementation: - - argocd: - uuid: fdb0e7cc-d3dd-4a2b-9f45-7d403001294f - name: argoCD - tags: - - deployment - url: https://argo-cd.readthedocs.io/en/stable/ - signing-of-commits-protection: - uuid: 86c6bdba-73c0-4c99-bbda-81b85c9fe2a4 - name: Enforcement of commit signing - tags: - - signing - url: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/defining-the-mergeability-of-pull-requests/managing-a-branch-protection-rule - description: Usage of branch protection rules - signing-of-commits: - uuid: d6d755d3-b9f1-4942-a084-e62b266541df - name: Signing of commits - tags: - - signing - url: https://git-scm.com/book/en/v2/Git-Tools-Signing-Your-Work - description: Signing of commits in git - ci-cd-tools: - uuid: b4bfead3-5fb6-4dd0-ba44-5da713bd22e4 - name: CI/CD tools - tags: - - ci-cd - url: https://martinfowler.com/articles/continuousIntegration.html - description: CI/CD tools such as jenkins, gitlab-ci or github-actions - apimaturity: - uuid: 596cb528-8981-4723-bcc3-22c261f26114 - name: API Security Maturity Model for Authorization - tags: - - api - url: https://curity.io/resources/learn/the-api-security-maturity-model/ - container-technologi: - uuid: ed6b6340-6c7f-4e13-8937-f560d3f5db11 - name: Container technologies and orchestration like Docker, Kubernetes - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:ContainerOrchestrationSoftware/ - cwe25: - uuid: c77f7ecd-76de-4611-bd6d-5b249f910c39 - name: CWE Top 25 Most Dangerous Software Weaknesses - tags: - - documentation - - threat - url: https://cwe.mitre.org/top25/archive/2020/2020_cwe_top25.html - docker-content-trust: - uuid: ee81f93f-8230-4cfb-a132-ae4ec61cb8e6 - name: Docker Content Trust - tags: [] - url: https://docs.docker.com/engine/security/trust/ - in-toto: - uuid: 6e9d8c14-ba3b-4698-afc3-365b4ab6fb1f - name: in-toto - tags: [] - url: https://in-toto.github.io/ - a-complete-backup-of: - uuid: ba7348e5-1abf-4c7d-8fbc-49f99460930b - name: A complete backup of persisted data might be performed*. - tags: [] - a-point-in-time-reco: - uuid: 9af7624e-0729-4eeb-b257-ebaf65f70355 - name: A Point in Time Recovery for databases should be implemented. - tags: [] - blue-green-deploymen: - uuid: 4fb3d95c-07c0-4cbb-b396-5054aba751c2 - name: Blue/Green Deployments - tags: [] - url: https://martinfowler.com/bliki/BlueGreenDeployment.html - docker: - uuid: cc47b2e3-6ee5-4926-af3a-d418ef91c8ba - name: Docker - url: https://github.com/moby/moby - tags: [] - webserver: - uuid: a71ce8f8-fd4a-4240-8b46-64a6cdb5dfdb - name: Webserver - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:WebServer/ - rolling-update: - uuid: ee2eb94b-7204-40d8-97da-43c7b1296e2e - name: rolling update - tags: [] - kubernetes-admission: - uuid: 2a76300f-6b1f-4a51-b925-134c36b723af - name: Kubernetes Admission Controller can whitelist registries and/or whitelist - a signing key. - tags: [] - url: https://medium.com/slalom-technology/build-a-kubernetes-dynamic-admission-controller-for-container-registry-whitelisting-b46fe020e22d - dependabot: - uuid: d6292c7d-aab7-43d3-a7c6-1e443b5c1aa4 - name: dependabot - tags: - - auto-pr - - patching - url: https://dependabot.com/ - renovate: - uuid: 8228266e-e04f-40ba-94c8-bfadc5310920 - name: renovate - tags: - - auto-pr - - patching - url: https://github.com/renovatebot/renovate - jenkins: - uuid: 42ddb49f-48f2-4a3a-b76a-e73104ac6971 - name: Jenkins - tags: [] - url: https://www.jenkins.io/ - sample-concept-1: - uuid: 1a463242-b480-46f6-a912-b51ec1c1558d - name: "Sample concept: \n(1" - tags: [] - description: "Sample concept: \n(1) each container has a set lifetime and - is killed / replaced with a new container multiple times a day where you - have some form of a graceful replacement to ensure no (short) service - outage will occur to the end users. \n(2) twice a day a rebuild of images - is done. The rebuilds are put into a automated testing pipeline. If the - testing has no blocking issues the new images will be released for deployment - during the next \"restart\" of a container. What has to be done, is to - ensure the new containers are deployed in some canary deployment manner, - this will ensure that if (and only if) something buggy has been introduced - which breaks functionality the canary deployment will make sure the \"older - version\" is being used and not the buggy newer one." - distroless: - uuid: ef647044-b675-47d3-9720-3ebc144ef37b - name: Distroless - tags: [] - url: https://github.com/GoogleContainerTools/distroless - fedora-coreos: - uuid: be757cb3-63d6-4a63-9c4e-e10b746fd47a - name: Fedora CoreOS - tags: [] - url: https://getfedora.org/coreos - distroless-usage: - uuid: a92c4f8f-a918-406a-b1e5-70acfc0477bd - name: Distroless or Alpine - tags: [] - url: https://itnext.io/which-container-images-to-use-distroless-or-alpine-96e3dab43a22 - threat-modeling-play: - uuid: fd0f282b-a065-4464-beed-770c604a5f52 - name: Threat Modeling Playbook - tags: - - owasp - - defender - - threat-modeling - - whiteboard - url: https://github.com/Toreon/threat-model-playbook - owasp-samm: - uuid: b5eaf710-e05f-49e5-a649-13afde9aeb52 - name: OWASP SAMM - tags: - - threat-modeling - - owasp - - defender - url: https://owaspsamm.org/model/design/threat-assessment/stream-b/ - whiteboard: - uuid: c0533602-11b7-4838-93cc-a40556398163 - name: Whiteboard - tags: - - defender - - threat-modeling - - collaboration - - whiteboard - url: https://en.wikipedia.org/wiki/Whiteboard - miro-or-any-other-c: - uuid: 965c3814-b6df-4ead-a096-1ed78ce1c7c1 - name: Miro (or any other collaborative board) - tags: - - defender - - threat-modeling - - collaboration - - whiteboard - url: https://miro.com/ - draw-io: - uuid: 088794c4-3424-40d4-9084-4151587fc84d - name: Draw.io - tags: - - defender - - threat-modeling - - whiteboard - url: https://github.com/jgraph/drawio-desktop - threagile: - uuid: e8332407-5149-459e-a2fe-c5c78c7ec55c - name: Threagile - tags: - - threat-modeling - url: https://github.com/Threagile/threagile - don-t-forget-evil-u: - uuid: bb5b8988-021b-452a-a914-bd36887b6860 - name: '[Don''t Forget EVIL U' - tags: [] - url: https://www.owasp.org/index.php/Agile_Software_Development - description: '[Do not Forget EVIL User Stories](https://www.owasp.org/index.php/Agile_Software_Development:_Don%27t_Forget_EVIL_User_Stories) - and [Practical Security Stories and Security Tasks for Agile Development - Environments](http://safecode.org/publication/SAFECode_Agile_Dev_Security0712.pdf)' - libyear: - uuid: 2fff917f-205e-4eab-2e0e-1fab8c04bf33 - name: libyear - tags: - - patching - - build - url: https://libyear.com/ - description: A simple measure of software dependency freshness. It is a - single number telling you how up-to-date your dependencies are. - owasp-juice-shop: - uuid: 1fff917f-205e-4eab-ae0e-1fab8c04bf3a - name: OWASP Juice Shop - tags: - - training - url: https://github.com/bkimminich/juice-shop - description: In case you do not have the budget to hire an external security - expert, an option is to use the OWASP JuiceShop on a "hacking Friday" - owasp-cheatsheet-ser: - uuid: 1c3f2f7a-5031-4687-9d69-76c5178c74e1 - name: OWASP Cheatsheet Series - tags: - - secure coding - url: https://cheatsheetseries.owasp.org/ - owasp-juiceshop: - uuid: 81476121-67dd-4ba9-a67b-e78a23050c28 - name: OWASP JuiceShop - tags: [] - url: https://github.com/bkimminich/juice-shop - description: |- - In case you do not have the budget to hire an external security expert, an option - is to use the [OWASP JuiceShop](https://github.com/bkimminich/juice-shop) on a "hacking Friday" - https-cheatsheetse: - uuid: 99080ac7-60cd-46af-93a1-a53a33597cba - name: https://cheatsheetseries.owasp.org/ - tags: - - training - - secure coding - url: https://cheatsheetseries.owasp.org/ - owasp-security-champ: - uuid: c191a515-3c10-4903-a889-70c8021f2ea1 - name: OWASP Security Champions Playbook - tags: - - security champions - url: https://github.com/c0rdis/security-champions-playbook - build-it-break-it-fi: - uuid: 8d4c1849-f310-4c42-8148-2810b382bc6f - name: Build it Break it Fix it Contest - tags: [] - url: https://builditbreakit.org/ - motivate-people: - uuid: 8e1b4a8a-c53b-4b1e-90f6-c60b7e225098 - name: Motivate people - tags: - - security champions - - gamification - - nudging - url: https://github.com/wurstbrot/security-pins - description: |- - Enhance motivation can be performed with the distribution of pins - as a reward, see [OWASP Security Pins Project](https://github.com/wurstbrot/security-pins) - owasp-top-10-maturit: - uuid: 22b63bdb-2003-4ac0-969d-b1e5268c2510 - name: OWASP Top 10 Maturity Categories for Security Champions - tags: - - security champions - url: https://owaspsamm.org/presentations/OWASP_Top_10_Maturity_Categories_for_Security_Champions.pptx - involve-security-sme: - uuid: 8a044b74-17f2-4ffa-9dee-6b3bb6e4baf3 - name: Involve Security SME - tags: [] - description: Security SME are involved in discussion for requirements analysis, - software design and sprint planning to provide guidance and suggestions. - damn-vulnerable-web: - uuid: a8cd9acb-ad22-44d6-b177-1154c65a8529 - name: Damn Vulnerable Web Application - tags: - - training - description: Simple Application with intended vulnerabilities. HTML based. - example-all-docker: - uuid: 349cf64c-abea-40bb-bd07-9c98ce648fa4 - name: 'Example: All docker images used by teams need to be based on standard - images.' - tags: [] - owasp-asvs: - uuid: 88767cde-1610-402e-98ec-bc3575377183 - name: OWASP ASVS - tags: [] - url: https://owasp.org/www-project-application-security-verification-standard/ - owasp-masvs: - uuid: 7bf90650-a53a-4581-a214-1afd5de3a059 - name: OWASP MASVS - tags: [] - url: https://github.com/OWASP/owasp-masvs - cis-kubernetes-bench: - uuid: edaec98d-dac7-4dfd-8ab3-42c471d5b9ff - name: CIS Kubernetes Bench for Security - tags: [] - url: https://www.cisecurity.org/cis-benchmarks/ - cis-docker-bench-for: - uuid: 4dd23c4a-5a7e-4917-82cf-d00e0f04482f - name: CIS Docker Bench for Security - tags: [] - url: https://www.cisecurity.org/cis-benchmarks/ - for-example-for-cont: - uuid: f4d7c796-8574-4a88-ab00-98d245a115ef - name: For example for Cont - tags: [] - description: 'For example for Containers: Deny running containers as root, - deny using advanced privileges, deny mounting of the hole filesystem, - ...' - url: https://d3fend.mitre.org/technique/d3f:ExecutionIsolation/ - attack-matrix-cloud: - uuid: 3b7df373-2ad9-456e-9abe-439cdc9d4d8b - name: Attack Matrix Cloud - tags: - - mitre - url: https://attack.mitre.org/matrices/enterprise/cloud/ - description: Attack matrix for cloud - attack-matrix-contai: - uuid: 59881520-4c69-4922-a44e-99044a77de2b - name: Attack Matrix Containers - tags: - - mitre - url: https://attack.mitre.org/matrices/enterprise/cloud/ - description: Attack matrix for containers - attack-matrix-kubern: - uuid: 9fbc47ad-82bc-46d1-bba9-66815ab79935 - name: Attack Matrix Kubernetes - tags: - - mitre - url: https://www.microsoft.com/security/blog/2020/04/02/attack-matrix-kubernetes/ - description: Attack matrix for kubernetes - istio: - uuid: 9429d52c-203d-49ae-814f-1401210887cd - name: istio - tags: [] - url: https://istio.io/ - bridges: - uuid: fc0eda30-2bf7-466f-948e-e17584db9f30 - name: bridges - tags: [] - firewalls: - uuid: e3c6fb92-3f7d-471f-9308-c62359f4f1b7 - name: firewalls - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:Firewall/ - open-policy-agent: - uuid: 4a024319-4510-4a53-a8b6-8f35b6c01867 - name: Open Policy Agent - tags: [] - url: https://www.openpolicyagent.org/ - gitops: - uuid: b0931397-2402-44f1-814b-63292ab4a339 - name: GitOps - tags: [] - url: https://www.redhat.com/en/topics/devops/what-is-gitops - ansible: - uuid: 73747d35-2185-4f22-94a0-723288fa283c - name: Ansible - tags: [] - url: https://github.com/ansible/ansible - chef: - uuid: 691c443f-b6e2-498d-94dc-778d8d51cfce - name: Chef - tags: [] - url: https://github.com/chef/chef - puppet: - uuid: eb7f76a8-87e5-4394-af4c-c09487c85982 - name: Puppet - tags: [] - url: https://github.com/puppetlabs/puppet - jenkinsfile: - uuid: 321dcfe4-d2fc-4dd2-85bf-aac563958458 - name: Jenkinsfile - tags: [] - url: https://www.jenkins.io/doc/book/pipeline/jenkinsfile/ - seccomp: - uuid: 0cc7e68b-f7d9-4e66-8065-47d076129ffd - name: seccomp - tags: [] - url: https://man7.org/linux/man-pages/man2/seccomp.2.html - strace: - uuid: 73ab2e3d-11a7-459d-8b57-9337662bd1ff - name: strace - tags: [] - url: https://man7.org/linux/man-pages/man1/strace.1.html - remove-direct-access: - uuid: b206481f-9c66-45e2-843c-37c5730580cd - name: Remove direct access to infrastructure - tags: [] - directory-service: - uuid: 04edc63e-d389-48dd-b365-552aaf4ea004 - name: Directory Service - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:DirectoryService/ - plugins: - uuid: cc55cba1-ea0a-466e-99c5-337c9da2b00e - name: Plugins - tags: [] - smartcard: - uuid: e76a395a-8d6a-4e25-a175-6cf25409b755 - name: Smartcard - tags: [] - url: https://d3fend.mitre.org/technique/d3f:Multi-factorAuthentication/ - yubikey: - uuid: d5981117-9bc2-45ed-b4a4-383135dc13d8 - name: YubiKey - tags: [] - url: https://d3fend.mitre.org/technique/d3f:Multi-factorAuthentication/ - sms: - uuid: 6151cfb3-c894-421e-83da-cac0b2bfaec8 - name: SMS - tags: [] - totp: - uuid: f69f5d03-691f-4e14-8fbc-ad66e2e5a12d - name: TOTP - tags: [] - url: https://d3fend.mitre.org/technique/d3f:One-timePassword/ - http-basic-authentic: - uuid: 41fda224-2980-443c-bfd4-0a1d4b520cb9 - name: HTTP-Basic Authentication - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:WebAuthentication/ - vpn: - uuid: e506f60b-747b-44b1-8fe8-f67ccd8f290e - name: VPN - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:VPN/ - for-applications-ch: - uuid: d7fb1f5a-05e3-49f7-ae67-00bfb8f8410c - name: 'For applications: Check default encoding' - tags: [] - managing-secrets: - uuid: 7e744f11-976e-46b6-88d4-f39b2965dfaf - name: managing secrets - tags: [] - url: https://d3fend.mitre.org/technique/d3f:CredentialHardening/ - crypto: - uuid: 520517ef-2911-4efc-8e1b-dcc9389aca45 - name: crypto - tags: [] - authentication: - uuid: ba6bd46c-2069-4f4d-b26c-7334a7553339 - name: authentication - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:Authentication/ - rsyslog: - uuid: 79f88310-d63e-471d-8e63-8c77f2281b66 - name: rsyslog - url: https://www.rsyslog.com/ - tags: - - tool - - logging - logstash: - uuid: 7a8fad2e-d642-4972-8501-74591b23feab - name: logstash - url: https://www.elastic.co/guide/en/logstash/current/getting-started-with-logstash.html - tags: - - tool - - logging - fluentd: - uuid: f5da3a20-ab64-4ecf-b4e1-660c80036e45 - name: fluentd - tags: - - tool - url: https://www.fluentd.org/ - bash: - uuid: 6226f8bc-2f6e-45c2-9232-98d2027e4531 - name: bash - tags: - - tool - url: https://www.gnu.org/software/bash/ - owasp-logging-cheats: - uuid: 5a5c7d99-41e8-454a-86ae-a638c9787d8c - name: OWASP Logging CheatSheet - url: https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html - tags: - - logging - - documentation - elk-stack: - uuid: 38fe9d00-df8b-44b6-910d-ca0f02b5c5d3 - name: ELK-Stack - tags: [] - url: https://www.elastic.co/elk-stack - https-ht-transpare: - uuid: 84ef86ea-ada4-4e10-ae4f-a5bb77dcae5d - name: https://ht.transpare - tags: [] - url: https://ht.transparencytoolkit.org/FileServer/FileServer/OLD - description: https://ht.transparencytoolkit.org/FileServer/FileServer/OLD%20Fileserver/books/SICUREZZA/Addison.Wesley.Security.Metrics.Mar.2007.pdf - prometheus: - uuid: ddf221df-3517-42e4-b23d-c1d9a162744c - name: Prometheus - tags: [] - url: https://prometheus.io/ - collected: - uuid: 73f6a52c-4fc2-45dc-991b-d5911b6c1ef8 - name: collected - tags: [] - httpunit: - uuid: 3bd40005-f180-4b95-907d-ec5b58ac1f20 - name: HttpUnit - tags: [] - url: http://httpunit.sourceforge.net/ - junit: - uuid: cc2eec82-f3a7-4ae5-9ccb-3d75352b2e4d - name: JUnit - tags: - - unittest - url: https://junit.org/junit5/ - karma: - uuid: fd56720a-ad4b-487c-b4c3-897a688672c4 - name: Karma - tags: [] - url: https://karma-runner.github.io - owasp-defectdojo: - uuid: 227d786c-dd76-4b81-b0b2-62389ab8f0fb - name: OWASP DefectDojo - tags: - - vulnerability management system - - owasp - url: https://github.com/DefectDojo/django-DefectDojo - description: | - DefectDojo is a security program and vulnerability management tool. DefectDojo allows you to manage your application security program, maintain product and application information, triage vulnerabilities and push findings into defect trackers. Consolidate your findings into one source of truth with DefectDojo. - purify: - uuid: d2eb592d-c9b5-4c39-bff7-bb313a58e3a9 - name: Purify - tags: - - vulnerability management system - url: https://github.com/faloker/purify/ - description: | - The goal of Purify to be an easy-in-use and efficient tool to simplify a workflow of managing vulnerabilities delivered from various (even custom) tools. - see-other-actions-e: - uuid: 44c08670-78dc-47ee-a4c1-2503ca6b6cf8 - name: See other actions, e.g. "Treatment of defects with severity high". - tags: [] - sast: - uuid: aaad322e-806e-4c51-b78d-6551f7dc376a - name: SAST - tags: [] - description: 'At SAST (Static Application Security Testing): Server-side - / client-side teams can easily be recorded. With microservice architecture - individual microservices can be used usually Teams.' - url: https://d3fend.mitre.org/dao/artifact/d3f:StaticAnalysisTool/ - dast: - uuid: 9d4bd377-11ec-4054-9c9e-9bfb99ac9609 - name: DAST - tags: [] - description: 'At DAST (Dynamic Application Security Testing): vulnerabilities - are classified and can be assigned to server-side and client-side teams.' - url: https://d3fend.mitre.org/dao/artifact/d3f:DynamicAnalysisTool/ - owasp-defect-dojo: - uuid: bb9d0f2d-f8bc-46b5-bbc7-7dbcf927191c - name: OWASP Defect Dojo - tags: [] - url: https://github.com/DefectDojo/django-DefectDojo - owasp-dependency-che: - uuid: 06334caf-8be6-487a-96b1-d41c7ed5f207 - name: OWASP Dependency Check - tags: - - OpenSource - - Supply Chain - - vulnerability - url: https://owasp.org/www-project-dependency-check/ - logparser-jenkins-pl: - uuid: ef80cd34-d3ba-4406-a4fa-4cf6f30c2e81 - name: LogParser Jenkins Plugins - tags: [] - owasp-code-pulse: - uuid: 7063cf8c-cd98-480f-8ef7-11cf241d2366 - name: OWASP Code Pulse - tags: [] - url: https://www.owasp.org/index.php/OWASP_Code_Pulse - ajax-spider: - uuid: 6583fd5f-4314-4b39-9265-de72f861c8cb - name: Ajax Spider - tags: [] - url: https://www.zaproxy.org/docs/desktop/addons/ajax-spider/ - curl: - uuid: f2a5f642-43b3-4b2c-97d5-b14d5964981b - name: cURL - tags: [] - url: https://curl.se/ - openapi: - uuid: 7ce77258-bf65-4e7a-9627-daf765ee1d77 - name: OpenAPI Specifications - tags: [] - url: https://spec.openapis.org/ - owasp-zap: - uuid: 42a87524-ec35-4de2-a30c-1a7c7d045801 - name: OWASP Zap - tags: - - vulnerability - - scanner - url: https://github.com/zaproxy/zaproxy - description: | - The OWASP Zed Attack Proxy (ZAP) is one of the world's most popular free security tools and is actively maintained by a dedicated international team of ... - arachni: - uuid: 83ae1e92-5eb9-4467-b3d3-fd2f96e6ab63 - name: Arachni - url: https://github.com/Arachni/arachni - zest: - uuid: 7eb37566-02d5-4fff-8dcf-8fcd1c8197f3 - name: Zest - url: https://www.zaproxy.org/docs/desktop/addons/zest/ - tags: - - zap - description: | - Zest is an experimental specialized scripting language (also known as a domain-specific language) originally developed by the Mozilla security team and is intended to be used in web oriented security tools. - owasp-securecodebox: - uuid: f220b299-0917-4750-96c5-d81cd402b4df - name: OWASP secureCodeBox - tags: - - vulnerability - - scanner-orchestration - url: https://github.com/secureCodeBox/secureCodeBox - description: | - secureCodeBox is a kubernetes based, modularized toolchain for continuous security scans of your software project. Its goal is to orchestrate and easily automate a bunch of security-testing tools out of the box. - kube-hunter: - uuid: 2af7204c-a25c-4625-9775-889978386407 - name: kube-hunter - tags: [] - url: https://github.com/aquasecurity/kube-hunter - openvas: - uuid: d45fba7d-f176-4f06-a33c-434b17ec8a8f - name: openVAS - tags: [] - url: https://www.openvas.org/ - htc-hydra: - uuid: b99c9d52-dd1a-4aef-8699-65173cf978ce - name: HTC Hydra - tags: - - password - url: https://www.htc-cs.com/en/products/htc-hydra/ - netassert: - uuid: fffa6fb9-1fae-4852-88dc-c7086961330c - name: netassert - tags: [] - url: https://github.com/controlplaneio/netassert - nmap: - uuid: 08111dc3-bdc4-47d8-8f2e-10bb50a86882 - name: nmap - tags: [] - url: https://nmap.org/ - owasp-amass: - uuid: f085295e-46a3-4c8d-bbc3-1ac6b9dfcf2a - name: OWASP Amass - tags: [] - url: https://github.com/OWASP/Amass - k8spurger: - uuid: 8fea20ad-e332-4aa8-b1f1-aa9deb635dc1 - name: K8sPurger - tags: - - vulnerability - - scanner - - dast - - infrastructure - url: https://github.com/yogeshkk/K8sPurger - description: | - Hunt Unused Resources In Kubernetes. - pmd: - uuid: 00702aca-04d9-49ca-90d0-c32c199b26cb - name: PMD - tags: [] - eslint: - uuid: 6a0948a7-4781-4858-9766-f4303971b28b - name: eslint - tags: [] - url: https://eslint.org/ - findsecuritybugs: - uuid: f911d2b4-3e0c-424c-acf9-3bd363ef5078 - name: FindSecurityBugs - tags: [] - jsprime: - uuid: cccc2882-62ab-4175-afa1-58471017e8ed - name: jsprime - tags: [] - url: https://github.com/dpnishant/jsprime - bdd-mobile-security: - uuid: 3a8ba0ea-37dc-4124-983b-bbf9b4443d75 - name: '[bdd-mobile-security' - tags: [] - url: https://github.com/ing-bank/bdd-mobile-security-automation-framework - description: '[bdd-mobile-security-automation-framework](https://github.com/ing-bank/bdd-mobile-security-automation-framework)' - retire-js: - uuid: aa54a82c-d628-4d42-9bc8-1aa269cd91c7 - name: retire.js - tags: [] - url: https://github.com/RetireJS/retire.js/ - npm-audit: - uuid: 7c26484a-763c-437d-b953-d482a4fd7cf3 - name: npm audit - tags: [] - url: https://docs.npmjs.com/cli/audit - sigmahq: - uuid: 1adf1ac0-8572-407b-a358-3976d9a225e2 - name: SigmaHQ - tags: [] - url: https://github.com/SigmaHQ/sigma - dive-to-inspect-a-co: - uuid: 73419fb5-b13d-4242-83ec-86f36c7d73d5 - name: Dive to inspect a container images - tags: [] - url: https://github.com/wagoodman/dive - clusterscanner: - url: https://github.com/SDA-SE/clusterscanner - uuid: 3c9ac78c-0fd4-43f4-8211-c915f9ef685f - name: ClusterScanner - tags: - - docker - - image - - container - - vulnerability - - misconfiguration - - security-tools - - scanning - description: Discover vulnerabilities and container image misconfiguration - in production environments. - dockerfile-with-hado: - uuid: 94d993ad-ef6e-4d9f-b7a8-27ea68dc3005 - name: Dockerfile with hadolint - tags: [] - url: https://github.com/hadolint/hadolint - deployment-with-kube: - uuid: 95b717cd-5ad3-40b5-993b-13a63c382b1b - name: Deployment with kube-score - tags: [] - url: https://github.com/zegl/kube-score - kubesec: - uuid: 1e58f8d2-61e2-45bb-a17c-51516d0cc9ba - name: kubesec - tags: [] - url: https://kubesec.io - anchore-io: - uuid: fab2765d-8d96-4fc6-af96-dc9304ca41dc - name: Anchore.io - tags: [] - url: https://anchore.com/ - clair: - uuid: f10f5423-4dff-4bb7-99c8-9ce214645071 - name: Clair - tags: [] - url: https://github.com/quay/clair - openscap: - uuid: d0c6b3a0-b073-44d7-a187-c4ad8eaa6531 - name: OpenSCAP - tags: [] - url: https://www.open-scap.org/ - vuls: - uuid: 04261564-2fcf-4b73-8847-83b0d855e1c5 - name: Vuls - tags: [] - url: https://github.com/future-architect/vuls - kube-bench: - uuid: 8aeefd29-6220-45bf-aead-83eba2e9d055 - name: kube-bench - tags: [] - url: https://github.com/aquasecurity/kube-bench - trufflehog: - uuid: d90fefc9-4e5d-420f-ac87-eeb165bf0ee6 - name: truffleHog - tags: [] - url: https://github.com/dxa4481/truffleHog - go-pillage-registrie: - uuid: 382873e2-8604-4410-ae5e-b0f5ccdee835 - name: go-pillage-registries - tags: [] - url: https://github.com/nccgroup/go-pillage-registries - https-github-com-a: - uuid: 7f500e95-2110-44c4-a1f8-cd7ef5d9eb6b - name: https://github.com/aquasecurity/trivy - tags: [] - url: https://github.com/aquasecurity/trivy - registries-like-quay: - uuid: 8737c6c0-4e90-400a-bf9a-f8e399913b57 - name: Registries like quay - tags: [] - description: Registries like quay, dockerhub provide (commercial) offerings, - often not suitable for distroless images - dockerfilelint: - uuid: eba2685d-2d25-4961-8e4e-2957e7c07c30 - name: dockerfilelint - tags: - - sast - - docker - - dockerfile - url: https://github.com/replicatedhq/dockerfilelint - description: dockerfilelint is an node module that analyzes a Dockerfile - and looks for common traps, mistakes and helps enforce best practices. - threat-matrix-for-storage: - uuid: 1c56dbea-e067-44e2-8d3b-0a1205a70617 - name: Threat Matrix for Storage - url: https://www.microsoft.com/security/blog/2021/04/08/threat-matrix-for-storage/ - tags: - - documentation - - storage - - cluster - - kubernetes - defend-the-core-kubernetes: - uuid: b7a92886-aec9-4bf4-94c4-07cc191a97af - name: Defend the core kubernetes security at every layer - url: https://thenewstack.io/defend-the-core-kubernetes-security-at-every-layer/ - tags: - - documentation - - cluster - - kubernetes - business-friendly-vulnerability-metrics: - uuid: 3b99799c-e875-4cc2-aad7-5ce4564a1cde - name: Business friendly vulnerability management metrics - url: https://medium.com/uber-security-privacy/business-friendly-vulnerability-management-metrics-cfd702fd7705 - tags: - - documentation - - vulnerability - - vulnerability management system - kubescape: - uuid: 893d9f37-2142-4490-996c-e43b55064d3d - name: kubescape - url: https://github.com/armosec/kubescape - tags: - - kubernetes - - vulnerability - - misconfiguration - description: _Testing if Kubernetes is deployed securely as defined in Kubernetes - Hardening Guidance by to NSA and CISA_ - azuredevops: - uuid: b1b88bc5-5a22-4888-a27b-acce3d9fe29a - name: Improve code quality with branch policies - url: https://docs.microsoft.com/en-us/azure/devops/repos/git/branch-policies?view=azure-devops - tags: - - source-code-protection - - scm - github-policies: - uuid: 99211481-de9c-4358-880e-628366416a27 - name: About protected branches - url: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/defining-the-mergeability-of-pull-requests/about-protected-branches - tags: - - source-code-protection - - scm - sonarqube: - uuid: aa5ded61-5380-4da6-9474-afc36a397682 - name: In-Depth Linting of Your TypeScript While Coding - url: https://blog.sonarsource.com/in-depth-linting-of-your-typescript-while-coding - tags: - - ide - - linting - stylecop: - uuid: 0b7ec352-0c36-4de1-8912-617fc6c608fe - name: How to enforce a consistent coding style in your projects - url: https://www.meziantou.net/how-to-enforce-a-consistent-coding-style-in-your-projects.htm - tags: - - ide - - linting - fortify-vscode-extension: - uuid: 5b52a841-c281-45fd-b68f-0a93aa6fa398 - name: Fortify Extension for Visual Studio Code - url: https://marketplace.visualstudio.com/items?itemName=fortifyvsts.fortify-extension-for-vs-code - tags: - - ide - - sast - appscan-vscode-extension: - uuid: 3f5a493d-12d0-4468-b9fa-c3e4eae89ffb - name: HCL AppScan CodeSweep - url: https://marketplace.visualstudio.com/items?itemName=HCLTechnologies.hclappscancodesweep - tags: - - ide - - sast - checkmarx-vscode-extension: - uuid: cf1213fd-8bfa-4a97-bf8b-937c93f31005 - name: Setting Up the Visual Studio Code Extension Plugin - url: https://checkmarx.atlassian.net/wiki/spaces/SD/pages/1759216424/Setting+Up+the+Visual+Studio+Code+Extension+Plugin - tags: - - ide - - sast - pre-commit-microsoft: - uuid: 58ac9dea-b6c7-4698-904e-df89a9451c82 - name: DevSecOps control Pre-commit - url: https://docs.microsoft.com/en-us/azure/cloud-adoption-framework/secure/devsecops-controls#plan-and-develop - tags: - - pre-commit - pre-commit-synopsis: - uuid: 8da8d115-0f4e-40f0-a3ce-484a49e845fb - name: Building your DevSecOps pipeline 5 essential activities - url: https://www.synopsys.com/blogs/software-security/devsecops-pipeline-checklist/ - tags: - - pre-commit - dependencyTrack: - uuid: 500399bd-7dfc-47fd-99d8-b55cefb760a9 - name: Dependency-Track is an intelligent Component Analysis platform that - allows organizations to identify and reduce risk in the software supply - chain. Dependency-Track takes a unique and highly beneficial approach - by leveraging the capabilities of Software Bill of Materials (SBOM). - url: https://github.com/DependencyTrack/dependency-track - tags: - - sca - - inventory - - OpenSource - - Supply Chain - - vulnerability - juice-shop: - uuid: c021aa72-c71c-43e4-9573-717b74d6c19d - name: OWASP Juice Shop - tags: - - training - url: https://github.com/bkimminich/juice-shop - description: In case you do not have the budget to hire an external security - expert, an option is to use the OWASP JuiceShop on a "hacking Friday" - dvwa: - uuid: e1282ab3-7ffd-4ee5-a564-8e9af070979d - name: Damn Vulnerable Web Application - tags: - - training - description: Simple Application with intended vulnerabilities. HTML based. - loggingCheatSheet: - uuid: 032ca7cc-67dc-46bc-9702-3580a3c9d1a9 - name: OWASP Logging CheatSheet - url: https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html - tags: - - logging - - documentation - zap: - uuid: 84a2a907-a6fb-4ceb-8e21-f65c0d633445 - name: OWASP Zap - tags: - - vulnerability - - scanner - url: https://github.com/zaproxy/zaproxy - description: | - The OWASP Zed Attack Proxy (ZAP) is one of the world's most popular free security tools and is actively maintained by a dedicated international team of ... - secureCodeBox: - uuid: dc0995a5-ff13-4cfc-b95f-07bf8a30b6ab - name: OWASP secureCodeBox - tags: - - vulnerability - - scanner-orchestration - url: https://github.com/secureCodeBox/secureCodeBox - description: | - secureCodeBox is a kubernetes based, modularized toolchain for continuous security scans of your software project. Its goal is to orchestrate and easily automate a bunch of security-testing tools out of the box. - K8sPurger: - uuid: 7a019f5e-a77d-4f4a-89a6-d5107054a2cb - name: K8sPurger - tags: - - vulnerability - - scanner - - dast - - infrastructure - url: https://github.com/yogeshkk/K8sPurger - description: | - Hunt Unused Resources In Kubernetes. - hashicorp-vault: - uuid: e3a2ffc8-313f-437e-9663-b24591568209 - name: Hashicorp Vault - tags: - - authentication - - authorization - - secrets - - infrastructure - url: https://github.com/hashicorp/vault - description: | - A tool for secrets management, encryption as a service, and privileged access management. - stoplight-spectral: - uuid: 261f243e-f89c-4169-b076-b22a03ec00be - name: Spectral - tags: - - linting - - api - - documentation - url: https://github.com/stoplightio/spectral - description: | - Spectral is a flexible JSON/YAML linter built with extensibility in mind. - It uses JSON/YAML path rules to describe the problems you want to find. - api-oas-checker: - uuid: d2c9403d-9da2-4518-b33f-8b74b9c5ca3f - name: API OAS Checker - tags: - - linting - - api - - documentation - url: https://github.com/italia/api-oas-checker - description: | - A tool to check OpenAPI specifications using a comprehensive ruleset based - on API best practices. - coveragepy: - uuid: f011de6e-ab7c-4ec7-af55-03427271ab32 - name: Coverage.py - tags: - - testing - - coverage - url: https://github.com/nedbat/coveragepy - description: | - Code coverage measurement for Python - github-dependabot: - uuid: 5c0e817b-204e-4301-a315-2f7cc180c240 - name: Dependabot - tags: - - dependency - - dependency-management - - scm - url: https://github.com/dependabot/dependabot-core - description: | - Dependabot creates pull requests to keep your dependencies secure and up-to-date. - github-super-linter: - uuid: 94a7a85e-8064-46b4-929a-9e03fa292a9f - name: Super-Linter - tags: - - linting - - scm - url: https://github.com/github/super-linter - description: | - Lint code bases to catch common errors and enforce code style - schemathesis: - uuid: c9bbecf2-567b-4422-b29a-67b16385f32b - name: Schemathesis - tags: - - testing - - api - - documentation - url: https://github.com/schemathesis/schemathesis - description: | - Schemathesis is a tool for testing web applications and services by sending requests based on the Open API / Swagger schema. - martin-feature-toggles: - uuid: 83be6c60-6633-4c32-98de-7ae065c143c9 - name: Feature Toggles - tags: - - development - - architecture - url: https://martinfowler.com/articles/feature-toggles.html - description: | - Feature Toggles are a powerful technique, allowing teams to modify system behavior without changing code. (Pete Hodgson) - defectdojo-client: - uuid: 7ec30b0e-9681-427a-80ee-ab811d9e476f - name: DefectDojo Client - tags: - - Defectdojo - - statistics - url: https://github.com/SDA-SE/defectdojo-client - description: | - This projects contains the DefectDojo upload client and statistics client. It is for example used within the ClusterImageScanner. - falco: - uuid: 32b64e6e-5187-45e3-b4f3-f5f9a9739012 - name: Falco - tags: - - falco - - systemcall - - monitoring - url: https://github.com/falcosecurity/falco - description: | - Falco makes it easy to consume kernel events, and enrich those events with information from Kubernetes and the rest of the cloud native stack. - sammancoaching: - uuid: 9223be73-00da-400e-a910-3871734cff2f - name: sammancoaching - tags: - - documentation - - coaching - - education - url: https://sammancoaching.org/ - description: | - Security coaches work with software development teams to help them adopt better security practices. - terraform: - uuid: 0d63f907-37fe-4375-88a5-a5e252732618 - name: terraform - tags: - - IaC - url: https://www.terraform.io/ - description: | - Terraform enables infrastructure automation for provisioning, compliance, and management of any cloud, datacenter, and service. - packj: - uuid: 5d8b27ac-286e-47a5-b23f-769eb6d74e4a - name: packj - tags: - - OpenSource - - Supply Chain - - vulnerability - url: https://github.com/ossillate-inc/packj - description: | - Packj is a tool to detect software supply chain attacks. It can detect malicious, vulnerable, abandoned, typo-squatting, and other "risky" packages from popular open-source package registries, such as NPM, RubyGems, and PyPI. - apiMyth: - uuid: 6150533e-58ca-4b52-a9b2-6226545d9ea0 - name: Top 5 API Security Myths That Are Crushing Your Business - tags: - - documentation - - waf - url: https://thehackernews.com/2022/11/top-5-api-security-myths-that-are.html - description: | - There are several myths and misconceptions about API security. These myths about securing APIs are crushing your business - references: - samm2: - - I-SD-1-B + - uuid: e3a2ffc8-313f-437e-9663-b24591568209 + name: Hashicorp Vault + tags: + - authentication + - authorization + - secrets + - infrastructure + url: https://github.com/hashicorp/vault + description: | + A tool for secrets management, encryption as a service, and privileged access management. + references: + samm2: + - I-SD-B-1 iso27001-2017: - 9.4.5 - 14.2.6 @@ -1469,11 +530,11 @@ Build and Deployment: - 8.31 d3f: - ApplicationConfigurationHardening + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Deployment/subsection/Environment%20depending%20configuration%20parameters%20%28secrets%29 isImplemented: false - evidence: "" - comments: "" tags: - - none + - secret Evaluation of the trust of used components: uuid: 0de465a6-55a7-4343-af79-948bb5ff10ba risk: Application and system components like Open Source libraries or images @@ -1497,6 +558,8 @@ Build and Deployment: a signing key. tags: [] url: https://medium.com/slalom-technology/build-a-kubernetes-dynamic-admission-controller-for-container-registry-whitelisting-b46fe020e22d + test-url-expects: + - 403 - uuid: 5d8b27ac-286e-47a5-b23f-769eb6d74e4a name: packj tags: @@ -1508,7 +571,7 @@ Build and Deployment: Packj is a tool to detect software supply chain attacks. It can detect malicious, vulnerable, abandoned, typo-squatting, and other "risky" packages from popular open-source package registries, such as NPM, RubyGems, and PyPI. references: samm2: - - O-EM-1-A + - O-EM-A-1 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 14.2.1 @@ -1517,11 +580,73 @@ Build and Deployment: - Not explicitly covered by ISO 27001 - too specific - 8.25 - 8.27 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Deployment/subsection/Evaluation%20of%20the%20trust%20of%20used%20components isImplemented: false evidence: "" comments: "" tags: - none + Inventory of production artifacts: + uuid: 83057028-0b77-4d2e-8135-40969768ae88 + risk: In case a vulnerability of severity high or critical exists, it needs + to be known where an artifacts (e.g. container image) with that vulnerability + is deployed. + measure: A documented inventory of artifacts in production like container images + exists (gathered manually or automatically). + dependsOn: + - 67e1a9aa-9fbf-4ec5-a2de-400f01960c51 # Automated deployment process + - 2a44b708-734f-4463-b0cb-86dc46344b2f # Inventory of production components + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 3 + usefulness: 3 + level: 2 + implementation: + - uuid: 2210e02b-a856-4da4-8732-5acd77e20fca + name: Backstage + tags: + - documentation + - inventory + url: https://github.com/backstage/backstage + description: | + Backstage is an open-source platform designed to create developer portals. At its core is a centralized software catalog that brings organization to your microservices and infrastructure. + - uuid: 500399bd-7dfc-47fd-99d8-b55cefb760a9 + name: Dependency-Track + description: | + Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track takes a unique and highly beneficial approach by leveraging the capabilities of Software Bill of Materials (SBOM). + url: https://github.com/DependencyTrack/dependency-track + tags: + - sca + - inventory + - OpenSource + - Supply Chain + - vulnerability + - inventory + - uuid: 879bd03f-8de1-43d6-b492-d974181bfa6c + name: Image Metadata Collector + tags: + - documentation + - inventory + - kubernetes + url: https://github.com/SDA-SE/image-metadata-collector/ + description: | + Collects namespaces and namespaces including responsible team and contact info through annotations/labels from Kubernetes clusters. Results are available in JSON and can be uploaded to S3, github and an API. + references: + samm2: + - I-SB-B-1 + - D-TA-B-1 + iso27001-2017: + - 8.1 + - 8.2 + iso27001-2022: + - 5.9 + - 5.12 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Deployment/subsection/Inventory%20of%20production%20artifacts + tags: + - inventory Handover of confidential parameters: uuid: 94a96f79-8bd6-4904-97c0-994ff88f176a risk: Parameters are often used to set credentials, for example by starting @@ -1538,10 +663,10 @@ Build and Deployment: level: 3 implementation: "" dependsOn: - - Environment depending configuration parameters (secrets) + - df428c9d-efa0-4226-9f47-a15bb53f822b # Environment depending configuration parameters (secrets) references: samm2: - - I-SD-2-B + - I-SD-B-2 iso27001-2017: - 14.1.3 - 13.1.3 @@ -1556,21 +681,21 @@ Build and Deployment: - 8.24 d3f: - ApplicationConfigurationHardening + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Deployment/subsection/Handover%20of%20confidential%20parameters isImplemented: false - evidence: "" - comments: "" tags: - - none - Inventory of dependencies: + - secret + Inventory of production dependencies: uuid: 13e9757e-58e2-4277-bc0f-eadc674891e6 - risk: In case a vulnerability of severity high or critical is known by the organization, - it needs to be known where an artifacts with that vulnerability is deployed - with which dependencies. - measure: A documented inventory of dependencies used in images and containers - exists. + risk: Delayed identification of components and their vulnerabilities in production. + In case a vulnerability is known by the organization, it needs to be known + where an artifacts with that vulnerability is deployed with which dependencies. + measure: A documented inventory of dependencies used in artifacts like container + images and containers exists. dependsOn: - - Defined deployment process - - SBOM of components + - 83057028-0b77-4d2e-8135-40969768ae88 # Inventory of production artifacts + - 2858ac12-0179-40d9-9acf-1b839c030473 # SBOM of components difficultyOfImplementation: knowledge: 2 time: 2 @@ -1578,11 +703,18 @@ Build and Deployment: usefulness: 3 level: 3 implementation: + - uuid: 2210e02b-a856-4da4-8732-5acd77e20fca + name: Backstage + tags: + - documentation + - inventory + url: https://github.com/backstage/backstage + description: | + Backstage is an open-source platform designed to create developer portals. At its core is a centralized software catalog that brings organization to your microservices and infrastructure. - uuid: 500399bd-7dfc-47fd-99d8-b55cefb760a9 - name: Dependency-Track is an intelligent Component Analysis platform that - allows organizations to identify and reduce risk in the software supply - chain. Dependency-Track takes a unique and highly beneficial approach by - leveraging the capabilities of Software Bill of Materials (SBOM). + name: Dependency-Track + description: | + Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track takes a unique and highly beneficial approach by leveraging the capabilities of Software Bill of Materials (SBOM). url: https://github.com/DependencyTrack/dependency-track tags: - sca @@ -1590,49 +722,35 @@ Build and Deployment: - OpenSource - Supply Chain - vulnerability + - inventory + - uuid: 879bd03f-8de1-43d6-b492-d974181bfa6c + name: Image Metadata Collector + tags: + - documentation + - inventory + - kubernetes + url: https://github.com/SDA-SE/image-metadata-collector/ + description: | + Collects namespaces and namespaces including responsible team and contact info through annotations/labels from Kubernetes clusters. Results are available in JSON and can be uploaded to S3, github and an API. references: samm2: - - I-SD-2-A - iso27001-2017: - - 8.1 - - 8.2 - iso27001-2022: - - 5.9 - - 5.12 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Inventory of running artifacts: - uuid: 83057028-0b77-4d2e-8135-40969768ae88 - risk: In case a vulnerability of severity high or critical exists, it needs - to be known where an artifacts (e.g. container image) with that vulnerability - is deployed. - measure: A documented inventory or a possibility to gather the needed information. - dependsOn: - - Defined deployment process - difficultyOfImplementation: - knowledge: 2 - time: 2 - resources: 3 - usefulness: 3 - level: 3 - implementation: [] - references: - samm2: - - I-SD-2-A + - I-SB-B-3 + - I-SB-B-2 + - I-SB-B-1 iso27001-2017: - 8.1 - 8.2 iso27001-2022: - 5.9 - 5.12 - isImplemented: false - evidence: "" + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Deployment/subsection/Inventory%20of%20production%20dependencies comments: "" tags: - - none + - inventory + - sbom + - scanning + - sca Rolling update on deployment: uuid: 85d52588-f542-4225-a338-20dc22a5508d risk: While a deployment is performed, the application can not be reached. @@ -1656,10 +774,11 @@ Build and Deployment: name: rolling update tags: [] dependsOn: - - Defined deployment process + - 67e1a9aa-9fbf-4ec5-a2de-400f01960c51 # Automated deployment process references: samm2: - - I-SD-1-A + - I-SD-A-2 + - I-SD-A-3 iso27001-2017: - 12.5.1 - 14.2.2 @@ -1668,6 +787,79 @@ Build and Deployment: - 8.19 - 8.32 - 8.14 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Deployment/subsection/Rolling%20update%20on%20deployment + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Canary deployment: + uuid: c4204a32-2545-4424-b524-d1cc52b46abd + description: |- + A *canary deployment* gradually shifts a small fraction of production + traffic to a new artifact version while monitoring service-level + indicators and security signals. If error rates, latency, or security + scanners (such as DAST probes against the canary fleet) report + anomalies, traffic is rolled back automatically before the new + version reaches the broader production population. + + Compared to *Blue/Green Deployment*, canary requires only a small + delta in infrastructure cost (commonly 5-10% additional capacity + rather than a doubled environment) but demands more sophisticated + traffic-control infrastructure such as a service mesh, an + application load balancer with weighted routing, or a feature-flag + platform. + risk: |- + A new artifact version can introduce regressions or security + issues. Promoting it to 100% of production traffic in one step + exposes the entire user population to those issues before they + can be detected. + measure: |- + Adopt a canary deployment strategy in which a small percentage of + production traffic (commonly 1-10%) is routed to the new artifact + version for a defined observation window. Promotion to higher + traffic percentages is gated on automated SLI checks (error rate, + latency, saturation) and security checks (DAST, runtime anomaly + detection). Rollback must be automated and triggered by gate + failure without human intervention. + assessment: | + - Canary stage exists in the deployment pipeline with a configured + initial traffic percentage and observation window. + - Automated promotion and rollback gates are defined based on SLIs + and security signals. + - Audit logs of canary deployments and their promotion or rollback + decisions are retained. + difficultyOfImplementation: + knowledge: 3 + time: 2 + resources: 2 + usefulness: 3 + level: 4 + implementation: + - uuid: cd49f792-a158-4b93-ac55-fd773954b217 + name: Canary release + tags: [] + url: https://martinfowler.com/bliki/CanaryRelease.html + dependsOn: + - 67e1a9aa-9fbf-4ec5-a2de-400f01960c51 # Automated deployment process + references: + samm2: + - I-SD-A-3 + iso27001-2017: + - 12.1.2 + - 12.5.1 + - 14.2.2 + - 14.2.9 + - 17.2.1 + iso27001-2022: + - 8.14 + - 8.19 + - 8.29 + - 8.31 + - 8.32 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Deployment/subsection/Canary%20deployment isImplemented: false evidence: "" comments: "" @@ -1691,10 +883,11 @@ Build and Deployment: url: https://github.com/moby/moby tags: [] dependsOn: - - Defined build process + - f6f7737f-25a9-4317-8de2-09bf59f29b5b # Defined build process references: samm2: - - I-SD-2-A + - I-SD-A-2 + - I-SD-A-3 iso27001-2017: - 14.3.1 - 14.2.8 @@ -1703,6 +896,8 @@ Build and Deployment: - 8.33 - 8.29 - 8.31 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Deployment/subsection/Same%20artifact%20for%20environments isImplemented: false evidence: "" comments: "" @@ -1735,9 +930,10 @@ Build and Deployment: description: | Feature Toggles are a powerful technique, allowing teams to modify system behavior without changing code. (Pete Hodgson) dependsOn: - - Same artifact for environments + - a854b48d-83bd-4f8d-8621-a0bdd470837f # Same artifact for environments references: - samm2: [] + samm2: + - I-SD-A-2 iso27001-2017: - 14.3.1 - 14.2.8 @@ -1749,6 +945,51 @@ Build and Deployment: - 8.31 d3f: - ApplicationConfigurationHardening + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Deployment/subsection/Usage%20of%20feature%20toggles + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Blue/Green Deployment: + uuid: 0cb2626b-fb0d-4a0f-9688-57f787310d97 + risk: A new artifact's version can have unknown defects. + measure: |- + Using a blue/green deployment strategy increases application availability + and reduces deployment risk by simplifying the rollback process if a deployment fails. + difficultyOfImplementation: + knowledge: 1 + time: 2 + resources: 1 + usefulness: 2 + level: 5 + implementation: + - uuid: 4fb3d95c-07c0-4cbb-b396-5054aba751c2 + name: Blue/Green Deployments + tags: [] + url: https://martinfowler.com/bliki/BlueGreenDeployment.html + dependsOn: + - 73aaae0b-5d68-4953-9fa4-fd25bf665f2a # Smoke Test + references: + samm2: + - I-SD-A-3 + iso27001-2017: + - 17.2.1 + - 12.1.1 + - 12.1.2 + - 12.1.4 + - 12.5.1 + - 14.2.9 + iso27001-2022: + - 8.14 + - 5.37 + - 8.31 + - 8.32 + - 8.19 + - 8.29 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Deployment/subsection/Blue%2FGreen%20Deployment isImplemented: false evidence: "" comments: "" @@ -1757,19 +998,27 @@ Build and Deployment: Patch Management: A patch policy is defined: uuid: 99415139-6b50-441b-89e1-0aa59accd43d - risk: Vulnerabilities in running artifacts stay for long and might get exploited. - measure: A patch policy for all artifacts (e.g. in images) is defined. How often - is an image rebuilt? + description: | + A patch policy defines how and when software components, images, and dependencies are updated. A patch policy ensures that all these artifacts are regularly reviewed and updated, reducing the window of exposure to known threats. The policy should specify the frequency, responsibilities, and documentation requirements for patching. + risk: Vulnerabilities in running artifacts may persist for a long time and might + be exploited. + measure: Define a patch policy for all artifacts (e.g. in images) is defined. + How often is an image rebuilt? + assessment: | + - Patch policy is documented and accessible to relevant staff. + - The policy defines patch frequency and responsible roles. + - Patch actions and exceptions are logged and reviewed. + - Evidence of regular patching and policy review is available. + level: 1 difficultyOfImplementation: knowledge: 3 time: 1 resources: 2 usefulness: 4 - level: 1 implementation: [] references: samm2: - - O-EM-1-B + - O-EM-B-1 iso27001-2017: - 12.6.1 - 12.5.1 @@ -1778,6 +1027,8 @@ Build and Deployment: - 8.8 - 8.19 - 8.27 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Patch%20Management/subsection/A%20patch%20policy%20is%20defined isImplemented: false evidence: "" comments: "" @@ -1785,26 +1036,34 @@ Build and Deployment: - patching Automated PRs for patches: uuid: 8ae0b92c-10e0-4602-ba22-7524d6aed488 - risk: Components with known (or unknown) vulnerabilities might stay for long - and get exploited, even when a patch is available. - measure: Fast patching of third party component is needed. The DevOps way is - to have an automated pull request for new components. This includes * Applications - * Virtualized operating system components (e.g. container images) * Operating - Systems * Infrastructure as Code/GitOps (e.g. argocd based on a git repository - or terraform) + description: | + Automated PRs for patches ensure that updates for outdated or vulnerable dependencies are created and proposed without manual intervention. Tools continuously monitor for new versions or security advisories and immediately generate pull requests to update affected components in code, container images, or infrastructure. This process ensures that available patches are quickly visible to developers and can be reviewed and merged with minimal delay, reducing the risk window for known vulnerabilities. + risk: | + Components with known vulnerabilities might persist for a long time and be exploited, even when a patch is available. + measure: | + Fast patching of third-party components is needed. The DevOps way is to have an automated pull request for new components. This includes: + * Applications + * Virtualized operating system components (e.g., container images) + * Operating systems + * Infrastructure as Code/GitOps (e.g., ArgoCD based on a git repository or Terraform) + assessment: | + - Automated PR tooling is enabled for all relevant repositories. + - PRs are created automatically for outdated or vulnerable dependencies. + - PRs are reviewed and merged according to the defined patch policy. + - Evidence of automated PRs and patching activity is available. + level: 1 difficultyOfImplementation: knowledge: 2 time: 2 resources: 2 - usefulness: 5 - level: 1 + usefulness: 4 implementation: - uuid: d6292c7d-aab7-43d3-a7c6-1e443b5c1aa4 name: dependabot tags: - auto-pr - patching - url: https://dependabot.com/ + url: https://docs.github.com/en/code-security/getting-started/dependabot-quickstart-guide - uuid: 42ddb49f-48f2-4a3a-b76a-e73104ac6971 name: Jenkins tags: [] @@ -1814,6 +1073,8 @@ Build and Deployment: tags: - IaC url: https://www.terraform.io/ + test-url-expects: + - 308 description: | Terraform enables infrastructure automation for provisioning, compliance, and management of any cloud, datacenter, and service. - uuid: 8228266e-e04f-40ba-94c8-bfadc5310920 @@ -1824,49 +1085,15 @@ Build and Deployment: url: https://github.com/renovatebot/renovate references: samm2: - - O-EM-1-B + - O-EM-B-1 iso27001-2017: - 12.6.1 - 14.2.5 iso27001-2022: - - 8.8 - - 8.27 - comments: "" - tags: - - patching - Automated deployment of automated PRs: - uuid: 08f27c26-2c6a-47fe-9458-5e88f188085d - description: Automated merges of automated created PRs for outdated dependencies. - risk: Even if automated dependencies PRs are merged, they might not be deployed. - This results in vulnerabilities in running artifacts stay for too long and - might get exploited. - measure: | - After merging of an automated dependency PR, automated deployment is needed, - difficultyOfImplementation: - knowledge: 3 - time: 3 - resources: 1 - usefulness: 3 - level: 3 - dependsOn: - - Automated merge of automated PRs - implementation: - - uuid: 0d63f907-37fe-4375-88a5-a5e252732618 - name: terraform - tags: - - IaC - url: https://www.terraform.io/ - description: | - Terraform enables infrastructure automation for provisioning, compliance, and management of any cloud, datacenter, and service. - - uuid: fdb0e7cc-d3dd-4a2b-9f45-7d403001294f - name: argoCD - tags: - - deployment - url: https://argo-cd.readthedocs.io/en/stable/ - references: - samm2: [] - iso27001-2017: [] - iso27001-2022: [] + - "8.8" + - "8.27" + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Patch%20Management/subsection/Automated%20PRs%20for%20patches comments: "" tags: - patching @@ -1885,14 +1112,14 @@ Build and Deployment: usefulness: 3 level: 2 dependsOn: - - Automated PRs for patches + - 8ae0b92c-10e0-4602-ba22-7524d6aed488 # Automated PRs for patches implementation: - uuid: d6292c7d-aab7-43d3-a7c6-1e443b5c1aa4 name: dependabot tags: - auto-pr - patching - url: https://dependabot.com/ + url: https://docs.github.com/en/code-security/getting-started/dependabot-quickstart-guide - uuid: 8228266e-e04f-40ba-94c8-bfadc5310920 name: renovate tags: @@ -1901,11 +1128,13 @@ Build and Deployment: url: https://github.com/renovatebot/renovate references: samm2: - - O-EM-2-B + - O-EM-B-2 iso27001-2017: - 12.6.1 iso27001-2022: - 8.8 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Patch%20Management/subsection/Automated%20merge%20of%20automated%20PRs comments: "" tags: - patching @@ -1932,11 +1161,13 @@ Build and Deployment: implementation: [] references: samm2: - - O-EM-1-B + - O-EM-B-2 iso27001-2017: - 12.6.1 iso27001-2022: - 8.8 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Patch%20Management/subsection/Nightly%20build%20of%20images%20%28base%20images%29 isImplemented: false evidence: "" comments: "" @@ -1968,19 +1199,23 @@ Build and Deployment: - uuid: be757cb3-63d6-4a63-9c4e-e10b746fd47a name: Fedora CoreOS tags: [] - url: https://getfedora.org/coreos + url: https://fedoraproject.org/coreos/ - uuid: a92c4f8f-a918-406a-b1e5-70acfc0477bd name: Distroless or Alpine tags: [] url: https://itnext.io/which-container-images-to-use-distroless-or-alpine-96e3dab43a22 + test-url-expects: + - 403 references: samm2: - - I-SB-2 + - I-SB-B-2 iso27001-2017: - hardening is missing in ISO 27001 - 14.2.1 iso27001-2022: - 8.25 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Patch%20Management/subsection/Reduction%20of%20the%20attack%20surface evidence: "" comments: "" tags: @@ -2013,30 +1248,70 @@ Build and Deployment: implementation: [] references: samm2: - - O-EM-1-B + - O-EM-B-1 iso27001-2017: - 12.6.1 iso27001-2022: - 8.8 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Patch%20Management/subsection/Usage%20of%20a%20maximum%20lifetime%20for%20images evidence: "" comments: "" tags: - patching - Usage of a short maximum lifetime for images: - uuid: 6b96e5a0-ce34-4ea4-a88f-469d3b84546e - description: |- - The maximum lifetime for a Docker container refers to the duration a container - should be allowed to run before it is considered outdated, stale, or insecure. - There is not a fixed, universally applicable maximum lifetime for a Docker - container, as it varies depending on the specific use case, application - requirements, and security needs. As a best practice, it is essential to define - a reasonable maximum lifetime for containers to ensure that you consistently - deploy the most recent, patched, and secure versions of both your custom base - images and third-party images. - risk: Vulnerabilities in running containers stay for too long and might get - exploited. - measure: | - A good practice is to perform the build and deployment daily or even just-in-time, when a new component (e.g. package) for the image is available. + Automated deployment of automated PRs: + uuid: 08f27c26-2c6a-47fe-9458-5e88f188085d + risk: Even if automated dependencies PRs are merged, they might not be deployed. + This results in vulnerabilities in running artifacts stay for too long and + might get exploited. + measure: | + After merging of an automated dependency PR, automated deployment is needed, + difficultyOfImplementation: + knowledge: 3 + time: 3 + resources: 1 + usefulness: 3 + level: 3 + dependsOn: + - f2594f8f-1cd6-45f9-af29-eaf3315698eb # Automated merge of automated PRs + implementation: + - uuid: 0d63f907-37fe-4375-88a5-a5e252732618 + name: terraform + tags: + - IaC + url: https://www.terraform.io/ + test-url-expects: + - 308 + description: | + Terraform enables infrastructure automation for provisioning, compliance, and management of any cloud, datacenter, and service. + - uuid: fdb0e7cc-d3dd-4a2b-9f45-7d403001294f + name: argoCD + tags: + - deployment + url: https://argo-cd.readthedocs.io/en/stable/ + references: + samm2: [] + iso27001-2017: [] + iso27001-2022: [] + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Patch%20Management/subsection/Automated%20deployment%20of%20automated%20PRs + tags: + - none + Usage of a short maximum lifetime for images: + uuid: 6b96e5a0-ce34-4ea4-a88f-469d3b84546e + description: |- + The maximum lifetime for a Docker container refers to the duration a container + should be allowed to run before it is considered outdated, stale, or insecure. + There is not a fixed, universally applicable maximum lifetime for a Docker + container, as it varies depending on the specific use case, application + requirements, and security needs. As a best practice, it is essential to define + a reasonable maximum lifetime for containers to ensure that you consistently + deploy the most recent, patched, and secure versions of both your custom base + images and third-party images. + risk: Vulnerabilities in running containers stay for too long and might get + exploited. + measure: | + A good practice is to perform the build and deployment daily or even just-in-time, when a new component (e.g. package) for the image is available. difficultyOfImplementation: knowledge: 3 time: 4 @@ -2045,7 +1320,7 @@ Build and Deployment: level: 4 implementation: - uuid: 1a463242-b480-46f6-a912-b51ec1c1558d - name: "Sample concept: \n(1" + name: Sample concept tags: [] description: "Sample concept: \n(1) each container has a set lifetime and is killed / replaced with a new container multiple times a day where you @@ -2060,11 +1335,13 @@ Build and Deployment: is being used and not the buggy newer one." references: samm2: - - O-EM-2-B + - O-EM-B-2 iso27001-2017: - 12.6.1 iso27001-2022: - 8.8 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Patch%20Management/subsection/Usage%20of%20a%20short%20maximum%20lifetime%20for%20images isImplemented: false evidence: "" comments: "" @@ -2072,33 +1349,64 @@ Build and Deployment: - patching Culture and Organization: Design: - Conduction of advanced threat modeling: - uuid: ae22dafd-bcd6-41ee-ba01-8b7fe6fc1ad9 - risk: Inadequate identification of business and technical risks. - measure: Threat modeling is performed by using reviewing user stories and producing - security driven data flow diagrams. - difficultyOfImplementation: - knowledge: 4 - time: 3 - resources: 2 - usefulness: 3 - level: 4 - dependsOn: - - Conduction of simple threat modeling on technical level - - Creation of threat modeling processes and standards + Conduction of simple threat modeling on technical level: + uuid: 47419324-e263-415b-815d-e7161b6b905e description: | - **Example High Maturity Scenario:** + # OWASP SAMM Description + Threat modeling is a structured activity for identifying, evaluating, and managing system threats, architectural design flaws, and recommended security mitigations. It is typically done as part of the design phase or as part of a security assessment. - Based on a detailed threat model defined and updated through code, the team decides the following: + Threat modeling is a team exercise, including product owners, architects, security champions, and security testers. At this maturity level, expose teams and stakeholders to threat modeling to increase security awareness and to create a shared vision on the security of the system. - * Local encrypted caches need to expire and auto-purged. - * Communication channels encrypted and authenticated. - * All secrets persisted in shared secrets store. - * Frontend designed with permissions model integration. - * Permissions matrix defined. - * Input is escaped output is encoded appropriately using well established libraries. + At maturity level 1, you perform threat modeling ad-hoc for high-risk applications and use simple threat checklists, such as STRIDE. Avoid lengthy workshops and overly detailed lists of low-relevant threats. Perform threat modeling iteratively to align to more iterative development paradigms. If you add new functionality to an existing application, look only into the newly added functions instead of trying to cover the entire scope. A good starting point is the existing diagrams that you annotate during discussion workshops. Always make sure to persist the outcome of a threat modeling discussion for later use. + + Your most important tool to start threat modeling is a whiteboard, smartboard, or a piece of paper. Aim for security awareness, a simple process, and actionable outcomes that you agree upon with your team. Once requirements are gathered and analysis is performed, implementation specifics need to be defined. The outcome of this stage is usually a diagram outlining data flows and a general system architecture. This presents an opportunity for both threat modeling and attaching security considerations to every ticket and epic that is the outcome of this stage. + + Source: https://owaspsamm.org/model/design/threat-assessment/stream-b/ + # OWASP Project Integration Description + There is some great advice on threat modeling out there *e.g.* [this](https://arstechnica.com/information-technology/2017/07/how-i-learned-to-stop-worrying-mostly-and-love-my-threat-model/) article or [this](https://www.microsoft.com/en-us/securityengineering/sdl/threatmodeling) one. + + A bite sized primer by Adam Shostack himself can be found [here](https://adam.shostack.org/blog/2018/03/threat-modeling-panel-at-appsec-cali-2018/). + + OWASP includes a short [article](https://wiki.owasp.org/index.php/Category:Threat_Modeling) on Threat Modeling along with a relevant [Cheatsheet](https://cheatsheetseries.owasp.org/cheatsheets/Threat_Modeling_Cheat_Sheet.html). Moreover, if you're following OWASP SAMM, it has a short section on [Threat Assessment](https://owaspsamm.org/model/design/threat-assessment/). + + There's a few projects that can help with creating Threat Models at this stage, [PyTM](https://github.com/izar/pytm) is one, [ThreatSpec](https://github.com/threatspec/threatspec) is another. + + > Note: _A threat model can be as simple as a data flow diagram with attack vectors on every flow and asset and equivalent remediations. An example can be found below._ + + ![Threat Model](https://github.com/OWASP/www-project-integration-standards/raw/master/writeups/owasp_in_sdlc/images/threat_model.png "Threat Model") + + Last, if the organizations maps Features to Epics, the Security Knowledge Framework (SKF) can be used to facilitate this process by leveraging it's questionnaire function. + + ![SKF](https://github.com/OWASP/www-project-integration-standards/raw/master/writeups/owasp_in_sdlc/images/skf_qs.png "SKF") + + This practice has the side effect that it trains non-security specialists to think like attackers. + + The outcomes of this stage should help lay the foundation of secure design and considerations. + + **Example Low Maturity Scenario:** + + Following vague feature requirements the design includes caching data to a local unencrypted database with a hardcoded password. + + Remote data store access secrets are hardcoded in the configuration files. All communication between backend systems is plaintext. + + Frontend serves data over GraphQL as a thin layer between caching system and end user. + + GraphQL queries are dynamically translated to SQL, Elasticsearch and NoSQL queries. Access to data is protected with basic auth set to _1234:1234_ for development purposes. Source: OWASP Project Integration Project + risk: Technical related threats are discovered too late in the development and + deployment process. + measure: | + Perform threat modeling of technical features during product sprint planning using simple checklists and diagrams. Document identified threats and mitigations for new or changed functionality. + assessment: | + - Evidence of threat modeling activities exists for high-risk applications, including annotated diagrams and documented threats/mitigations. + - Activities are performed during sprint planning and involve relevant stakeholders. Outcomes are recorded and accessible for review. + level: 1 + difficultyOfImplementation: + knowledge: 2 + time: 3 + resources: 1 + usefulness: 3 implementation: - uuid: c0533602-11b7-4838-93cc-a40556398163 name: Whiteboard @@ -2138,14 +1446,9 @@ Culture and Organization: - owasp - defender url: https://owaspsamm.org/model/design/threat-assessment/stream-b/ - - uuid: e8332407-5149-459e-a2fe-c5c78c7ec55c - name: Threagile - tags: - - threat-modeling - url: https://github.com/Threagile/threagile - uuid: 1c56dbea-e067-44e2-8d3b-0a1205a70617 name: Threat Matrix for Storage - url: https://www.microsoft.com/security/blog/2021/04/08/threat-matrix-for-storage/ + url: https://www.microsoft.com/en-US/security/blog/2021/04/08/threat-matrix-for-storage/ tags: - documentation - storage @@ -2153,7 +1456,7 @@ Culture and Organization: - kubernetes references: samm2: - - D-TA-2-B + - D-TA-B-2 iso27001-2017: - Not explicitly covered by ISO 27001 - May be part of risk assessment @@ -2164,6 +1467,38 @@ Culture and Organization: - May be part of risk assessment - 5.12 - 8.25 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Design/subsection/Conduction%20of%20simple%20threat%20modeling%20on%20technical%20level + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Information security targets are communicated: + uuid: 1b9281b9-48e2-4c01-9ac6-9db9931c4885 + risk: Employees don't know their organizations security targets. Therefore security + is not considered during development and administration as much as it should + be. + measure: Transparent and timely communication of the security targets by senior + management is essential to ensure teams' buy-in and support. + difficultyOfImplementation: + knowledge: 1 + time: 1 + resources: 1 + usefulness: 3 + level: 2 + implementation: [] + references: + samm2: + - G-SM-A-2 + iso27001-2017: + - 5.1.1 + - 7.2.1 + iso27001-2022: + - 5.1 + - 5.4 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Design/subsection/Information%20security%20targets%20are%20communicated isImplemented: false evidence: "" comments: "" @@ -2184,7 +1519,8 @@ Culture and Organization: implementation: [] references: samm2: - - D-TA-2-B + - D-TA-B-1 + - D-TA-A-2 iso27001-2017: - Not explicitly covered by ISO 27001 - May be part of risk assessment @@ -2195,23 +1531,137 @@ Culture and Organization: - May be part of risk assessment - 5.12 - 8.25 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Design/subsection/Conduction%20of%20simple%20threat%20modeling%20on%20business%20level isImplemented: false evidence: "" comments: "" tags: - none - Conduction of simple threat modeling on technical level: - uuid: 47419324-e263-415b-815d-e7161b6b905e - risk: Technical related threats are discovered too late in the development and - deployment process. - measure: Threat modeling of technical features is performed during the product - sprint planning. + Creation of simple abuse stories: + uuid: bacf85b6-5bc0-405d-b5ba-a5d971467cc1 + risk: User stories mostly don't consider security implications. Security flaws + are discovered too late in the development and deployment process. + measure: Abuse stories are created during the creation of user stories. difficultyOfImplementation: knowledge: 2 - time: 3 + time: 2 resources: 1 + usefulness: 4 + level: 3 + implementation: + - uuid: bb5b8988-021b-452a-a914-bd36887b6860 + name: Don't Forget EVIL User stories + tags: [] + url: https://medium.com/serious-scrum/evil-user-storys-story-telling-for-it-security-e4a9ec94193c + test-url-expects: + - 403 + description: Do not Forget _Evil_ User Stories and [Practical Security Stories + and Security Tasks for Agile Development Environments](https://safecode.org/publication/SAFECode_Agile_Dev_Security0712.pdf) + dependsOn: + - 47419324-e263-415b-815d-e7161b6b905e # Conduction of simple threat modeling on technical level + - dd5ed7c1-bdbf-400f-b75f-6d3953a1a04e # Creation of threat modeling processes and standards + references: + samm2: + - D-TA-B-2 + iso27001-2017: + - Not explicitly covered by ISO 27001 + - May be part of project management + - 6.1.5 + - May be part of risk assessment + - 8.1.2 + iso27001-2022: + - Not explicitly covered by ISO 27001 + - May be part of project management + - 5.8 + - May be part of risk assessment + - 5.9 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Design/subsection/Creation%20of%20simple%20abuse%20stories + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Creation of threat modeling processes and standards: + uuid: dd5ed7c1-bdbf-400f-b75f-6d3953a1a04e + risk: Inadequate identification of business and technical risks. + measure: Creation of threat modeling processes and standards through the organization + helps to enhance the security culture and provide more structure to the threat + model exercises. + difficultyOfImplementation: + knowledge: 4 + time: 3 + resources: 2 usefulness: 3 - level: 1 + level: 3 + description: "" + implementation: + - uuid: fd0f282b-a065-4464-beed-770c604a5f52 + name: Threat Modeling Playbook + tags: + - owasp + - defender + - threat-modeling + - whiteboard + url: https://github.com/Toreon/threat-model-playbook + - uuid: b5eaf710-e05f-49e5-a649-13afde9aeb52 + name: OWASP SAMM + tags: + - threat-modeling + - owasp + - defender + url: https://owaspsamm.org/model/design/threat-assessment/stream-b/ + dependsOn: + - 47419324-e263-415b-815d-e7161b6b905e # Conduction of simple threat modeling on technical level + references: + samm2: + - D-TA-B-3 + - D-TA-B-2 + iso27001-2017: + - Not explicitly covered by ISO 27001 + - May be part of risk assessment + - 8.2.1 + - 14.2.1 + iso27001-2022: + - Not explicitly covered by ISO 27001 + - May be part of risk assessment + - 5.12 + - 8.25 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Design/subsection/Creation%20of%20threat%20modeling%20processes%20and%20standards + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Conduction of advanced threat modeling: + uuid: ae22dafd-bcd6-41ee-ba01-8b7fe6fc1ad9 + risk: Inadequate identification of business and technical risks. + measure: Threat modeling is performed by using reviewing user stories and producing + security driven data flow diagrams. + difficultyOfImplementation: + knowledge: 4 + time: 3 + resources: 2 + usefulness: 3 + level: 4 + dependsOn: + - 47419324-e263-415b-815d-e7161b6b905e # Conduction of simple threat modeling on technical level + - dd5ed7c1-bdbf-400f-b75f-6d3953a1a04e # Creation of threat modeling processes and standards + description: | + **Example High Maturity Scenario:** + + Based on a detailed threat model defined and updated through code, the team decides the following: + + * Local encrypted caches need to expire and auto-purged. + * Communication channels encrypted and authenticated. + * All secrets persisted in shared secrets store. + * Frontend designed with permissions model integration. + * Permissions matrix defined. + * Input is escaped output is encoded appropriately using well established libraries. + + Source: OWASP Project Integration Project implementation: - uuid: c0533602-11b7-4838-93cc-a40556398163 name: Whiteboard @@ -2251,60 +1701,22 @@ Culture and Organization: - owasp - defender url: https://owaspsamm.org/model/design/threat-assessment/stream-b/ - - uuid: 1c56dbea-e067-44e2-8d3b-0a1205a70617 + - uuid: e8332407-5149-459e-a2fe-c5c78c7ec55c + name: Threagile + tags: + - threat-modeling + url: https://github.com/Threagile/threagile + - uuid: 1c56dbea-e067-44e2-8d3b-0a1205a70617 name: Threat Matrix for Storage - url: https://www.microsoft.com/security/blog/2021/04/08/threat-matrix-for-storage/ + url: https://www.microsoft.com/en-US/security/blog/2021/04/08/threat-matrix-for-storage/ tags: - documentation - storage - cluster - kubernetes - description: | - # OWASP SAMM Description - Threat modeling is a structured activity for identifying, evaluating, and managing system threats, architectural design flaws, and recommended security mitigations. It is typically done as part of the design phase or as part of a security assessment. - - Threat modeling is a team exercise, including product owners, architects, security champions, and security testers. At this maturity level, expose teams and stakeholders to threat modeling to increase security awareness and to create a shared vision on the security of the system. - - At maturity level 1, you perform threat modeling ad-hoc for high-risk applications and use simple threat checklists, such as STRIDE. Avoid lengthy workshops and overly detailed lists of low-relevant threats. Perform threat modeling iteratively to align to more iterative development paradigms. If you add new functionality to an existing application, look only into the newly added functions instead of trying to cover the entire scope. A good starting point is the existing diagrams that you annotate during discussion workshops. Always make sure to persist the outcome of a threat modeling discussion for later use. - - Your most important tool to start threat modeling is a whiteboard, smartboard, or a piece of paper. Aim for security awareness, a simple process, and actionable outcomes that you agree upon with your team. Once requirements are gathered and analysis is performed, implementation specifics need to be defined. The outcome of this stage is usually a diagram outlining data flows and a general system architecture. This presents an opportunity for both threat modeling and attaching security considerations to every ticket and epic that is the outcome of this stage. - - Source: https://owaspsamm.org/model/design/threat-assessment/stream-b/ - # OWASP Project Integration Description - There is some great advice on threat modeling out there *e.g.* [this](https://arstechnica.com/information-technology/2017/07/how-i-learned-to-stop-worrying-mostly-and-love-my-threat-model/) article or [this](https://www.microsoft.com/en-us/securityengineering/sdl/threatmodeling) one. - - A bite sized primer by Adam Shostack himself can be found [here](https://adam.shostack.org/blog/2018/03/threat-modeling-panel-at-appsec-cali-2018/). - - OWASP includes a short [article](https://wiki.owasp.org/index.php/Category:Threat_Modeling) on Threat Modeling along with a relevant [Cheatsheet](https://cheatsheetseries.owasp.org/cheatsheets/Threat_Modeling_Cheat_Sheet.html). Moreover, if you're following OWASP SAMM, it has a short section on [Threat Assessment](https://owaspsamm.org/model/design/threat-assessment/). - - There's a few projects that can help with creating Threat Models at this stage, [PyTM](https://github.com/izar/pytm) is one, [ThreatSpec](https://github.com/threatspec/threatspec) is another. - - > Note: _A threat model can be as simple as a data flow diagram with attack vectors on every flow and asset and equivalent remediations. An example can be found below._ - - ![Threat Model](https://github.com/OWASP/www-project-integration-standards/raw/master/writeups/owasp_in_sdlc/images/threat_model.png "Threat Model") - - Last, if the organizations maps Features to Epics, the Security Knowledge Framework (SKF) can be used to facilitate this process by leveraging it's questionnaire function. - - ![SKF](https://github.com/OWASP/www-project-integration-standards/raw/master/writeups/owasp_in_sdlc/images/skf_qs.png "SKF") - - This practice has the side effect that it trains non-security specialists to think like attackers. - - The outcomes of this stage should help lay the foundation of secure design and considerations. - - **Example Low Maturity Scenario:** - - Following vague feature requirements the design includes caching data to a local unencrypted database with a hardcoded password. - - Remote data store access secrets are hardcoded in the configuration files. All communication between backend systems is plaintext. - - Frontend serves data over GraphQL as a thin layer between caching system and end user. - - GraphQL queries are dynamically translated to SQL, Elasticsearch and NoSQL queries. Access to data is protected with basic auth set to _1234:1234_ for development purposes. - - Source: OWASP Project Integration Project references: samm2: - - D-TA-2-B + - D-TA-B-2 iso27001-2017: - Not explicitly covered by ISO 27001 - May be part of risk assessment @@ -2315,6 +1727,8 @@ Culture and Organization: - May be part of risk assessment - 5.12 - 8.25 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Design/subsection/Conduction%20of%20advanced%20threat%20modeling isImplemented: false evidence: "" comments: "" @@ -2333,18 +1747,20 @@ Culture and Organization: usefulness: 4 level: 5 dependsOn: - - Creation of simple abuse stories + - bacf85b6-5bc0-405d-b5ba-a5d971467cc1 # Creation of simple abuse stories implementation: - uuid: bb5b8988-021b-452a-a914-bd36887b6860 - name: '[Don''t Forget EVIL U' + name: Don't Forget EVIL User stories tags: [] - url: https://www.owasp.org/index.php/Agile_Software_Development - description: '[Do not Forget EVIL User Stories](https://www.owasp.org/index.php/Agile_Software_Development:_Don%27t_Forget_EVIL_User_Stories) - and [Practical Security Stories and Security Tasks for Agile Development - Environments](http://safecode.org/publication/SAFECode_Agile_Dev_Security0712.pdf)' + url: https://medium.com/serious-scrum/evil-user-storys-story-telling-for-it-security-e4a9ec94193c + test-url-expects: + - 403 + description: Do not Forget _Evil_ User Stories and [Practical Security Stories + and Security Tasks for Agile Development Environments](https://safecode.org/publication/SAFECode_Agile_Dev_Security0712.pdf) references: samm2: - - D-TA-2-B + - D-TA-B-2 + - V-RT-B-2 iso27001-2017: - Not explicitly covered by ISO 27001 - May be part of project management @@ -2357,204 +1773,327 @@ Culture and Organization: - 5.8 - May be part of risk assessment - 5.9 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Design/subsection/Creation%20of%20advanced%20abuse%20stories isImplemented: false evidence: "" comments: "" tags: - none - Creation of simple abuse stories: - uuid: bacf85b6-5bc0-405d-b5ba-a5d971467cc1 - risk: User stories mostly don't consider security implications. Security flaws - are discovered too late in the development and deployment process. - measure: Abuse stories are created during the creation of user stories. + Education and Guidance: + Ad-Hoc Security trainings for software developers: + uuid: 12c90cc6-3d58-4d9b-82ff-d469d2a0c298 + description: | + Ad-hoc security training provides basic awareness of software security risks and best practices to developers and other personnel involved in software development. These trainings are delivered as needed, without a fixed schedule, to address immediate knowledge gaps or respond to emerging threats. + risk: | + Without any security training, personnel may lack awareness of common software vulnerabilities (such as SQL Injection and vulnerable dependencies), increasing the risk of introducing exploitable flaws into applications. + measure: | + Provide security awareness training for all personnel involved in software development on an ad-hoc basis, ensuring that relevant topics are covered when new risks or needs are identified. + assessment: | + - Conduct security training for developers and relevant personnel + - Training materials are available + - Attendance records are available + level: 1 difficultyOfImplementation: knowledge: 2 - time: 2 + time: 1 resources: 1 - usefulness: 4 - level: 3 + usefulness: 3 implementation: - - uuid: bb5b8988-021b-452a-a914-bd36887b6860 - name: '[Don''t Forget EVIL U' - tags: [] - url: https://www.owasp.org/index.php/Agile_Software_Development - description: '[Do not Forget EVIL User Stories](https://www.owasp.org/index.php/Agile_Software_Development:_Don%27t_Forget_EVIL_User_Stories) - and [Practical Security Stories and Security Tasks for Agile Development - Environments](http://safecode.org/publication/SAFECode_Agile_Dev_Security0712.pdf)' - dependsOn: - - Conduction of simple threat modeling on technical level - - Creation of threat modeling processes and standards + - uuid: 1fff917f-205e-4eab-ae0e-1fab8c04bf3a + name: OWASP Juice Shop + tags: + - training + url: https://github.com/juice-shop/juice-shop + description: In case you do not have the budget to hire an external security + expert, an option is to use the OWASP JuiceShop on a "hacking Friday" + - uuid: 1c3f2f7a-5031-4687-9d69-76c5178c74e1 + name: OWASP Cheatsheet Series + tags: + - training + - secure coding + url: https://cheatsheetseries.owasp.org/ references: samm2: - - D-TA-2-B + - G-EG-A-1 iso27001-2017: - - Not explicitly covered by ISO 27001 - - May be part of project management - - 6.1.5 - - May be part of risk assessment - - 8.1.2 + - 7.2.2 iso27001-2022: - - Not explicitly covered by ISO 27001 - - May be part of project management - - 5.8 - - May be part of risk assessment - - 5.9 - isImplemented: false - evidence: "" - comments: "" + - 6.3 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Education%20and%20Guidance/subsection/Ad-Hoc%20Security%20trainings%20for%20software%20developers tags: - none - Creation of threat modeling processes and standards: - uuid: dd5ed7c1-bdbf-400f-b75f-6d3953a1a04e - risk: Inadequate identification of business and technical risks. - measure: Creation of threat modeling processes and standards through the organization - helps to enhance the security culture and provide more structure to the threat - model exercises. + Security consulting on request: + uuid: 0b28367b-75a0-4bae-a926-3725c1bf9bb0 + level: 1 + description: | + Security consulting on request allows teams to seek expert advice on security-related questions or challenges as they arise. This support can be provided by internal or external security consultants and helps address specific concerns during software development. + risk: | + If teams do not consult security experts when questions arise, security flaws may be introduced or remain undetected, increasing the risk of vulnerabilities in the software. + measure: | + Make security consulting available to teams on request, ensuring that expert advice is accessible when needed to address security concerns during development. + assessment: | + - Show evidence that an it security expert is available for questions at least quarterly. + - Documentation of consultations and resulting actions is available for review. difficultyOfImplementation: - knowledge: 4 - time: 3 - resources: 2 + knowledge: 3 + time: 1 + resources: 1 usefulness: 3 - level: 3 - description: "" implementation: - - uuid: fd0f282b-a065-4464-beed-770c604a5f52 - name: Threat Modeling Playbook - tags: - - owasp - - defender - - threat-modeling - - whiteboard - url: https://github.com/Toreon/threat-model-playbook - - uuid: b5eaf710-e05f-49e5-a649-13afde9aeb52 - name: OWASP SAMM + - uuid: 1c3f2f7a-5031-4687-9d69-76c5178c74e1 + name: OWASP Cheatsheet Series tags: - - threat-modeling - - owasp - - defender - url: https://owaspsamm.org/model/design/threat-assessment/stream-b/ - dependsOn: - - Conduction of simple threat modeling on technical level + - training + - secure coding + url: https://cheatsheetseries.owasp.org/ references: samm2: - - D-TA-3-B + - G-EG-A-1 + - G-EG-B-1 iso27001-2017: - - Not explicitly covered by ISO 27001 - - May be part of risk assessment - - 8.2.1 - - 14.2.1 + - security consulting is missing in ISO 27001 may be + - 6.1.1 + - 6.1.4 + - 6.1.5 iso27001-2022: - - Not explicitly covered by ISO 27001 - - May be part of risk assessment - - 5.12 - - 8.25 + - Security consulting is missing in ISO 27001 may be + - 5.2 + - 5.6 + - 5.8 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Education%20and%20Guidance/subsection/Security%20consulting%20on%20request isImplemented: false evidence: "" comments: "" tags: - none - Information security targets are communicated: - uuid: 1b9281b9-48e2-4c01-9ac6-9db9931c4885 - risk: Employees don't known their organizations security targets. Therefore - security is not considered during development and administration as much as - it should be. - measure: Transparent and timely communication of the security targets by senior - management is essential to ensure teams' buy-in and support. + Each team has a security champion: + uuid: 6217fe11-5ed7-4cf4-9de4-555bcfa6fe87 + risk: No one feels directly responsible for security and the security champion + does not have enough time to allocate to each team. + measure: Each team defines an individual to be responsible for security. These + individuals are often referred to as 'security champions' difficultyOfImplementation: - knowledge: 1 - time: 1 + knowledge: 3 + time: 2 resources: 1 - usefulness: 3 + usefulness: 4 level: 2 - implementation: [] + description: | + Implement a program where each software development team has a member considered a "Security Champion" who is the liaison between Information Security and developers. Depending on the size and structure of the team the "Security Champion" may be a software developer, tester, or a product manager. The "Security Champion" has a set number of hours per week for Information Security related activities. They participate in periodic briefings to increase awareness and expertise in different security disciplines. "Security Champions" have additional training to help develop these roles as Software Security subject-matter experts. You may need to customize the way you create and support "Security Champions" for cultural reasons. + + The goals of the position are to increase effectiveness and efficiency of application security and compliance and to strengthen the relationship between various teams and Information Security. To achieve these objectives, "Security Champions" assist with researching, verifying, and prioritizing security and compliance related software defects. They are involved in all Risk Assessments, Threat Assessments, and Architectural Reviews to help identify opportunities to remediate security defects by making the architecture of the application more resilient and reducing the attack threat surface. + + [Source: OWASP SAMM](https://owaspsamm.org/model/governance/education-and-guidance/stream-b/) + implementation: + - uuid: c191a515-3c10-4903-a889-70c8021f2ea1 + name: OWASP Security Champions Playbook + tags: + - security champions + url: https://github.com/c0rdis/security-champions-playbook references: - samm2: [] + samm2: + - G-EG-B-1 + - G-EG-B-2 iso27001-2017: - - 5.1.1 + - Security champions are missing in ISO 27001 most likely - 7.2.1 + - 7.2.2 iso27001-2022: - - 5.1 + - Security champions are missing in ISO 27001 most likely - 5.4 + - 6.3 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Education%20and%20Guidance/subsection/Each%20team%20has%20a%20security%20champion isImplemented: false evidence: "" comments: "" tags: - none - Education and Guidance: - Ad-Hoc Security trainings for software developers: - uuid: 12c90cc6-3d58-4d9b-82ff-d469d2a0c298 - risk: Understanding security is hard and personnel needs to be trained on it. - Otherwise, flaws like an SQL Injection might be introduced into the software - which might get exploited. - measure: Provide security awareness training for all personnel involved in software - development Ad-Hoc. + Regular security training for all: + uuid: 9768f154-357a-4c06-af6f-d66570677c9b + risk: Understanding security is hard. + measure: Provide security awareness training for all internal personnel involved + in software development on a regular basis like twice in a year for 1-3 days. difficultyOfImplementation: - knowledge: 2 - time: 1 - resources: 1 - usefulness: 3 - level: 1 + knowledge: 3 + time: 4 + resources: 2 + usefulness: 4 + level: 2 + description: | + Conduct security awareness training for all roles currently involved in the management, development, testing, or auditing of the software. The goal is to increase the awareness of application security threats and risks, security best practices, and secure software design principles. Develop training internally or procure it externally. Ideally, deliver training in person so participants can have discussions as a team, but Computer-Based Training (CBT) is also an option. + + Course content should include a range of topics relevant to application security and privacy, while remaining accessible to a non-technical audience. Suitable concepts are secure design principles including Least Privilege, Defense-in-Depth, Fail Secure (Safe), Complete Mediation, Session Management, Open Design, and Psychological Acceptability. Additionally, the training should include references to any organization-wide standards, policies, and procedures defined to improve application security. The OWASP Top 10 vulnerabilities should be covered at a high level. + + Training is mandatory for all employees and contractors involved with software development and includes an auditable sign-off to demonstrate compliance. Consider incorporating innovative ways of delivery (such as gamification) to maximize its effectiveness and combat desensitization. + + [Source: OWASP SAMM 2](https://owaspsamm.org/model/governance/education-and-guidance/stream-a/) implementation: - uuid: 1fff917f-205e-4eab-ae0e-1fab8c04bf3a name: OWASP Juice Shop tags: - training - url: https://github.com/bkimminich/juice-shop + url: https://github.com/juice-shop/juice-shop description: In case you do not have the budget to hire an external security expert, an option is to use the OWASP JuiceShop on a "hacking Friday" - uuid: 1c3f2f7a-5031-4687-9d69-76c5178c74e1 name: OWASP Cheatsheet Series tags: + - training - secure coding url: https://cheatsheetseries.owasp.org/ references: samm2: - - G-EG-1-A + - G-EG-A-1 iso27001-2017: - 7.2.2 iso27001-2022: - 6.3 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Education%20and%20Guidance/subsection/Regular%20security%20training%20for%20all isImplemented: false evidence: "" comments: "" tags: - none - Aligning security in teams: - uuid: f994a55d-71bb-45a4-a887-0a213d72c504 - risk: The concept of Security Champions might suggest that only he/she is responsible - for security. However, everyone in the project team should be responsible - for security. - measure: By aligning security Subject Matter Experts with project teams, a higher - security standard can be achieved. + Regular security training of security champions: + uuid: f88d1b17-3d7d-4c3d-8139-ad44fc4942d4 + risk: Understanding security is hard, even for security champions. + measure: Regular security training of security champions. + assessment: | + - Process Documentation: TODO + - Training Content: TOODO difficultyOfImplementation: knowledge: 4 - time: 4 - resources: 1 + time: 2 + resources: 2 usefulness: 5 + level: 2 implementation: - - uuid: 8a044b74-17f2-4ffa-9dee-6b3bb6e4baf3 - name: Involve Security SME - tags: [] - description: Security SME are involved in discussion for requirements analysis, - software design and sprint planning to provide guidance and suggestions. - level: 4 + - uuid: 1c3f2f7a-5031-4687-9d69-76c5178c74e1 + name: OWASP Cheatsheet Series + tags: + - training + - secure coding + url: https://cheatsheetseries.owasp.org/ + dependsOn: + - 6217fe11-5ed7-4cf4-9de4-555bcfa6fe87 # Each team has a security champion references: samm2: - - G-EG-3-B + - D-TA-B-2 + - G-EG-A-1 iso27001-2017: - - 7.1.1 + - Security champions are missing in ISO 27001 + - 7.2.2 iso27001-2022: - - 6.1 + - Security champions are missing in ISO 27001 + - 6.3 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Education%20and%20Guidance/subsection/Regular%20security%20training%20of%20security%20champions isImplemented: false evidence: "" comments: "" tags: - none - Conduction of build-it, break-it, fix-it contests: - uuid: bfdb576e-a416-4ec6-96fe-a078d58b2ff8 - risk: Understanding security is hard, even for security champions and the conduction - of security training often focuses on breaking a component instead of building - a component secure. + Reward of good communication: + uuid: 91b6f75b-9f4a-4d77-95a2-af7ad3222c7c + risk: Employees are not getting excited about security. + measure: Good communication and transparency encourages cross-organizational + support. Gamification of security is also known to help, examples include + T-Shirts, mugs, cups, gift cards and 'High-Fives'. + difficultyOfImplementation: + knowledge: 3 + time: 2 + resources: 1 + usefulness: 3 + level: 2 + implementation: + - uuid: 8e1b4a8a-c53b-4b1e-90f6-c60b7e225098 + name: Motivate people + tags: + - security champions + - gamification + - nudging + url: https://github.com/wurstbrot/security-pins + description: |- + Enhance motivation can be performed with the distribution of pins + as a reward, see [OWASP Security Pins Project](https://github.com/wurstbrot/security-pins) + - uuid: 22b63bdb-2003-4ac0-969d-b1e5268c2510 + name: OWASP Top 10 Maturity Categories for Security Champions + tags: + - security champions + url: https://owaspsamm.org/presentations/OWASP_Top_10_Maturity_Categories_for_Security_Champions.pptx + references: + samm2: + - G-EG-B-1 + iso27001-2017: + - not required by ISO 27001 + - interestingly enough A7.2.3 is requiring a process to handle misconduct + but nothing to promote good behavior. + iso27001-2022: + - ISO 27001:2022 mapping is missing + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Education%20and%20Guidance/subsection/Reward%20of%20good%20communication + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Security code review: + uuid: 7121b0c7-6ace-4d6b-95d0-94535dbccb57 + risk: Understanding security is hard. + measure: | + The following areas of code tend to have a high-risk of containing security vulnerabilities: + - Crypto implementations / usage + - Parser, unparser + - System configuration + - Authentication, authorization + - Session management + - Request throttling + - :unicorn: (self-developed code, only used in that one software) + description: | + ### Benefits + - New vulnerabilities may be found before reaching production. + - Old vulnerabilities are found and fixed. + assessment: | + - Present the performed reviews (including participants, findings, consequences) and assess whether it is reasonable. + difficultyOfImplementation: + knowledge: 3 + time: 2 + resources: 1 + usefulness: 3 + level: 2 + implementation: + - uuid: c77f7ecd-76de-4611-bd6d-5b249f910c39 + name: CWE Top 25 Most Dangerous Software Weaknesses + tags: + - documentation + - threat + url: https://cwe.mitre.org/top25/archive/2020/2020_cwe_top25.html + credits: | + AppSecure-nrw [Security Belts](https://github.com/AppSecure-nrw/security-belts/) + references: + samm2: + - V-ST-B-1 + iso27001-2017: + - ISO 27001:2017 mapping is missing + iso27001-2022: + - ISO 27001:2022 mapping is missing + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Education%20and%20Guidance/subsection/Security%20code%20review + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Conduction of build-it, break-it, fix-it contests: + uuid: bfdb576e-a416-4ec6-96fe-a078d58b2ff8 + risk: Understanding security is hard, even for security champions and the conduction + of security training often focuses on breaking a component instead of building + a component secure. measure: The build-it, break-it, fix-it contest allows to train people with security related roles like security champions the build, break and fix part of a secure application. This increases the learning of building secure components. @@ -2571,45 +2110,189 @@ Culture and Organization: url: https://builditbreakit.org/ references: samm2: - - G-EG-2-A + - G-EG-A-2 iso27001-2017: - 7.2.2 iso27001-2022: - 6.3 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Education%20and%20Guidance/subsection/Conduction%20of%20build-it%2C%20break-it%2C%20fix-it%20contests isImplemented: false evidence: "" comments: "" tags: - none - Conduction of collaborative security checks with developers and system administrators: - uuid: 95caef96-36ed-458c-a087-5c35d4f9dec2 - risk: Security checks by external companies do not increase the understanding - of an application/system for internal employees. - measure: Periodically security reviews of source code (SCA), in which security - SME, developers and operations are involved, are effective at increasing the - robustness of software and the security knowledge of the teams involved. + Office Hours: + uuid: 185d5a74-19dc-4422-be07-44ea35226783 + risk: Developers and Operations are not in contact with the security team and + therefore do not ask prior implementation of (known or unknown) threats- + measure: As a security team, be open for questions and hints during defined + office hours. x x d + difficultyOfImplementation: + knowledge: 1 + time: 1 + resources: 1 + usefulness: 3 + level: 3 + implementation: ~ + references: + samm2: + - G-EG-A-1 + iso27001-2017: + - 7.2.2 + iso27001-2022: + - 6.3 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Education%20and%20Guidance/subsection/Office%20Hours + tags: + - none + Security Coaching: + uuid: f7b215dc-73a4-4c61-9e49-b3a3af1c9ac3 + risk: Training does not change behaviour. Therefore, even if security practices + are understood, it's likely that they are not performed. + measure: By coaching teams on security topics using for example the samman coaching + method, teams internalize security practices as new habits in their development + process. + difficultyOfImplementation: + knowledge: 4 + time: 3 + resources: 1 + usefulness: 3 + implementation: + - uuid: 9223be73-00da-400e-a910-3871734cff2f + name: sammancoaching + tags: + - documentation + - coaching + - education + url: https://sammancoaching.org/ + description: | + Security coaches work with software development teams to help them adopt better security practices. + level: 3 + references: + samm2: + - G-EG-B-3 + iso27001-2017: + - 7.1.1 + iso27001-2022: + - 6.1 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Education%20and%20Guidance/subsection/Security%20Coaching + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Security-Lessoned-Learned: + uuid: 58c46807-fee9-448b-b6dd-8050c464ab52 + risk: After an incident, a similar incident might reoccur. + measure: Running a 'lessons learned' session after an incident helps drive continuous + improvement. Regular meetings with security champions are a good place to + share and discuss lessons learned. difficultyOfImplementation: knowledge: 3 - time: 2 + time: 3 resources: 1 usefulness: 3 - level: 5 + level: 3 implementation: [] references: samm2: - - G-EG-2-A + - G-EG-B-3 + - O-IM-B-3 + iso27001-2017: + - 16.1.6 + iso27001-2022: + - 5.27 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Education%20and%20Guidance/subsection/Security-Lessoned-Learned + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Simple mob hacking: + uuid: 535f301a-e8e8-4eda-ad77-a08b035c92de + risk: Understanding security is hard. + measure: | + Participate with your whole team in a simple mob hacking session organized by the Security Champion Guild. + In the session the guild presents a vulnerable application and together you look at possible exploits. + Just like in mob programming there is one driver and several navigators. + description: | + ### Guidelines for your simple mob hacking session + - All exploits happen via the user interface. + - No need for security/hacking tools. + - No need for deep technical or security knowledge. + - Use an insecure training app, e.g., [DVWA](https://dvwa.co.uk/) or [OWASP Juice Shop](https://owasp.org/www-project-juice-shop/). + - Encourage active participation, e.g., use small groups. + - Allow enough time for everyone to run at least one exploit. + + ### Benefits + - The team gets an idea of how exploits can look like and how easy applications can be attacked. + - The team understands functional correct working software can be highly insecure and easy to exploit. + difficultyOfImplementation: + knowledge: 5 + time: 3 + resources: 1 + usefulness: 3 + level: 3 + credits: | + AppSecure-nrw [Security Belts](https://github.com/AppSecure-nrw/security-belts/) + implementation: + - uuid: 1fff917f-205e-4eab-ae0e-1fab8c04bf3a + name: OWASP Juice Shop + tags: + - training + url: https://github.com/juice-shop/juice-shop + description: In case you do not have the budget to hire an external security + expert, an option is to use the OWASP JuiceShop on a "hacking Friday" + - uuid: a8cd9acb-ad22-44d6-b177-1154c65a8529 + name: Damn Vulnerable Web Application + tags: + - training + description: Simple Application with intended vulnerabilities. HTML based. + references: + samm2: + - G-EG-A-2 iso27001-2017: - - Mutual review of source code is not explicitly required in ISO 27001 may - be - 7.2.2 - - 12.6.1 - - 12.7.1 iso27001-2022: - - Mutual review of source code is not explicitly required in ISO 27001 may - be - 6.3 - - 8.8 - - 8.34 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Education%20and%20Guidance/subsection/Simple%20mob%20hacking + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Aligning security in teams: + uuid: f994a55d-71bb-45a4-a887-0a213d72c504 + risk: The concept of Security Champions might suggest that only he/she is responsible + for security. However, everyone in the project team should be responsible + for security. + measure: By aligning security Subject Matter Experts with project teams, a higher + security standard can be achieved. + difficultyOfImplementation: + knowledge: 4 + time: 4 + resources: 1 + usefulness: 5 + implementation: + - uuid: 8a044b74-17f2-4ffa-9dee-6b3bb6e4baf3 + name: Involve Security SME + tags: [] + description: Security SME are involved in discussion for requirements analysis, + software design and sprint planning to provide guidance and suggestions. + level: 4 + references: + samm2: + - G-EG-B-3 + iso27001-2017: + - 7.1.1 + iso27001-2022: + - 6.1 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Education%20and%20Guidance/subsection/Aligning%20security%20in%20teams isImplemented: false evidence: "" comments: "" @@ -2629,14 +2312,16 @@ Culture and Organization: implementation: [] references: samm2: - - G-EG-1-A - - G-EG-2-A + - G-EG-A-1 + - G-EG-A-2 iso27001-2017: - Mutual security testing is not explicitly required in ISO 27001 may be - 7.2.2 iso27001-2022: - Mutual security testing is not explicitly required in ISO 27001 may be - 6.3 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Education%20and%20Guidance/subsection/Conduction%20of%20collaborative%20team%20security%20checks isImplemented: false evidence: "" comments: "" @@ -2657,7 +2342,8 @@ Culture and Organization: implementation: [] references: samm2: - - G-EG-2-A + - G-EG-A-2 + - O-IM-B-2 iso27001-2017: - War games are not explicitly required in ISO 27001 may be - 7.2.2 @@ -2668,502 +2354,410 @@ Culture and Organization: - 6.3 - 5.24 - 5.26 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Education%20and%20Guidance/subsection/Conduction%20of%20war%20games isImplemented: false evidence: "" comments: "" tags: - none - Each team has a security champion: - uuid: 6217fe11-5ed7-4cf4-9de4-555bcfa6fe87 - risk: No one feels directly responsible for security and the security champion - does not have enough time to allocate to each team. - measure: Each team defines an individual to be responsible for security. These - individuals are often referred to as 'security champions' + Regular security training for externals: + uuid: 31833d56-35af-4ef3-9300-f23d27646ce7 + risk: Understanding security is hard. + measure: Provide security awareness training for all personnel including externals + involved in software development on a regular basis. difficultyOfImplementation: knowledge: 3 time: 2 - resources: 1 + resources: 3 usefulness: 4 - level: 2 - description: "Implement a program where each software development team has a - member considered a \u201CSecurity Champion\u201D who is the liaison between - Information Security and developers. Depending on the size and structure of - the team the \u201CSecurity Champion\u201D may be a software developer, tester, - or a product manager. The \u201CSecurity Champion\u201D has a set number of - hours per week for Information Security related activities. They participate - in periodic briefings to increase awareness and expertise in different security - disciplines. \u201CSecurity Champions\u201D have additional training to help - develop these roles as Software Security subject-matter experts. You may need - to customize the way you create and support \u201CSecurity Champions\u201D - for cultural reasons.\n\nThe goals of the position are to increase effectiveness - and efficiency of application security and compliance and to strengthen the - relationship between various teams and Information Security. To achieve these - objectives, \u201CSecurity Champions\u201D assist with researching, verifying, - and prioritizing security and compliance related software defects. They are - involved in all Risk Assessments, Threat Assessments, and Architectural Reviews - to help identify opportunities to remediate security defects by making the - architecture of the application more resilient and reducing the attack threat - surface.\nSource: [OWASP SAMM](https://owaspsamm.org/model/governance/education-and-guidance/stream-b/)\n" + level: 4 implementation: - - uuid: c191a515-3c10-4903-a889-70c8021f2ea1 - name: OWASP Security Champions Playbook + - uuid: 1fff917f-205e-4eab-ae0e-1fab8c04bf3a + name: OWASP Juice Shop tags: - - security champions - url: https://github.com/c0rdis/security-champions-playbook - references: - samm2: - - G-EG-1-B - - G-EG-2-B - iso27001-2017: - - Security champions are missing in ISO 27001 most likely - - 7.2.1 - - 7.2.2 - iso27001-2022: - - Security champions are missing in ISO 27001 most likely - - 5.4 - - 6.3 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Regular security training for all: - uuid: 9768f154-357a-4c06-af6f-d66570677c9b - risk: Understanding security is hard. - measure: Provide security awareness training for all internal personnel involved - in software development on a regular basis like twice in a year for 1-3 days. - difficultyOfImplementation: - knowledge: 3 - time: 4 - resources: 2 - usefulness: 4 - level: 2 - description: | - Conduct security awareness training for all roles currently involved in the management, development, testing, or auditing of the software. The goal is to increase the awareness of application security threats and risks, security best practices, and secure software design principles. Develop training internally or procure it externally. Ideally, deliver training in person so participants can have discussions as a team, but Computer-Based Training (CBT) is also an option. - - Course content should include a range of topics relevant to application security and privacy, while remaining accessible to a non-technical audience. Suitable concepts are secure design principles including Least Privilege, Defense-in-Depth, Fail Secure (Safe), Complete Mediation, Session Management, Open Design, and Psychological Acceptability. Additionally, the training should include references to any organization-wide standards, policies, and procedures defined to improve application security. The OWASP Top 10 vulnerabilities should be covered at a high level. - - Training is mandatory for all employees and contractors involved with software development and includes an auditable sign-off to demonstrate compliance. Consider incorporating innovative ways of delivery (such as gamification) to maximize its effectiveness and combat desensitization. - - [Source: OWASP SAMM 2](https://owaspsamm.org/model/governance/education-and-guidance/stream-a/) - implementation: - - uuid: 81476121-67dd-4ba9-a67b-e78a23050c28 - name: OWASP JuiceShop - tags: [] - url: https://github.com/bkimminich/juice-shop - description: |- - In case you do not have the budget to hire an external security expert, an option - is to use the [OWASP JuiceShop](https://github.com/bkimminich/juice-shop) on a "hacking Friday" + - training + url: https://github.com/juice-shop/juice-shop + description: In case you do not have the budget to hire an external security + expert, an option is to use the OWASP JuiceShop on a "hacking Friday" - uuid: 1c3f2f7a-5031-4687-9d69-76c5178c74e1 name: OWASP Cheatsheet Series tags: + - training - secure coding url: https://cheatsheetseries.owasp.org/ references: samm2: - - G-EG-1-A + - G-EG-A-2 iso27001-2017: - 7.2.2 iso27001-2022: - 6.3 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Education%20and%20Guidance/subsection/Regular%20security%20training%20for%20externals isImplemented: false evidence: "" comments: "" tags: - none - Regular security training for externals: - uuid: 31833d56-35af-4ef3-9300-f23d27646ce7 - risk: Understanding security is hard. - measure: Provide security awareness training for all personnel including externals - involved in software development on a regular basis. + Conduction of collaborative security checks with developers and system administrators: + uuid: 95caef96-36ed-458c-a087-5c35d4f9dec2 + risk: Security checks by external companies do not increase the understanding + of an application/system for internal employees. + measure: Periodically security reviews of source code (SCA), in which security + SME, developers and operations are involved, are effective at increasing the + robustness of software and the security knowledge of the teams involved. difficultyOfImplementation: knowledge: 3 time: 2 - resources: 3 - usefulness: 4 - level: 4 - implementation: - - uuid: 81476121-67dd-4ba9-a67b-e78a23050c28 - name: OWASP JuiceShop - tags: [] - url: https://github.com/bkimminich/juice-shop - description: |- - In case you do not have the budget to hire an external security expert, an option - is to use the [OWASP JuiceShop](https://github.com/bkimminich/juice-shop) on a "hacking Friday" - - uuid: 99080ac7-60cd-46af-93a1-a53a33597cba - name: https://cheatsheetseries.owasp.org/ - tags: - - training - - secure coding - url: https://cheatsheetseries.owasp.org/ + resources: 1 + usefulness: 3 + level: 5 + implementation: [] references: samm2: - - G-EG-3-A + - G-EG-A-2 + - G-EG-B-2 iso27001-2017: + - Mutual review of source code is not explicitly required in ISO 27001 may + be - 7.2.2 + - 12.6.1 + - 12.7.1 iso27001-2022: + - Mutual review of source code is not explicitly required in ISO 27001 may + be - 6.3 + - 8.8 + - 8.34 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Education%20and%20Guidance/subsection/Conduction%20of%20collaborative%20security%20checks%20with%20developers%20and%20system%20administrators isImplemented: false evidence: "" comments: "" tags: - none - Regular security training of security champions: - uuid: f88d1b17-3d7d-4c3d-8139-ad44fc4942d4 - risk: Understanding security is hard, even for security champions. - measure: Regular security training of security champions. - assessment: | - - Process Documentation: TODO - - Training Content: TOODO + Process: + Definition of simple BCDR practices for critical components: + uuid: c72da779-86cc-45b1-a339-190ce5093171 + description: | + Business Continuity and Disaster Recovery (BCDR) is a plan and a process that enable an organization to quickly restore normal operations after a disruptive event, such as a cyberattack or natural disaster. + risk: | + If the disaster recovery actions are not clear, you risk slow reaction and remediation delays. + This applies to cyber attacks as well as natural emergencies, such as a power outage. + measure: | + Develop, document, and communicate a BCDR plan for all critical components. The plan must define roles and responsibilities, Service Level Agreements (SLAs), Recovery Point Objectives (RPOs), Recovery Time Objectives (RTOs), and failover procedures. Ensure all relevant personnel are trained and the plan is reviewed and updated regularly. + assessment: "- There is a documented BCDR plan covering all critical components + of the application(s).\n- The plan clearly defines responsibilities, SLAs, + RPOs, RTOs, and failover steps. \n- Relevant staff are aware of the plan, + and evidence of regular review and testing is available.\n" + level: 1 difficultyOfImplementation: knowledge: 4 - time: 2 + time: 3 resources: 2 - usefulness: 5 - level: 2 - implementation: - - uuid: 1c3f2f7a-5031-4687-9d69-76c5178c74e1 - name: OWASP Cheatsheet Series - tags: - - secure coding - url: https://cheatsheetseries.owasp.org/ - dependsOn: - - Each team has a security champion + usefulness: 4 + implementation: [] references: samm2: - - D-TA-2-B - - G-EG-1-A + - O-IM-B-2 iso27001-2017: - - Security champions are missing in ISO 27001 - - 7.2.2 + - 17.1.1 iso27001-2022: - - Security champions are missing in ISO 27001 - - 6.3 - isImplemented: false - evidence: "" - comments: "" + - 5.29 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Process/subsection/Definition%20of%20simple%20BCDR%20practices%20for%20critical%20components tags: - none - Reward of good communication: - uuid: 91b6f75b-9f4a-4d77-95a2-af7ad3222c7c - risk: Employees are not getting excited about security. - measure: Good communication and transparency encourages cross-organizational - support. Gamification of security is also known to help, examples include - T-Shirts, mugs, cups, gift cards and 'High-Fives'. + Determining the protection requirement: + uuid: 72737130-472c-4984-80f8-9ab2f1c2ed5d + risk: "Not defining the protection requirement of applications can lead to wrong + prioritization, delayed remediation of \ncritical security issues, increasing + the risk of exploitation and potential damage to the organization." + measure: "Defining the protection requirement. \nThe protection requirements + for an application should consider:\n- Processed data criticality\n- Application + accessibility (internal vs. external)\n- Regulatory compliance\n- Other relevant + factors" difficultyOfImplementation: - knowledge: 3 + knowledge: 2 time: 2 resources: 1 usefulness: 3 level: 2 + dependsOn: + - 2a44b708-734f-4463-b0cb-86dc46344b2f # Inventory of production components implementation: - - uuid: 8e1b4a8a-c53b-4b1e-90f6-c60b7e225098 - name: Motivate people + - uuid: 227d786c-dd76-4b81-b0b2-62389ab8f0fb + name: OWASP DefectDojo tags: - - security champions - - gamification - - nudging - url: https://github.com/wurstbrot/security-pins - description: |- - Enhance motivation can be performed with the distribution of pins - as a reward, see [OWASP Security Pins Project](https://github.com/wurstbrot/security-pins) - - uuid: 22b63bdb-2003-4ac0-969d-b1e5268c2510 - name: OWASP Top 10 Maturity Categories for Security Champions + - vulnerability management system + - owasp + url: https://github.com/DefectDojo/django-DefectDojo + description: | + DefectDojo is a security program and vulnerability management tool. DefectDojo allows you to manage your application security program, maintain product and application information, triage vulnerabilities and push findings into defect trackers. Consolidate your findings into one source of truth with DefectDojo. + - uuid: d2eb592d-c9b5-4c39-bff7-bb313a58e3a9 + name: Purify tags: - - security champions - url: https://owaspsamm.org/presentations/OWASP_Top_10_Maturity_Categories_for_Security_Champions.pptx + - vulnerability management system + url: https://github.com/faloker/purify/ + description: | + The goal of Purify to be an easy-in-use and efficient tool to simplify a workflow of managing vulnerabilities delivered from various (even custom) tools. + - uuid: 3b99799c-e875-4cc2-aad7-5ce4564a1cde + name: Business friendly vulnerability management metrics + url: https://medium.com/uber-security-privacy/business-friendly-vulnerability-management-metrics-cfd702fd7705 + test-url-expects: + - 403 + tags: + - documentation + - vulnerability + - vulnerability management system + - uuid: 7ec30b0e-9681-427a-80ee-ab811d9e476f + name: DefectDojo Client + tags: + - Defectdojo + - statistics + url: https://github.com/SDA-SE/defectdojo-client + description: | + This projects contains the DefectDojo upload client and statistics client. It is for example used within the ClusterImageScanner. references: samm2: - - G-EG-1-B + - O-OM-A-2 + - G-PC-B-2 + iso27001-2022: + - 5.25 + - 5.12 + - 5.13 + - 5.1 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Process/subsection/Determining%20the%20protection%20requirement + tags: + - vulnerability-mgmt + - metrics + - vmm-measurements + Approval by reviewing any new version: + uuid: 3f63bdbc-c75f-4780-a941-e6ad42e894e1 + risk: An individual might forget to implement security measures to protect source + code or infrastructure components. + measure: On each new version (e.g. Pull Request) of source code or infrastructure + components a security peer review of the changes is performed (two eyes principle) + and approval given by the reviewer. + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 1 + usefulness: 3 + level: 3 + implementation: [] + references: + samm2: [] iso27001-2017: - - not required by ISO 27001 - - interestingly enough A7.2.3 is requiring a process to handle misconduct - but nothing to promote good behavior. + - Peer review - four eyes principle is not explicitly required by ISO 27001 + - 6.1.2 + - 14.2.1 iso27001-2022: - - ISO 27001:2022 mapping is missing + - Peer review - four eyes principle is not explicitly required by ISO 27001 + - 5.3 + - 8.25 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Process/subsection/Approval%20by%20reviewing%20any%20new%20version isImplemented: false evidence: "" comments: "" tags: - none - Security Coaching: - uuid: f7b215dc-73a4-4c61-9e49-b3a3af1c9ac3 - risk: Training does not change behaviour. Therefore, even if security practices - are understood, it's likely that they are not performed. - measure: By coaching teams on security topics using for example the samman coaching - method, teams internalize security practices as new habits in their development - process. + Definition of a change management process: + uuid: b4193d32-3948-47e2-a326-3748c48019a1 + risk: The impact of a change is not controlled because these are not recorded + or documented. + measure: Each change of a system is automatically recorded and adequately logged. difficultyOfImplementation: knowledge: 4 time: 3 resources: 1 usefulness: 3 - implementation: - - uuid: 9223be73-00da-400e-a910-3871734cff2f - name: sammancoaching - tags: - - documentation - - coaching - - education - url: https://sammancoaching.org/ - description: | - Security coaches work with software development teams to help them adopt better security practices. level: 3 + implementation: [] references: - samm2: - - G-EG-3-B + samm2: [] iso27001-2017: - - 7.1.1 + - 14.2.2 + - 12.1.2 + - 12.4.1 iso27001-2022: - - 6.1 + - 8.32 + - 8.15 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Process/subsection/Definition%20of%20a%20change%20management%20process isImplemented: false evidence: "" comments: "" tags: - none - Security code review: - uuid: 7121b0c7-6ace-4d6b-95d0-94535dbccb57 - risk: Understanding security is hard. +Implementation: + Application Hardening: + App. Hardening Level 1 (50%): + uuid: b597928e-54d6-48a5-a806-8003dcd56aab + risk: Using an insecure application might lead to a compromised application. + This might lead to total data theft or data modification. measure: | - The following areas of code tend to have a high-risk of containing security vulnerabilities: - - Crypto implementations / usage - - Parser, unparser - - System configuration - - Authentication, authorization - - Session management - - Request throttling - - :unicorn: (self-developed code, only used in that one software) - description: | - ### Benefits - - New vulnerabilities may be found before reaching production. - - Old vulnerabilities are found and fixed. - assessment: | - - Present the performed reviews (including participants, findings, consequences) and assess whether it is reasonable. - difficultyOfImplementation: - knowledge: 3 + Following frameworks like the + * OWASP Application Security Verification Standard Level 1 + * OWASP Mobile Application Security Verification Standard + + in all applications provides a good baseline. Implement 50% of the recommendations. + difficultyOfImplementation: + knowledge: 2 time: 2 resources: 1 usefulness: 3 - level: 2 + level: 1 + description: | + To tackle the security of code developed in-house, OWASP offers an extensive collection of [Cheatsheets](https://cheatsheetseries.owasp.org/) demonstrating how to implement features securely. Moreover, the Security Knowledge Framework[1] offers an extensive library of code patterns spanning several programming languages. These patterns can be used to not only jumpstart the development process, but also do so securely. + + [...] + + ### Planning aka Requirements Gathering & Analysis + The Requirements gathering process tries to answer the question: _"What is the system going to do?"_ At this stage, the [SAMM project](https://owaspsamm.org/model/) offers 3 distinct maturity levels covering both [in-house](https://owaspsamm.org/model/design/security-requirements/stream-a/) software development and [third party](https://owaspsamm.org/model/design/security-requirements/stream-b/) supplier security. + + ![SAMM Requirements](https://github.com/OWASP/www-project-integration-standards/raw/master/writeups/owasp_in_sdlc/images/OWASP-in0.png) + + Organizations can use these to add solid security considerations at the start of the Software Development or Procurement process. + + These general security considerations can be audited by using a subsection of the ASVS controls in section V1 as a questionnaire. This process attempts to ensure that every feature has concrete security considerations. + + In case of internal development and if the organization maps Features to Epics, the [Security Knowledge Framework](https://securityknowledgeframework.org/) can be used to facilitate this process by leveraging its questionnaire function, shown below. + + Source: [OWASP Project Integration](https://raw.githubusercontent.com/OWASP/www-project-integration-standards/master/writeups/owasp_in_sdlc/index.md) implementation: - - uuid: c77f7ecd-76de-4611-bd6d-5b249f910c39 - name: CWE Top 25 Most Dangerous Software Weaknesses + - uuid: 88767cde-1610-402e-98ec-bc3575377183 + name: OWASP ASVS + tags: [] + url: https://owasp.org/www-project-application-security-verification-standard/ + - uuid: 7bf90650-a53a-4581-a214-1afd5de3a059 + name: OWASP MASVS + tags: [] + url: https://github.com/OWASP/masvs + - uuid: 596cb528-8981-4723-bcc3-22c261f26114 + name: API Security Maturity Model for Authorization + tags: + - api + url: https://curity.io/resources/learn/the-api-security-maturity-model/ + - uuid: 6150533e-58ca-4b52-a9b2-6226545d9ea0 + name: Top 5 API Security Myths That Are Crushing Your Business tags: - documentation - - threat - url: https://cwe.mitre.org/top25/archive/2020/2020_cwe_top25.html - credits: | - AppSecure-nrw [Security Belts](https://github.com/AppSecure-nrw/security-belts/) + - waf + url: https://thehackernews.com/2022/11/top-5-api-security-myths-that-are.html + description: | + There are several myths and misconceptions about API security. These myths about securing APIs are crushing your business references: samm2: - - V-ST-1-B + - D-SR-A-2 iso27001-2017: - - ISO 27001:2017 mapping is missing + - Hardening is not explicitly covered by ISO 27001 - too specific + - 13.1.3 iso27001-2022: - - ISO 27001:2022 mapping is missing - isImplemented: false - evidence: "" + - Hardening is not explicitly covered by ISO 27001 - too specific + - 8.22 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Application%20Hardening/subsection/App.%20Hardening%20Level%201%20%2850%25%29 comments: "" tags: - none - Security consulting on request: - uuid: 0b28367b-75a0-4bae-a926-3725c1bf9bb0 - risk: Not asking a security expert when questions regarding security appear - might lead to flaws. - measure: Security consulting to teams is given on request. The security consultants - can be internal or external. + Context-aware output encoding: + uuid: e1f37abb-d848-4a3a-b3df-65e91a89dcb7 + description: "**Input validation** stops malicious data from entering your system. + \\\n**Output encoding** neutralizes malicious data before rendering to user, + or the next system.\n\nInput validation and output encoding work together. + Apply both. \n\n**Context-aware output encoding** encodes data differently, + depending on its context. In the sample below the `{{bad_data}}` must be encoded + differently, depending on its context, to render safe HTML.\n\n```html\n
{{bad_data}}
\nClick me\n\n\n```\n" + risk: If an attacker manages to slip though your input validation, the attacker + may gain control over the user session or execute arbitrary actions. + measure: "* Use modern secure frameworks such as React/Angular/Vue/Svelte. The + default method here renders data in a safe way.\n* Use established and well-maintained + encoding libraries such as OWASP\u2019s Java Encoder and Microsoft\u2019s + AntiXSS.\n* Implement content security policies (CSP) to restrict the types + of content that can be loaded and executed.\n" difficultyOfImplementation: - knowledge: 3 - time: 1 + knowledge: 1 + time: 2 resources: 1 usefulness: 3 level: 1 implementation: - - uuid: 1c3f2f7a-5031-4687-9d69-76c5178c74e1 - name: OWASP Cheatsheet Series + - uuid: 2d61e48f-bade-4332-a383-adc50c29673a + name: OWASP DOM based XSS Prevention CheatSheet + url: https://cheatsheetseries.owasp.org/cheatsheets/DOM_based_XSS_Prevention_Cheat_Sheet.html + tags: [] + - uuid: ae97c9b0-308c-4dab-bff9-bf3330a897dc + name: CWE-838 Inappropriate Encoding for Output Context tags: - - secure coding - url: https://cheatsheetseries.owasp.org/ - references: - samm2: - - G-EG-1-A - iso27001-2017: - - security consulting is missing in ISO 27001 may be - - 6.1.1 - - 6.1.4 - - 6.1.5 - iso27001-2022: - - Security consulting is missing in ISO 27001 may be - - 5.2 - - 5.6 - - 5.8 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Security-Lessoned-Learned: - uuid: 58c46807-fee9-448b-b6dd-8050c464ab52 - risk: After an incident, a similar incident might reoccur. - measure: Running a 'lessons learned' session after an incident helps drive continuous - improvement. Regular meetings with security champions are a good place to - share and discuss lessons learned. - difficultyOfImplementation: - knowledge: 3 - time: 3 - resources: 1 - usefulness: 3 - level: 3 - implementation: [] + - documentation + - cwe + url: https://cwe.mitre.org/data/definitions/838.html references: samm2: - - O-IM-3-B + - D-SR-A-1 iso27001-2017: - - 16.1.6 + - Hardening is not explicitly covered by ISO 27001 - too specific + - 13.1.3 iso27001-2022: - - 5.27 - isImplemented: false - evidence: "" + - Hardening is not explicitly covered by ISO 27001 - too specific + - 8.22 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Application%20Hardening/subsection/Context-aware%20output%20encoding comments: "" tags: - none - Simple mob hacking: - uuid: 535f301a-e8e8-4eda-ad77-a08b035c92de - risk: Understanding security is hard. - measure: | - Participate with your whole team in a simple mob hacking session organized by the Security Champion Guild. - In the session the guild presents a vulnerable application and together you look at possible exploits. - Just like in mob programming there is one driver and several navigators. + Parametrization: + uuid: 00e91a8a-3972-4692-8679-674ab8547486 description: | - ### Guidelines for your simple mob hacking session - - All exploits happen via the user interface. - - No need for security/hacking tools. - - No need for deep technical or security knowledge. - - Use an insecure training app, e.g., [DVWA](https://dvwa.co.uk/) or [OWASP Juice Shop](https://owasp.org/www-project-juice-shop/). - - Encourage active participation, e.g., use small groups. - - Allow enough time for everyone to run at least one exploit. + By concatenating strings from user input to build SQL queries, an attacker can manipulate the query to do other unintentional SQL commands as well. - ### Benefits - - The team gets an idea of how exploits can look like and how easy applications can be attacked. - - The team understands functional correct working software can be highly insecure and easy to exploit. - difficultyOfImplementation: - knowledge: 5 - time: 3 - resources: 1 - usefulness: 3 - level: 3 - credits: | - AppSecure-nrw [Security Belts](https://github.com/AppSecure-nrw/security-belts/) - implementation: - - uuid: 1fff917f-205e-4eab-ae0e-1fab8c04bf3a - name: OWASP Juice Shop - tags: - - training - url: https://github.com/bkimminich/juice-shop - description: In case you do not have the budget to hire an external security - expert, an option is to use the OWASP JuiceShop on a "hacking Friday" - - uuid: a8cd9acb-ad22-44d6-b177-1154c65a8529 - name: Damn Vulnerable Web Application - tags: - - training - description: Simple Application with intended vulnerabilities. HTML based. - references: - samm2: - - G-EG-1-A - iso27001-2017: - - 7.2.2 - iso27001-2022: - - 6.3 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Process: - Approval by reviewing any new version: - uuid: 3f63bdbc-c75f-4780-a941-e6ad42e894e1 - risk: An individual might forget to implement security measures to protect source - code or infrastructure components. - measure: On each new version (e.g. Pull Request) of source code or infrastructure - components a security peer review of the changes is performed (two eyes principle) - and approval given by the reviewer. + This is called *SQL injection* but the principle applies to NoSql, and anywhere that your code is building commands that will be executed. + + Pay attention to these two lines of code. They seem similar, but behave very differently. + + * `sql.execute("SELECT * FROM table WHERE ID = " + id);` + * `sql.execute("SELECT * FROM table WHERE ID = ?", id);` + The second line is parameterized. The same principle applies to other types, such as command line execution, etc. + risk: "Systems vulnerable to injections may lead to data breaches, loss of data, + \nunauthorized alteration of data, or complete database compromise or downtime.\n\nThis + applies to SQL, NoSql, LDAP, XPath, email headers OS commands, etc.\n" + measure: | + * Identify which of the types your application is using. Check that you use: + * Use _parametrized queries_ (or _prepared statements_) + * For database queries, you may also use: + * Use _stored procedures_ () + * Use ORM (Object-Relational Mapping) tools that automatically handle input sanitization difficultyOfImplementation: - knowledge: 2 + knowledge: 1 time: 2 resources: 1 usefulness: 3 - level: 3 - implementation: [] - references: - samm2: [] - iso27001-2017: - - Peer review - four eyes principle is not explicitly required by ISO 27001 - - 6.1.2 - - 14.2.1 - iso27001-2022: - - Peer review - four eyes principle is not explicitly required by ISO 27001 - - 5.3 - - 8.25 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Definition of a change management process: - uuid: b4193d32-3948-47e2-a326-3748c48019a1 - risk: The impact of a change is not controlled because these are not recorded - or documented. - measure: Each change of a system is automatically recorded and adequately logged. - difficultyOfImplementation: - knowledge: 4 - time: 3 - resources: 1 - usefulness: 3 - level: 3 - implementation: [] - references: - samm2: [] - iso27001-2017: - - 14.2.2 - - 12.1.2 - - 12.4.1 - iso27001-2022: - - 8.32 - - 8.15 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Definition of simple BCDR practices for critical components: - uuid: c72da779-86cc-45b1-a339-190ce5093171 - risk: In case of an emergency, like a power outage, DR actions to perform are - not clear. This leads to reaction and remediation delays. - measure: By understanding and documenting a business continuity and disaster - recovery (BCDR) plan, the overall availability of systems and applications - is increased. Success factors like responsibilities, Service Level Agreements, - Recovery Point Objectives, Recovery Time Objectives or Failover must be fully - documented and understood. - difficultyOfImplementation: - knowledge: 4 - time: 3 - resources: 2 - usefulness: 4 level: 1 - implementation: [] + implementation: + - uuid: d880fa0f-9dbb-454e-a003-d844fad31ab4 + name: OWASP Parameterization CheatSheet + url: https://cheatsheetseries.owasp.org/cheatsheets/Query_Parameterization_Cheat_Sheet.html + tags: [] references: - samm2: [] + samm2: + - D-SR-A-1 iso27001-2017: - - 17.1.1 + - Hardening is not explicitly covered by ISO 27001 - too specific + - 13.1.3 iso27001-2022: - - 5.29 - isImplemented: false - evidence: "" + - Hardening is not explicitly covered by ISO 27001 - too specific + - 8.22 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Application%20Hardening/subsection/Parametrization comments: "" tags: - none -Implementation: - Application Hardening: App. Hardening Level 1: uuid: cf819225-30cb-4702-8e32-60225eedc33d risk: Using an insecure application might lead to a compromised application. @@ -3181,7 +2775,7 @@ Implementation: usefulness: 4 level: 2 dependsOn: - - App. Hardening Level 1 (50%) + - b597928e-54d6-48a5-a806-8003dcd56aab # App. Hardening Level 1 (50%) description: | To tackle the security of code developed in-house, OWASP offers an extensive collection of [Cheatsheets](https://cheatsheetseries.owasp.org/) demonstrating how to implement features securely. Moreover, the Security Knowledge Framework[1] offers an extensive library of code patterns spanning several programming languages. These patterns can be used to not only jump-start the development process, but also do so securely. @@ -3207,86 +2801,94 @@ Implementation: - uuid: 7bf90650-a53a-4581-a214-1afd5de3a059 name: OWASP MASVS tags: [] - url: https://github.com/OWASP/owasp-masvs + url: https://github.com/OWASP/masvs - uuid: 596cb528-8981-4723-bcc3-22c261f26114 name: API Security Maturity Model for Authorization tags: - api url: https://curity.io/resources/learn/the-api-security-maturity-model/ + - uuid: 6150533e-58ca-4b52-a9b2-6226545d9ea0 + name: Top 5 API Security Myths That Are Crushing Your Business + tags: + - documentation + - waf + url: https://thehackernews.com/2022/11/top-5-api-security-myths-that-are.html + description: | + There are several myths and misconceptions about API security. These myths about securing APIs are crushing your business references: samm2: - - D-SR-1-A + - D-SR-A-3 iso27001-2017: - Hardening is not explicitly covered by ISO 27001 - too specific - 13.1.3 iso27001-2022: - Hardening is not explicitly covered by ISO 27001 - too specific - 8.22 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Application%20Hardening/subsection/App.%20Hardening%20Level%201 comments: "" tags: - none - App. Hardening Level 1 (50%): - uuid: b597928e-54d6-48a5-a806-8003dcd56aab - risk: Using an insecure application might lead to a compromised application. - This might lead to total data theft or data modification. - measure: | - Following frameworks like the - * OWASP Application Security Verification Standard Level 1 - * OWASP Mobile Application Security Verification Standard + Containers are running as non-root: + uuid: a86c1fbc-28fd-4610-89a3-a7f73acfe45f + risk: |- + There are various reasons to run a container as non-root. Samples are listed: + ## Container Escape Vectors - in all applications provides a good baseline. Implement 50% of the recommendations. + - Root privileges significantly increase the chance of breaking container isolation + - Root access can be leveraged to exploit kernel vulnerabilities + - Compromised root containers provide attackers with maximum privileges inside the container + - Greater potential for escaping container boundaries to the host system + + ## Host System Vulnerabilities + + Root containers can potentially: + + - Mount sensitive host filesystems + - Access critical device files + - Modify host network settings + - Interact with host system processes + - Override security controls + + ## Resource Management Issues + + Root privileges may allow containers to: + + - Bypass resource quotas and limits + - Modify control group (cgroup) settings + - Interfere with other containers' resources + - Circumvent memory and CPU restrictions + + Security Boundary Weakening + + - Violates the principle of least privilege + - Provides unnecessary elevated permissions + - Expands the potential attack surface + - Increases the impact of a successful compromise + measure: "Containers are running as non-root. This can be enforced in the image + itself or during runtime parameters \n(e.g. `podman run --user [...]`)." difficultyOfImplementation: knowledge: 2 time: 2 resources: 1 usefulness: 3 - level: 1 - description: | - To tackle the security of code developed in-house, OWASP offers an extensive collection of [Cheatsheets](https://cheatsheetseries.owasp.org/) demonstrating how to implement features securely. Moreover, the Security Knowledge Framework[1] offers an extensive library of code patterns spanning several programming languages. These patterns can be used to not only jumpstart the development process, but also do so securely. - - [...] - - ### Planning aka Requirements Gathering & Analysis - The Requirements gathering process tries to answer the question: _"What is the system going to do?"_ At this stage, the [SAMM project](https://owaspsamm.org/model/) offers 3 distinct maturity levels covering both [in-house](https://owaspsamm.org/model/design/security-requirements/stream-a/) software development and [third party](https://owaspsamm.org/model/design/security-requirements/stream-b/) supplier security. - - ![SAMM Requirements](https://github.com/OWASP/www-project-integration-standards/raw/master/writeups/owasp_in_sdlc/images/OWASP-in0.png) - - Organizations can use these to add solid security considerations at the start of the Software Development or Procurement process. - - These general security considerations can be audited by using a subsection of the ASVS controls in section V1 as a questionnaire. This process attempts to ensure that every feature has concrete security considerations. - - In case of internal development and if the organization maps Features to Epics, the [Security Knowledge Framework](https://securityknowledgeframework.org/) can be used to facilitate this process by leveraging its questionnaire function, shown below. - - Source: [OWASP Project Integration](https://raw.githubusercontent.com/OWASP/www-project-integration-standards/master/writeups/owasp_in_sdlc/index.md) - implementation: - - uuid: 88767cde-1610-402e-98ec-bc3575377183 - name: OWASP ASVS - tags: [] - url: https://owasp.org/www-project-application-security-verification-standard/ - - uuid: 7bf90650-a53a-4581-a214-1afd5de3a059 - name: OWASP MASVS - tags: [] - url: https://github.com/OWASP/owasp-masvs - - uuid: 596cb528-8981-4723-bcc3-22c261f26114 - name: API Security Maturity Model for Authorization - tags: - - api - url: https://curity.io/resources/learn/the-api-security-maturity-model/ + level: 2 + implementation: [] references: samm2: - - D-SR-1-A + - O-EM-A-1 iso27001-2017: - - Hardening is not explicitly covered by ISO 27001 - too specific + - Virtual environments are not explicitly covered by ISO 27001 - too specific - 13.1.3 iso27001-2022: - - Hardening is not explicitly covered by ISO 27001 - too specific + - Virtual environments are not explicitly covered by ISO 27001 - too specific - 8.22 - isImplemented: false - comments: "" + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Application%20Hardening/subsection/Containers%20are%20running%20as%20non-root tags: - none - App. Hardening Level 2: - uuid: ffe86caf-2fec-4630-b514-2db83983984d + App. Hardening Level 2 (75%): + uuid: 03643ca2-03c2-472b-8e19-956bf02fe9b7 risk: Using an insecure application might lead to a compromised application. This might lead to total data theft or data modification. measure: | @@ -3294,13 +2896,13 @@ Implementation: * OWASP Application Security Verification Standard Level 2 * OWASP Mobile Application Security Verification Standard Level 2 - Implement 95%-100% of the recommendations. + Implement 75% of the recommendations. difficultyOfImplementation: knowledge: 3 time: 3 resources: 1 usefulness: 3 - level: 4 + level: 3 implementation: - uuid: 88767cde-1610-402e-98ec-bc3575377183 name: OWASP ASVS @@ -3309,25 +2911,96 @@ Implementation: - uuid: 7bf90650-a53a-4581-a214-1afd5de3a059 name: OWASP MASVS tags: [] - url: https://github.com/OWASP/owasp-masvs + url: https://github.com/OWASP/masvs + - uuid: 6150533e-58ca-4b52-a9b2-6226545d9ea0 + name: Top 5 API Security Myths That Are Crushing Your Business + tags: + - documentation + - waf + url: https://thehackernews.com/2022/11/top-5-api-security-myths-that-are.html + description: | + There are several myths and misconceptions about API security. These myths about securing APIs are crushing your business references: samm2: - - D-SR-2-A + - D-SR-A-3 iso27001-2017: - Hardening is not explicitly covered by ISO 27001 - too specific - 13.1.3 iso27001-2022: - Hardening is not explicitly covered by ISO 27001 - too specific - 8.22 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Application%20Hardening/subsection/App.%20Hardening%20Level%202%20%2875%25%29 isImplemented: false - evidence: "" comments: "" dependsOn: - - App. Hardening Level 2 (75%) + - cf819225-30cb-4702-8e32-60225eedc33d # App. Hardening Level 1 + tags: + - none + Secure headers: + uuid: 29318d60-18ce-4526-80ea-f5928e49f639 + risk: | + Missing or misconfigured security headers can lead to various security vulnerabilities, e.g.: + - Cross-Site Scripting (XSS) due to missing Content Security Policy + - Clickjacking attacks due to missing X-Frame-Options + - Information disclosure through Server header exposure + - SSL/TLS downgrade attacks due to missing HSTS + - Cross-site scripting and injection due to missing security headers + measure: | + Implement and enforce security headers across all applications and services + + Implementation Methods: + 1. Reverse Proxy/Load Balancer: Configure at nginx/Apache level + 2. Web Application: Implement in the application middleware + 3. Service Mesh: Configure at the ingress controller level + 4. Standard Docker Image: Use secure base images with preset headers + + Remove or Secure: + - Server header: Hide server version information + - X-Powered-By: Remove technology stack information + difficultyOfImplementation: + knowledge: 2 + time: 1 + resources: 2 + usefulness: 4 + level: 3 + implementation: + - uuid: 370b7f35-4da7-4833-89d6-7266b82ea07e + name: OWASP Secure Headers Project + tags: + - header + - documentation + url: https://owasp.org/www-project-secure-headers/ + description: "The OWASP Secure Headers Project (also called OSHP) describes + HTTP response headers that your application can use \nto increase the security + of your application. Once set, these HTTP response headers can restrict + modern browsers \nfrom running into easily preventable vulnerabilities. + The OWASP Secure Headers Project intends to raise awareness\nand use of + these headers." + meta: + implementationGuide: | + Essential headers: + - Content-Security-Policy: Define trusted sources for content + - Strict-Transport-Security: Enforce HTTPS connections + - X-Frame-Options: Prevent clickjacking attacks + - X-Content-Type-Options: Prevent MIME-type sniffing + - X-XSS-Protection: Enable browser's XSS filtering + - Referrer-Policy: Control information in the Referrer header + references: + samm2: + - O-EM-A-2 + iso27001-2017: + - Hardening is not explicitly covered by ISO 27001 - too specific + - 13.1.3 + iso27001-2022: + - Hardening is not explicitly covered by ISO 27001 - too specific + - 8.22 + openCRE: + - https://www.opencre.org/cre/620-421 tags: - none - App. Hardening Level 2 (75%): - uuid: 03643ca2-03c2-472b-8e19-956bf02fe9b7 + App. Hardening Level 2: + uuid: ffe86caf-2fec-4630-b514-2db83983984d risk: Using an insecure application might lead to a compromised application. This might lead to total data theft or data modification. measure: | @@ -3335,13 +3008,13 @@ Implementation: * OWASP Application Security Verification Standard Level 2 * OWASP Mobile Application Security Verification Standard Level 2 - Implement 75% of the recommendations. + Implement 95%-100% of the recommendations. difficultyOfImplementation: knowledge: 3 time: 3 resources: 1 usefulness: 3 - level: 3 + level: 4 implementation: - uuid: 88767cde-1610-402e-98ec-bc3575377183 name: OWASP ASVS @@ -3350,21 +3023,22 @@ Implementation: - uuid: 7bf90650-a53a-4581-a214-1afd5de3a059 name: OWASP MASVS tags: [] - url: https://github.com/OWASP/owasp-masvs + url: https://github.com/OWASP/masvs references: samm2: - - D-SR-2-A + - D-SR-A-2 iso27001-2017: - Hardening is not explicitly covered by ISO 27001 - too specific - 13.1.3 iso27001-2022: - Hardening is not explicitly covered by ISO 27001 - too specific - 8.22 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Application%20Hardening/subsection/App.%20Hardening%20Level%202 isImplemented: false - evidence: "" comments: "" dependsOn: - - App. Hardening Level 1 + - 03643ca2-03c2-472b-8e19-956bf02fe9b7 # App. Hardening Level 2 (75%) tags: - none App. Hardening Level 3: @@ -3391,66 +3065,45 @@ Implementation: - uuid: 7bf90650-a53a-4581-a214-1afd5de3a059 name: OWASP MASVS tags: [] - url: https://github.com/OWASP/owasp-masvs + url: https://github.com/OWASP/masvs references: samm2: - - D-SR-3-A + - D-SR-A-3 iso27001-2017: - Hardening is not explicitly covered by ISO 27001 - too specific - 13.1.3 iso27001-2022: - Hardening is not explicitly covered by ISO 27001 - too specific - 8.22 - isImplemented: false - evidence: "" - comments: "" + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Application%20Hardening/subsection/App.%20Hardening%20Level%203 dependsOn: - - App. Hardening Level 2 - tags: - - none - Contextualized Encoding: - uuid: e1f37abb-d848-4a3a-b3df-65e91a89dcb7 - risk: The generation of interpreter directives from user-provided data poses - difficulties and can introduce vulnerabilities to injection attacks. - measure: | - Implementing contextualized encoding, such as employing object-relational mapping tools or utilizing prepared statements, nearly removes the threat of injection vulnerabilities. - difficultyOfImplementation: - knowledge: 2 - time: 2 - resources: 1 - usefulness: 3 - level: 1 - description: | - Bear in mind that utilizing frameworks is a recommended approach; however, they can develop known security weaknesses over time. Diligent and regular patching is crucial. - implementation: [] - references: - samm2: - - D-SR-1-A - iso27001-2017: - - Hardening is not explicitly covered by ISO 27001 - too specific - - 13.1.3 - iso27001-2022: - - Hardening is not explicitly covered by ISO 27001 - too specific - - 8.22 + - ffe86caf-2fec-4630-b514-2db83983984d # App. Hardening Level 2 tags: - none Development and Source Control: - .gitignore: - uuid: 363a3eea-baf9-4010-88ca-bb8186a2989d - risk: Unintended leakage of secrets, debug, or workstation specific data - measure: .gitignore files help prevent accidental commits of secrets, debug, - or workstation specific data + Version control: + uuid: 066084c6-1135-4635-9cc5-9e75c7c5459f + description: |- + Use a _version control system_ like Github, Gitlab, Bitbucket, etc to version your source code. + Also known as _source control_, _revision control_, or _source code management_. + risk: Without version control, it is challenging to track changes, collaborate + effectively, and maintain a history of code modifications. Rollback to earlier + versions is hard. + measure: Version your source code in order to identify deployed features and + issues. This includes application and infrastructure code, jenkins configuration, + container and virtual machine images definitions. difficultyOfImplementation: - knowledge: 2 - time: 1 - resources: 1 + knowledge: 3 + time: 3 + resources: 3 usefulness: 5 - level: 4 - dependsOn: [] + level: 1 implementation: [] references: samm2: - - O-EM-1-A + - O-EM-A-1 + - I-SB-A-2 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 12.1.1 @@ -3460,119 +3113,122 @@ Implementation: - Not explicitly covered by ISO 27001 - too specific - 5.37 - 8.32 - evidence: "" - comments: "" + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Development%20and%20Source%20Control/subsection/Version%20control tags: - none - API design validation: - uuid: 948a4d51-ceb5-4ebd-bdc7-d74ea25e171c - risk: Creation of insecure or non-compliant API. - measure: | - Design contract-first APIs using an interface description language such as OpenAPI, AsyncAPI or SOAP - and validate the specification using specific tools. - Checks should be integrated in IDEs and CI/CD pipelines. + Require a PR before merging: + uuid: e7598ac4-b082-4e56-b7df-e2c6b426a5e2 + risk: Intentional or accidental alterations in critical branches like main (or + master). + measure: Define source code management system policies (e.g. branch protection + rules, mandatory code reviews from at least one person, ...) to ensure that + changes to critical branches are only possible under defined conditions. These + policies can be implemented at repository level or organization level, depending + on the source code management system. difficultyOfImplementation: knowledge: 2 - time: 2 + time: 1 resources: 2 usefulness: 4 - level: 3 + level: 2 implementation: - - uuid: 261f243e-f89c-4169-b076-b22a03ec00be - name: Spectral + - uuid: b1b88bc5-5a22-4888-a27b-acce3d9fe29a + name: Improve code quality with branch policies + url: https://learn.microsoft.com/en-us/azure/devops/repos/git/branch-policies?view=azure-devops tags: - - linting - - api - - documentation - url: https://github.com/stoplightio/spectral - description: | - Spectral is a flexible JSON/YAML linter built with extensibility in mind. - It uses JSON/YAML path rules to describe the problems you want to find. - - uuid: d2c9403d-9da2-4518-b33f-8b74b9c5ca3f - name: API OAS Checker + - source-code-protection + - scm + - uuid: 99211481-de9c-4358-880e-628366416a27 + name: About protected branches + url: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/about-protected-branches tags: - - linting - - api - - documentation - url: https://github.com/italia/api-oas-checker - description: | - A tool to check OpenAPI specifications using a comprehensive ruleset based - on API best practices. + - source-code-protection + - scm references: samm2: - - V-ST-1-A + - O-EM-A-1 iso27001-2017: + - Peer review - four eyes principle is not explicitly required by ISO 27001 + - 6.1.2 - 14.2.1 - - 14.2.5 iso27001-2022: + - Peer review - four eyes principle is not explicitly required by ISO 27001 + - 5.3 - 8.25 - - 8.27 - - 8.28 - isImplemented: false - evidence: "" - comments: "" + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Development%20and%20Source%20Control/subsection/Require%20a%20PR%20before%20merging tags: - none - Local development linting & style checks performed: - uuid: 517b0957-4981-4ac0-b4c7-0d8d1934c474 - risk: Insecure or unmaintainable code base. - measure: Integrate static code analysis tools in IDEs. + Block force pushes: + uuid: c7d99b18-c3e1-4d22-b2e3-9aa9146c0b17 + risk: "Misuse of force push can lead to loss of work. It may overwrite remote + \nbranches without warning, potentially erasing valuable contributions from + team members. This can disrupt collaboration, \ncause data loss, and create + confusion in the development process.\n\nBypassing the pull request process + might remove an important code review step. \nThis increases the risk of merging + low-quality or buggy code into the main branch, potentially introducing bugs + in the codebase." + measure: Mandate blocking of force pushes in the version control platform. difficultyOfImplementation: - knowledge: 1 + knowledge: 2 time: 1 - resources: 1 - usefulness: 2 - level: 5 - description: "" + resources: 2 + usefulness: 3 + level: 3 + dependsOn: + - e7598ac4-b082-4e56-b7df-e2c6b426a5e2 # Require a PR before merging implementation: - - uuid: 0b7ec352-0c36-4de1-8912-617fc6c608fe - name: How to enforce a consistent coding style in your projects - url: https://www.meziantou.net/how-to-enforce-a-consistent-coding-style-in-your-projects.htm + - uuid: b1b88bc5-5a22-4888-a27b-acce3d9fe29a + name: Improve code quality with branch policies + url: https://learn.microsoft.com/en-us/azure/devops/repos/git/branch-policies?view=azure-devops tags: - - ide - - linting - - uuid: aa5ded61-5380-4da6-9474-afc36a397682 - name: In-Depth Linting of Your TypeScript While Coding - url: https://blog.sonarsource.com/in-depth-linting-of-your-typescript-while-coding + - source-code-protection + - scm + - uuid: 99211481-de9c-4358-880e-628366416a27 + name: About protected branches + url: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/about-protected-branches tags: - - ide - - linting + - source-code-protection + - scm references: samm2: - - V-ST-1-A + - O-EM-A-1 iso27001-2017: - - ISO 27001:2017 mapping is missing + - 6.1.2 + - 14.2.1 iso27001-2022: - - ISO 27001:2022 mapping is missing - isImplemented: false - evidence: "" - comments: "" + - 5.3 + - 8.25 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Development%20and%20Source%20Control/subsection/Block%20force%20pushes tags: - none - Source Control Protection: - uuid: e7598ac4-b082-4e56-b7df-e2c6b426a5e2 - risk: Intentional or accidental alterations in critical branches like master. - measure: Define source code management system policies (e.g. branch protection - rules, mandatory code reviews, ...) to ensure that changes to critical branches - are only possible under defined conditions. These policies can be implemented - at repository level or organization level, depending on the source code management - system. + Dismiss stale PR approvals: + uuid: ea6f69f7-54a5-4922-ac15-a77ff0c16162 + risk: Intentional or accidental alterations in critical branches like main (or + master) through post-approval code additions. + measure: Implement a policy where any commits made after a pull request has + been approved automatically revoke that approval, necessitating a fresh review + and re-approval process. difficultyOfImplementation: knowledge: 2 time: 1 resources: 2 usefulness: 4 - level: 2 + level: 3 + dependsOn: + - e7598ac4-b082-4e56-b7df-e2c6b426a5e2 # Require a PR before merging implementation: - uuid: b1b88bc5-5a22-4888-a27b-acce3d9fe29a name: Improve code quality with branch policies - url: https://docs.microsoft.com/en-us/azure/devops/repos/git/branch-policies?view=azure-devops + url: https://learn.microsoft.com/en-us/azure/devops/repos/git/branch-policies?view=azure-devops tags: - source-code-protection - scm - uuid: 99211481-de9c-4358-880e-628366416a27 name: About protected branches - url: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/defining-the-mergeability-of-pull-requests/about-protected-branches + url: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/about-protected-branches tags: - source-code-protection - scm @@ -3580,11 +3236,11 @@ Implementation: name: Enforcement of commit signing tags: - signing - url: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/defining-the-mergeability-of-pull-requests/managing-a-branch-protection-rule + url: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/managing-a-branch-protection-rule description: Usage of branch protection rules references: samm2: - - O-EM-1-A + - O-EM-A-1 iso27001-2017: - Peer review - four eyes principle is not explicitly required by ISO 27001 - 6.1.2 @@ -3593,44 +3249,242 @@ Implementation: - Peer review - four eyes principle is not explicitly required by ISO 27001 - 5.3 - 8.25 - isImplemented: false - evidence: "" - comments: "" + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Development%20and%20Source%20Control/subsection/Dismiss%20stale%20PR%20approvals tags: - none - Versioning: - uuid: 066084c6-1135-4635-9cc5-9e75c7c5459f - risk: Deployment of untracked artifacts. - measure: Version artifacts in order to identify deployed features and issues. - This includes application and infrastructure code, jenkins configuration, - container and virtual machine images. + Require status checks to pass: + uuid: ac8730a2-ccc0-465c-9550-d91edae9d5ee + risk: Organizations risk introducing broken builds, quality issues, and security + vulnerabilities into their codebase. + measure: Mandate passing of security related specified status checks, like successful + builds or static application security tests, before proceeding. difficultyOfImplementation: - knowledge: 3 - time: 3 - resources: 3 - usefulness: 5 - level: 1 + knowledge: 2 + time: 1 + resources: 2 + usefulness: 4 + level: 3 dependsOn: - - Defined deployment process - implementation: [] + - e7598ac4-b082-4e56-b7df-e2c6b426a5e2 # Require a PR before merging + implementation: + - uuid: b1b88bc5-5a22-4888-a27b-acce3d9fe29a + name: Improve code quality with branch policies + url: https://learn.microsoft.com/en-us/azure/devops/repos/git/branch-policies?view=azure-devops + tags: + - source-code-protection + - scm + - uuid: 99211481-de9c-4358-880e-628366416a27 + name: About protected branches + url: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/about-protected-branches + tags: + - source-code-protection + - scm + - uuid: 86c6bdba-73c0-4c99-bbda-81b85c9fe2a4 + name: Enforcement of commit signing + tags: + - signing + url: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/managing-a-branch-protection-rule + description: Usage of branch protection rules references: samm2: - - O-EM-1-A + - O-EM-A-1 iso27001-2017: - - Not explicitly covered by ISO 27001 - too specific - - 12.1.1 - - 12.1.2 - - 14.2.2 + - 6.1.2 + - 14.2.1 iso27001-2022: - - Not explicitly covered by ISO 27001 - too specific - - 5.37 - - 8.32 - isImplemented: false - evidence: "" - comments: "" - tags: + - 5.3 + - 8.25 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Development%20and%20Source%20Control/subsection/Require%20status%20checks%20to%20pass + tags: + - none + .gitignore: + uuid: 363a3eea-baf9-4010-88ca-bb8186a2989d + risk: Unintended leakage of secrets, debug, or workstation specific data + measure: .gitignore files help prevent accidental commits of secrets, debug, + or workstation specific data + difficultyOfImplementation: + knowledge: 2 + time: 1 + resources: 1 + usefulness: 5 + level: 4 + dependsOn: [] + implementation: [] + references: + samm2: + - O-EM-A-1 + iso27001-2017: + - Not explicitly covered by ISO 27001 - too specific + - 12.1.1 + - 12.1.2 + - 14.2.2 + iso27001-2022: + - Not explicitly covered by ISO 27001 - too specific + - 5.37 + - 8.32 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Development%20and%20Source%20Control/subsection/.gitignore + tags: + - none + Local development linting & style checks performed: + uuid: 517b0957-4981-4ac0-b4c7-0d8d1934c474 + risk: Insecure or unmaintainable code base. + measure: Integrate static code analysis tools in IDEs. + difficultyOfImplementation: + knowledge: 1 + time: 1 + resources: 1 + usefulness: 2 + level: 5 + description: "" + implementation: + - uuid: 0b7ec352-0c36-4de1-8912-617fc6c608fe + name: How to enforce a consistent coding style in your projects + url: https://www.meziantou.net/how-to-enforce-a-consistent-coding-style-in-your-projects.htm + tags: + - ide + - linting + - uuid: aa5ded61-5380-4da6-9474-afc36a397682 + name: In-Depth Linting of Your TypeScript While Coding + url: https://medium.com/@elenavilchik/in-depth-linting-of-your-typescript-while-coding-1d084affbf0 + test-url-expects: + - 403 + tags: + - ide + - linting + - uuid: 6a0948a7-4781-4858-9766-f4303971b28b + name: eslint + tags: [] + url: https://eslint.org/ + references: + samm2: + - V-ST-A-1 + iso27001-2017: + - ISO 27001:2017 mapping is missing + iso27001-2022: + - ISO 27001:2022 mapping is missing + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Development%20and%20Source%20Control/subsection/Local%20development%20linting%20%26%20style%20checks%20performed + isImplemented: false + evidence: "" + comments: "" + tags: - none Infrastructure Hardening: + MFA for admins: + uuid: 8098e416-e1ed-4ae4-a561-83efbe76bf57 + risk: One factor authentication is more vulnerable to brute force attacks and + is considered less secure. + measure: Two ore more factor authentication for all privileged accounts on systems + and applications + difficultyOfImplementation: + knowledge: 2 + time: 1 + resources: 2 + usefulness: 4 + level: 1 + implementation: + - uuid: d5981117-9bc2-45ed-b4a4-383135dc13d8 + name: YubiKey - Smartcard + tags: [] + url: https://d3fend.mitre.org/technique/d3f:Multi-factorAuthentication/ + - uuid: 6151cfb3-c894-421e-83da-cac0b2bfaec8 + name: SMS + tags: [] + - uuid: f69f5d03-691f-4e14-8fbc-ad66e2e5a12d + name: TOTP + tags: [] + url: https://d3fend.mitre.org/technique/d3f:One-timePassword/ + references: + samm2: + - O-EM-A-1 + iso27001-2017: + - 9.2.4 + - 6.1.2 + - 14.2.1 + iso27001-2022: + - 5.17 + - 5.3 + - 8.25 + d3f: + - Multi-factorAuthentication + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/MFA%20for%20admins + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Simple access control for systems: + uuid: 82e499d1-f463-4a4b-be90-68812a874af6 + description: Basic access control for internal systems is implemented. + risk: Attackers a gaining access to other internal systems and application interfaces + is one breach occurs. + measure: All internal systems are using simple authentication + assessment: "- Presenting the documentation of the review of all user privileges + yearly. \n- Presenting the admin count and validating that there are less + than 5 admins per system.\n" + difficultyOfImplementation: + knowledge: 3 + time: 3 + resources: 3 + usefulness: 5 + level: 1 + implementation: + - uuid: 41fda224-2980-443c-bfd4-0a1d4b520cb9 + name: HTTP-Basic Authentication + tags: [] + url: https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/Authentication + - uuid: e506f60b-747b-44b1-8fe8-f67ccd8f290e + name: VPN + tags: [] + url: https://d3fend.mitre.org/dao/artifact/d3f:VPNServer/ + references: + samm2: + - O-EM-A-1 + iso27001-2017: + - 9.4.1 + iso27001-2022: + - 8.3 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/Simple%20access%20control%20for%20systems + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Usage of edge encryption at transit: + uuid: ad23be9c-5661-4f1f-81a3-5a5dc7061629 + risk: Evil actors might be able to perform a man in the middle attack and sniff + confidential information (e.g. authentication factors like passwords). + measure: |- + By using encryption at the edge of traffic in transit, it is impossible + or at least harder to sniff credentials or information being outside of the organization. + + Using standard secure protocols like HTTPS is recommended. + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 1 + usefulness: 4 + level: 1 + implementation: "" + references: + samm2: + - I-SD-B-2 + iso27001-2017: + - 10.1 + iso27001-2022: + - 8.24 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/Usage%20of%20edge%20encryption%20at%20transit + isImplemented: false + evidence: "" + comments: "" + tags: + - none Applications are running in virtualized environments: uuid: 3a94d55e-fd82-4996-9eb3-20d23ff2a873 risk: Through a vulnerability in one service on a server, the attacker gains @@ -3645,15 +3499,15 @@ Implementation: implementation: [] references: samm2: - - O-EM-1-A + - O-EM-A-1 iso27001-2017: - Virtual environments are not explicitly covered by ISO 27001 - too specific - 13.1.3 iso27001-2022: - Virtual environments are not explicitly covered by ISO 27001 - too specific - 8.22 - isImplemented: false - evidence: "" + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/Applications%20are%20running%20in%20virtualized%20environments comments: "" tags: - none @@ -3677,7 +3531,7 @@ Implementation: name: A Point in Time Recovery for databases should be implemented. tags: [] dependsOn: - - Defined deployment process + - 74938a3f-1269-49b9-9d0f-c43a79a1985a # Defined deployment process references: samm2: - TODO @@ -3687,6 +3541,8 @@ Implementation: iso27001-2022: - 8.13 - 8.31 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/Backup isImplemented: false evidence: "" comments: "" @@ -3707,13 +3563,13 @@ Implementation: level: 2 implementation: - uuid: edaec98d-dac7-4dfd-8ab3-42c471d5b9ff - name: CIS Kubernetes Bench for Security + name: CIS Kubernetes Benchmark for Security tags: [] - url: https://www.cisecurity.org/cis-benchmarks/ + url: https://www.cisecurity.org/benchmark/kubernetes - uuid: 4dd23c4a-5a7e-4917-82cf-d00e0f04482f - name: CIS Docker Bench for Security + name: CIS Docker Benchmark for Security tags: [] - url: https://www.cisecurity.org/cis-benchmarks/ + url: https://www.cisecurity.org/benchmark/docker - uuid: f4d7c796-8574-4a88-ab00-98d245a115ef name: For example for Cont tags: [] @@ -3730,13 +3586,13 @@ Implementation: name: Attack Matrix Containers tags: - mitre - url: https://attack.mitre.org/matrices/enterprise/cloud/ + url: https://attack.mitre.org/matrices/enterprise/containers/ description: Attack matrix for containers - uuid: 9fbc47ad-82bc-46d1-bba9-66815ab79935 name: Attack Matrix Kubernetes tags: - mitre - url: https://www.microsoft.com/security/blog/2020/04/02/attack-matrix-kubernetes/ + url: https://www.microsoft.com/en-US/security/blog/2020/04/02/attack-matrix-kubernetes/ description: Attack matrix for kubernetes - uuid: b7a92886-aec9-4bf4-94c4-07cc191a97af name: Defend the core kubernetes security at every layer @@ -3747,117 +3603,264 @@ Implementation: - kubernetes references: samm2: - - O-EM-1-A + - O-EM-A-1 iso27001-2017: - system hardening is not explicitly covered by ISO 27001 - too specific - 13.1.3 iso27001-2022: - ISO 27001:2022 mapping is missing + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/Baseline%20Hardening%20of%20the%20environment isImplemented: false evidence: "" comments: "" tags: - none - Filter outgoing traffic: - uuid: 6df508ef-86fc-4c22-bd9f-646c3127ce7d - risk: A compromised infrastructure component might try to send out stolen data. - measure: Having a whitelist and explicitly allowing egress traffic provides - the ability to stop unauthorized data leakage. + Isolated networks for virtual environments: + uuid: 4ce24abd-8ba6-494c-828d-4d193e28e4a1 + risk: Virtual environments in default settings are able to access other virtual + environments on the network stack. By using virtual machines, it is often + possible to connect to other virtual machines. By using docker, one bridge + is used by default so that all containers on one host can communicate with + each other. + measure: The communication between virtual environments is controlled and regulated. difficultyOfImplementation: knowledge: 3 time: 3 resources: 3 - usefulness: 2 - level: 3 + usefulness: 5 + level: 2 dependsOn: [] implementation: - - uuid: 4a024319-4510-4a53-a8b6-8f35b6c01867 - name: Open Policy Agent + - uuid: 9429d52c-203d-49ae-814f-1401210887cd + name: istio + tags: [] + url: https://istio.io/ + - uuid: fc0eda30-2bf7-466f-948e-e17584db9f30 + name: bridges tags: [] - url: https://www.openpolicyagent.org/ - uuid: e3c6fb92-3f7d-471f-9308-c62359f4f1b7 name: firewalls tags: [] url: https://d3fend.mitre.org/dao/artifact/d3f:Firewall/ references: samm2: - - O-EM-1-A + - O-EM-A-1 iso27001-2017: - Virtual environments are not explicitly covered by ISO 27001 - too specific - 13.1.3 iso27001-2022: - Virtual environments are not explicitly covered by ISO 27001 - too specific - 8.22 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/Isolated%20networks%20for%20virtual%20environments isImplemented: false evidence: "" comments: "" tags: - none - Hardening of the Environment: - uuid: dcf9601b-b4f2-4e25-9143-e39af75f7c33 - risk: Using default configurations for a cluster environment leads to potential - risks. - measure: Harden environments according to best practices. Level 2 and partially - level 3 from hardening practices like 'CIS Kubernetes Bench for Security' - should be considered. + MFA: + uuid: 598e9f13-1ac8-4a01-b85e-8fab93ee81de + risk: One factor authentication is more vulnerable to brute force attacks and + is considered less secure. + measure: Two ore more factor authentication for all accounts on all (important) + systems and applications difficultyOfImplementation: - knowledge: 4 - time: 4 + knowledge: 2 + time: 2 resources: 2 - usefulness: 3 - level: 4 + usefulness: 4 + level: 2 + dependsOn: + - 8098e416-e1ed-4ae4-a561-83efbe76bf57 # MFA for admins implementation: - - uuid: edaec98d-dac7-4dfd-8ab3-42c471d5b9ff - name: CIS Kubernetes Bench for Security + - uuid: d5981117-9bc2-45ed-b4a4-383135dc13d8 + name: YubiKey - Smartcard tags: [] - url: https://www.cisecurity.org/cis-benchmarks/ - - uuid: 4dd23c4a-5a7e-4917-82cf-d00e0f04482f - name: CIS Docker Bench for Security + url: https://d3fend.mitre.org/technique/d3f:Multi-factorAuthentication/ + - uuid: 6151cfb3-c894-421e-83da-cac0b2bfaec8 + name: SMS tags: [] - url: https://www.cisecurity.org/cis-benchmarks/ - - uuid: f4d7c796-8574-4a88-ab00-98d245a115ef - name: For example for Cont + - uuid: f69f5d03-691f-4e14-8fbc-ad66e2e5a12d + name: TOTP tags: [] - description: 'For example for Containers: Deny running containers as root, - deny using advanced privileges, deny mounting of the hole filesystem, ...' - url: https://d3fend.mitre.org/technique/d3f:ExecutionIsolation/ - - uuid: 3b7df373-2ad9-456e-9abe-439cdc9d4d8b - name: Attack Matrix Cloud - tags: - - mitre - url: https://attack.mitre.org/matrices/enterprise/cloud/ - description: Attack matrix for cloud - - uuid: 59881520-4c69-4922-a44e-99044a77de2b - name: Attack Matrix Containers - tags: - - mitre - url: https://attack.mitre.org/matrices/enterprise/cloud/ - description: Attack matrix for containers - - uuid: 9fbc47ad-82bc-46d1-bba9-66815ab79935 - name: Attack Matrix Kubernetes - tags: - - mitre - url: https://www.microsoft.com/security/blog/2020/04/02/attack-matrix-kubernetes/ - description: Attack matrix for kubernetes - - uuid: b7a92886-aec9-4bf4-94c4-07cc191a97af - name: Defend the core kubernetes security at every layer - url: https://thenewstack.io/defend-the-core-kubernetes-security-at-every-layer/ - tags: - - documentation - - cluster - - kubernetes + url: https://d3fend.mitre.org/technique/d3f:One-timePassword/ references: samm2: - - O-EM-1-A + - O-EM-A-1 iso27001-2017: - - Hardening is not explicitly covered by ISO 27001 - too specific - - 13.1.3 + - 9.2.4 + - 6.1.2 + - 14.2.1 iso27001-2022: - - Hardening is not explicitly covered by ISO 27001 - too specific - - 8.22 - isImplemented: false - evidence: "" - comments: "" + - 5.17 + - 5.3 + - 8.25 + d3f: + - Multi-factorAuthentication + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/MFA + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Usage of an security account: + uuid: 746025a6-dbfb-4087-a000-e46acab64ee1 + risk: Having security auditing in the same account as infrastructure and applications + at the cloud provide might cause evil administrators (or threat actors taking + over an account of an administrator) to alter evidence like audit logs. + measure: Usage of a separate account dedicated for security activities. + difficultyOfImplementation: + knowledge: 3 + time: 2 + resources: 3 + usefulness: 4 + level: 2 + implementation: "" + references: + samm2: + - I-SD-B-2 + iso27001-2017: + - 10.1 + iso27001-2022: + - ISO 27001:2022 mapping is missing + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/Usage%20of%20an%20security%20account + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Usage of encryption at rest: + uuid: 0ff45fb8-7eef-46ed-9b3a-84c955cd7060 + risk: Evil actors might be able to access data and read information, e.g. from + physical hard disks. + measure: By using encryption at rest, it is impossible or at least harder to + to read information. + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 1 + usefulness: 4 + level: 2 + implementation: "" + references: + samm2: + - I-SD-B-2 + iso27001-2017: + - 10.1 + iso27001-2022: + - 8.24 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/Usage%20of%20encryption%20at%20rest + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Usage of test and production environments: + uuid: bfdacb52-1e3f-431d-ae72-d844a5e86415 + risk: Security tests are not running regularly because test environments are + missing + measure: A test and a production like environment is used + difficultyOfImplementation: + knowledge: 3 + time: 3 + resources: 5 + usefulness: 4 + level: 2 + dependsOn: + - 74938a3f-1269-49b9-9d0f-c43a79a1985a # Defined deployment process + implementation: [] + references: + samm2: + - O-EM-A-1 + iso27001-2017: + - Not explicitly covered by ISO 27001 - too specific + - 12.1.4 + - 17.2.1 + iso27001-2022: + - Not explicitly covered by ISO 27001 - too specific + - 8.31 + - 8.14 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/Usage%20of%20test%20and%20production%20environments + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Virtual environments are limited: + uuid: 760f1056-b0ee-4f22-a35b-f65446f944ca + risk: Denial of service (internally by an attacker or unintentionally by a bug) + on one service effects other services + measure: All virtual environments are using resource limits on hard disks, memory + and CPU + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 3 + usefulness: 3 + level: 2 + dependsOn: + - 3a94d55e-fd82-4996-9eb3-20d23ff2a873 # Applications are running in virtualized environments + implementation: [] + references: + samm2: + - O-EM-A-1 + iso27001-2017: + - Virtual environments are not explicitly covered by ISO 27001 - too specific + - 12.1.3 + - 13.1.3 + - 17.2.1 + iso27001-2022: + - Virtual environments are not explicitly covered by ISO 27001 - too specific + - 8.6 + - 8.22 + - 8.14 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/Virtual%20environments%20are%20limited + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Filter outgoing traffic: + uuid: 6df508ef-86fc-4c22-bd9f-646c3127ce7d + risk: A compromised infrastructure component might try to send out stolen data. + measure: Having a whitelist and explicitly allowing egress traffic provides + the ability to stop unauthorized data leakage. + difficultyOfImplementation: + knowledge: 3 + time: 3 + resources: 3 + usefulness: 2 + level: 3 + dependsOn: [] + implementation: + - uuid: 4a024319-4510-4a53-a8b6-8f35b6c01867 + name: Open Policy Agent + tags: [] + url: https://www.openpolicyagent.org/ + - uuid: e3c6fb92-3f7d-471f-9308-c62359f4f1b7 + name: firewalls + tags: [] + url: https://d3fend.mitre.org/dao/artifact/d3f:Firewall/ + references: + samm2: + - O-EM-A-2 + iso27001-2017: + - Virtual environments are not explicitly covered by ISO 27001 - too specific + - 13.1.3 + iso27001-2022: + - Virtual environments are not explicitly covered by ISO 27001 - too specific + - 8.22 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/Filter%20outgoing%20traffic + isImplemented: false + evidence: "" + comments: "" tags: - none Immutable infrastructure: @@ -3871,20 +3874,22 @@ Implementation: usefulness: 3 level: 3 dependsOn: - - Infrastructure as Code + - 8b994601-575e-4ea5-b228-accb18c8e514 # Infrastructure as Code implementation: - uuid: b206481f-9c66-45e2-843c-37c5730580cd name: Remove direct access to infrastructure tags: [] references: samm2: - - O-EM-1-A + - O-EM-A-2 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 17.2.1 iso27001-2022: - Not explicitly covered by ISO 27001 - too specific - 8.14 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/Immutable%20infrastructure isImplemented: false evidence: "" comments: "" @@ -3926,7 +3931,7 @@ Implementation: url: https://www.jenkins.io/doc/book/pipeline/jenkinsfile/ references: samm2: - - O-EM-1-A + - O-EM-A-2 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 12.1.1 @@ -3935,47 +3940,8 @@ Implementation: - Not explicitly covered by ISO 27001 - too specific - 5.37 - 8.32 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Isolated networks for virtual environments: - uuid: 4ce24abd-8ba6-494c-828d-4d193e28e4a1 - risk: Virtual environments in default settings are able to access other virtual - environments on the network stack. By using virtual machines, it is often - possible to connect to other virtual machines. By using docker, one bridge - is used by default so that all containers on one host can communicate with - each other. - measure: The communication between virtual environments is controlled and regulated. - difficultyOfImplementation: - knowledge: 3 - time: 3 - resources: 3 - usefulness: 5 - level: 2 - dependsOn: [] - implementation: - - uuid: 9429d52c-203d-49ae-814f-1401210887cd - name: istio - tags: [] - url: https://istio.io/ - - uuid: fc0eda30-2bf7-466f-948e-e17584db9f30 - name: bridges - tags: [] - - uuid: e3c6fb92-3f7d-471f-9308-c62359f4f1b7 - name: firewalls - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:Firewall/ - references: - samm2: - - O-EM-1-A - iso27001-2017: - - Virtual environments are not explicitly covered by ISO 27001 - too specific - - 13.1.3 - iso27001-2022: - - Virtual environments are not explicitly covered by ISO 27001 - too specific - - 8.22 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/Infrastructure%20as%20Code isImplemented: false evidence: "" comments: "" @@ -3992,7 +3958,7 @@ Implementation: usefulness: 5 level: 3 dependsOn: - - Audit of system events + - 1cd5e4b8-be36-4726-adc7-d8f843f47ac8 # Audit of system events implementation: - uuid: 0cc7e68b-f7d9-4e66-8065-47d076129ffd name: seccomp @@ -4013,236 +3979,277 @@ Implementation: Falco makes it easy to consume kernel events, and enrich those events with information from Kubernetes and the rest of the cloud native stack. references: samm2: - - O-EM-1-A + - O-EM-A-2 iso27001-2017: - System hardening is not explicitly covered by ISO 27001 - too specific iso27001-2022: - ISO 27001:2022 mapping is missing + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/Limitation%20of%20system%20events isImplemented: false evidence: "" comments: "" tags: - none - MFA: - uuid: 598e9f13-1ac8-4a01-b85e-8fab93ee81de - risk: One factor authentication is more vulnerable to brute force attacks and - is considered less secure. - measure: Two ore more factor authentication for all accounts on all (important) - systems and applications + Role based authentication and authorization: + uuid: 070bb14b-e04a-4f3d-896a-a08eba7a35f9 + risk: Everyone is able to get unauthorized access to information on systems + or to modify information unauthorized on systems. + measure: The usage of a (role based) access control helps to restrict system + access to authorized users. And enhancement is to use *attribute based access + control*. difficultyOfImplementation: knowledge: 2 - time: 2 - resources: 2 - usefulness: 4 - level: 2 - dependsOn: - - MFA for admins + time: 3 + resources: 1 + usefulness: 3 + level: 3 implementation: - - uuid: e76a395a-8d6a-4e25-a175-6cf25409b755 - name: Smartcard - tags: [] - url: https://d3fend.mitre.org/technique/d3f:Multi-factorAuthentication/ - - uuid: d5981117-9bc2-45ed-b4a4-383135dc13d8 - name: YubiKey - tags: [] - url: https://d3fend.mitre.org/technique/d3f:Multi-factorAuthentication/ - - uuid: 6151cfb3-c894-421e-83da-cac0b2bfaec8 - name: SMS + - uuid: 04edc63e-d389-48dd-b365-552aaf4ea004 + name: Directory Service tags: [] - - uuid: f69f5d03-691f-4e14-8fbc-ad66e2e5a12d - name: TOTP + url: https://d3fend.mitre.org/dao/artifact/d3f:DirectoryService/ + - uuid: cc55cba1-ea0a-466e-99c5-337c9da2b00e + name: Plugins tags: [] - url: https://d3fend.mitre.org/technique/d3f:One-timePassword/ references: samm2: - - O-EM-1-A + - O-EM-A-2 iso27001-2017: - - 9.2.4 - - 6.1.2 - - 14.2.1 + - 9.4.1 iso27001-2022: - - 5.17 - - 5.3 - - 8.25 - d3f: - - Multi-factorAuthentication + - 8.3 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/Role%20based%20authentication%20and%20authorization isImplemented: false evidence: "" comments: "" tags: - none - MFA for admins: - uuid: 8098e416-e1ed-4ae4-a561-83efbe76bf57 - risk: One factor authentication is more vulnerable to brute force attacks and - is considered less secure. - measure: Two ore more factor authentication for all privileged accounts on systems - and applications + Usage of internal encryption at transit: + uuid: ecb0184c-6bc9-45da-bbbb-a983797ffc93 + risk: Evil actors within the organization of traffic in transit might be able + to perform a man in the middle attack and sniff confidential information (e.g. + authentication factors like passwords) + measure: By using encryption internally, e.g. inside of a cluster, it is impossible + or at least harder to sniff credentials. difficultyOfImplementation: - knowledge: 2 - time: 1 - resources: 2 + knowledge: 3 + time: 4 + resources: 3 usefulness: 4 - level: 1 - implementation: - - uuid: e76a395a-8d6a-4e25-a175-6cf25409b755 - name: Smartcard - tags: [] - url: https://d3fend.mitre.org/technique/d3f:Multi-factorAuthentication/ - - uuid: d5981117-9bc2-45ed-b4a4-383135dc13d8 - name: YubiKey - tags: [] - url: https://d3fend.mitre.org/technique/d3f:Multi-factorAuthentication/ - - uuid: 6151cfb3-c894-421e-83da-cac0b2bfaec8 - name: SMS - tags: [] - - uuid: f69f5d03-691f-4e14-8fbc-ad66e2e5a12d - name: TOTP - tags: [] - url: https://d3fend.mitre.org/technique/d3f:One-timePassword/ + level: 3 + implementation: "" references: samm2: - - O-EM-1-A + - I-SD-B-2 iso27001-2017: - - 9.2.4 - - 6.1.2 - - 14.2.1 + - 10.1 iso27001-2022: - - 5.17 - - 5.3 - - 8.25 - d3f: - - Multi-factorAuthentication + - 8.24 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/Usage%20of%20internal%20encryption%20at%20transit isImplemented: false evidence: "" comments: "" tags: - none - Microservice-architecture: - uuid: 118b869b-3850-456e-98d9-1abdb85cbc5a - risk: Monolithic applications are hard to test. - measure: A microservice-architecture helps to have small components, which are - more easy to test. + Usage of security by default for components: + uuid: 11b3848e-e931-4146-a35d-35409ada24ee + risk: Components (images, libraries, applications) are not hardened. + measure: Hardening of components is important, specially for image on which + other teams base on. Hardening should be performed on the operation system + and on the services inside (e.g. Nginx or a Java-Application). difficultyOfImplementation: knowledge: 4 - time: 5 - resources: 5 - usefulness: 1 - level: 5 - implementation: [] + time: 3 + resources: 1 + usefulness: 3 + level: 3 + implementation: + - uuid: d7fb1f5a-05e3-49f7-ae67-00bfb8f8410c + name: 'For applications: Check default encoding' + tags: [] + - uuid: 7e744f11-976e-46b6-88d4-f39b2965dfaf + name: managing secrets + tags: [] + url: https://d3fend.mitre.org/technique/d3f:CredentialHardening/ + - uuid: 520517ef-2911-4efc-8e1b-dcc9389aca45 + name: crypto + tags: [] + - uuid: ba6bd46c-2069-4f4d-b26c-7334a7553339 + name: authentication + tags: [] + url: https://d3fend.mitre.org/dao/artifact/d3f:AuthenticationServer/ + dependsOn: + - f6f7737f-25a9-4317-8de2-09bf59f29b5b # Defined build process references: samm2: - - O-EM-1-A + - O-EM-A-2 iso27001-2017: - - Not explicitly covered by ISO 27001 + - not explicitly covered by ISO 27001 - too specific iso27001-2022: - ISO 27001:2022 mapping is missing + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/Usage%20of%20security%20by%20default%20for%20components isImplemented: false evidence: "" comments: "" tags: - none - Production near environments are used by developers: - uuid: e14de741-94b3-447c-8b07-eea947d82e61 - risk: In case an errors occurs in production, the developer need to be able - to create a production near environment on a local development environment. - measure: Usage of infrastructure as code helps to create a production near environment. - The developer needs to be trained in order to setup a local development environment. - In addition, it should be possible to create production like test data. Often - personal identifiable information is anonymized in order to comply with data - protection laws. + WAF baseline: + uuid: f0e01814-3b88-4bd0-a3a9-f91db001d20b + risk: Vulnerable input, such as exploits, can infiltrate the application via + numerous entry points, posing a significant security threat. + measure: |- + Implementing a web application firewall (WAF) is a critical security control. At a baseline level, the objective is to finely balance the reduction of false positives, maintaining user experience, against a potential increase in the less noticeable false negatives. + Begin with the WAF in a monitoring state to understand the traffic and threats. Progressively enforce blocking actions based on intelligence gathered, ensuring minimal disruption to legitimate traffic. + description: | + A baseline WAF configuration provides essential defense against common vulnerabilities, acting as a first line of automated threat detection and response. + Steps: + - Configure WAF in alert mode to establish traffic patterns + - Analyze alerts and adjust sensitivity to optimize for fewer false positives + - Gradually switch to a proactive blocking stance as confidence in the accuracy of the rules increases + + It's crucial to monitor and update the WAF configuration to adapt to evolving threats and minimize the potential for both false positives and false negatives. + + There are debates on how useful a WAF is for APIs. difficultyOfImplementation: knowledge: 3 - time: 3 + time: 4 resources: 3 - usefulness: 4 - level: 4 + usefulness: 3 + level: 3 dependsOn: - - Defined deployment process - - Infrastructure as Code - implementation: [] + - e1f37abb-d848-4a3a-b3df-65e91a89dcb7 # Context-aware output encoding + implementation: + - uuid: 6150533e-58ca-4b52-a9b2-6226545d9ea0 + name: Top 5 API Security Myths That Are Crushing Your Business + tags: + - documentation + - waf + url: https://thehackernews.com/2022/11/top-5-api-security-myths-that-are.html + description: | + There are several myths and misconceptions about API security. These myths about securing APIs are crushing your business references: samm2: - - O-EM-1-A + - O-EM-A-1 iso27001-2017: - - 12.1.4 - - 17.2.1 + - Hardening is not explicitly covered by ISO 27001 - too specific + - 13.1.3 iso27001-2022: - - 8.31 - - 8.14 - isImplemented: false - evidence: "" - comments: "" + - Hardening is not explicitly covered by ISO 27001 - too specific + - 8.22 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/WAF%20baseline + comments: ~ tags: - none - Role based authentication and authorization: - uuid: 070bb14b-e04a-4f3d-896a-a08eba7a35f9 - risk: Everyone is able to get unauthorized access to information on systems - or to modify information unauthorized on systems. - measure: The usage of a (role based) access control helps to restrict system - access to authorized users. + Hardening of the Environment: + uuid: dcf9601b-b4f2-4e25-9143-e39af75f7c33 + risk: Using default configurations for a cluster environment leads to potential + risks. + measure: Harden environments according to best practices. Level 2 and partially + level 3 from hardening practices like 'CIS Kubernetes Bench for Security' + should be considered. difficultyOfImplementation: - knowledge: 2 - time: 3 - resources: 1 + knowledge: 4 + time: 4 + resources: 2 usefulness: 3 - level: 3 + level: 4 implementation: - - uuid: 04edc63e-d389-48dd-b365-552aaf4ea004 - name: Directory Service + - uuid: edaec98d-dac7-4dfd-8ab3-42c471d5b9ff + name: CIS Kubernetes Benchmark for Security tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:DirectoryService/ - - uuid: cc55cba1-ea0a-466e-99c5-337c9da2b00e - name: Plugins + url: https://www.cisecurity.org/benchmark/kubernetes + - uuid: 4dd23c4a-5a7e-4917-82cf-d00e0f04482f + name: CIS Docker Benchmark for Security tags: [] - dependsOn: - - Defined deployment process - - Defined build process + url: https://www.cisecurity.org/benchmark/docker + - uuid: f4d7c796-8574-4a88-ab00-98d245a115ef + name: For example for Cont + tags: [] + description: 'For example for Containers: Deny running containers as root, + deny using advanced privileges, deny mounting of the hole filesystem, ...' + url: https://d3fend.mitre.org/technique/d3f:ExecutionIsolation/ + - uuid: 3b7df373-2ad9-456e-9abe-439cdc9d4d8b + name: Attack Matrix Cloud + tags: + - mitre + url: https://attack.mitre.org/matrices/enterprise/cloud/ + description: Attack matrix for cloud + - uuid: 59881520-4c69-4922-a44e-99044a77de2b + name: Attack Matrix Containers + tags: + - mitre + url: https://attack.mitre.org/matrices/enterprise/containers/ + description: Attack matrix for containers + - uuid: 9fbc47ad-82bc-46d1-bba9-66815ab79935 + name: Attack Matrix Kubernetes + tags: + - mitre + url: https://www.microsoft.com/en-US/security/blog/2020/04/02/attack-matrix-kubernetes/ + description: Attack matrix for kubernetes + - uuid: b7a92886-aec9-4bf4-94c4-07cc191a97af + name: Defend the core kubernetes security at every layer + url: https://thenewstack.io/defend-the-core-kubernetes-security-at-every-layer/ + tags: + - documentation + - cluster + - kubernetes references: samm2: - - O-EM-1-A + - O-EM-A-2 iso27001-2017: - - 9.4.1 + - Hardening is not explicitly covered by ISO 27001 - too specific + - 13.1.3 iso27001-2022: - - 8.3 + - Hardening is not explicitly covered by ISO 27001 - too specific + - 8.22 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/Hardening%20of%20the%20Environment isImplemented: false evidence: "" comments: "" tags: - none - Simple access control for systems: - uuid: 82e499d1-f463-4a4b-be90-68812a874af6 - risk: Attackers a gaining access to internal systems and application interfaces - measure: All internal systems are using simple authentication + Production near environments are used by developers: + uuid: e14de741-94b3-447c-8b07-eea947d82e61 + risk: In case an errors occurs in production, the developer need to be able + to create a production near environment on a local development environment. + measure: Usage of infrastructure as code helps to create a production near environment. + The developer needs to be trained in order to setup a local development environment. + In addition, it should be possible to create production like test data. Often + personal identifiable information is anonymized in order to comply with data + protection laws. difficultyOfImplementation: knowledge: 3 time: 3 resources: 3 - usefulness: 5 - level: 1 + usefulness: 4 + level: 4 dependsOn: - - Defined deployment process - implementation: - - uuid: 41fda224-2980-443c-bfd4-0a1d4b520cb9 - name: HTTP-Basic Authentication - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:WebAuthentication/ - - uuid: e506f60b-747b-44b1-8fe8-f67ccd8f290e - name: VPN - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:VPN/ + - 67e1a9aa-9fbf-4ec5-a2de-400f01960c51 # Automated deployment process + - 8b994601-575e-4ea5-b228-accb18c8e514 # Infrastructure as Code + implementation: [] references: samm2: - - O-EM-1-A + - O-EM-A-2 iso27001-2017: - - 9.4.1 + - 12.1.4 + - 17.2.1 iso27001-2022: - - 8.3 + - 8.31 + - 8.14 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/Production%20near%20environments%20are%20used%20by%20developers isImplemented: false evidence: "" comments: "" tags: - none - Usage of a chaos monkey: + Usage of a chaos technology: uuid: f8e80f18-2503-4e3e-b3bc-7f67bb28defe risk: Due to manual changes on a system, they are not replaceable anymore. In case of a crash it might happen that a planned redundant system is unavailable. @@ -4255,365 +4262,381 @@ Implementation: resources: 5 usefulness: 3 level: 4 - implementation: [] + implementation: + - uuid: c117e79b-8223-4e55-9da5-efbf5d741c15 + name: Chaos Monkey + tags: + - chaos + - testing + url: https://github.com/Netflix/chaosmonkey + description: Chaos Monkey is a resiliency tool that helps applications tolerate + random instance failures. Chaos Monkey randomly terminates virtual machine + instances and containers that run inside of your production environment. + Exposing engineers to failures more frequently incentivizes them to build + resilient services. references: samm2: - - O-EM-1-A + - O-EM-A-3 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 17.1.3 iso27001-2022: - Not explicitly covered by ISO 27001 - too specific - 5.29 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/Usage%20of%20a%20chaos%20technology isImplemented: false evidence: "" comments: "" tags: - none - Usage of an security account: - uuid: 746025a6-dbfb-4087-a000-e46acab64ee1 - risk: Having security auditing in the same account as infrastructure and applications - at the cloud provide might cause evil administrators (or threat actors taking - over an account of an administrator) to alter evidence like audit logs. - measure: Usage of a separate account dedicated for security activities. + WAF medium: + uuid: f0e01814-3b88-4bd0-a3a9-f91db001d20b-medium + risk: The threat from malicious inputs remains high, with exploits seeking to + exploit any vulnerabilities present at the various points of entry to the + application. + measure: |- + A WAF deployed with a medium level of protection strengthens the security posture by striking a more advanced balance between the detection of genuine threats and the minimization of false alarms. + Maintain the WAF in alert mode initially to ensure a comprehensive understanding of potential threats. With a medium-level configuration, the WAF settings are refined for greater precision in threat detection, with a stronger emphasis on security without significantly impacting legitimate traffic. + description: "A medium-level WAF configuration builds upon the baseline to offer + a more nuanced and responsive defense mechanism against a wider array of threats.\n\nSample + steps:\n - Implement an enhanced set of WAF rules based on baseline data\n + \ - Continuous monitoring and fine-tuning of the WAF configuration\n - Develop + a strategic incident response plan utilizing WAF insights \n \nThe + medium configuration requires diligent management and continuous improvement + to address new vulnerabilities while maintaining the integrity of application + access.\n\nThere are debates on how useful a WAF is for APIs.\n" difficultyOfImplementation: - knowledge: 3 - time: 2 - resources: 3 - usefulness: 4 - level: 2 - implementation: "" + knowledge: 4 + time: 5 + resources: 4 + usefulness: 3 + level: 4 + dependsOn: + - f0e01814-3b88-4bd0-a3a9-f91db001d20b # WAF baseline + implementation: + - uuid: 6150533e-58ca-4b52-a9b2-6226545d9ea0 + name: Top 5 API Security Myths That Are Crushing Your Business + tags: + - documentation + - waf + url: https://thehackernews.com/2022/11/top-5-api-security-myths-that-are.html + description: | + There are several myths and misconceptions about API security. These myths about securing APIs are crushing your business references: samm2: - - I-SD-2-B + - O-EM-A-2 iso27001-2017: - - 10.1 + - Hardening is not explicitly covered by ISO 27001 - too specific + - 13.1.3 iso27001-2022: - - ISO 27001:2022 mapping is missing - isImplemented: false - evidence: "" - comments: "" + - Hardening is not explicitly covered by ISO 27001 - too specific + - 8.22 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/WAF%20medium + comments: ~ tags: - none - Usage of edge encryption at transit: - uuid: ad23be9c-5661-4f1f-81a3-5a5dc7061629 - risk: Evil actors might be able to perform a man in the middle attack and sniff - confidential information (e.g. authentication factors like passwords) - measure: By using encryption at the edge of traffic in transit, it is impossible - or at least harder to sniff credentials being outside of the organization. + WAF Advanced: + uuid: f0e01814-3b88-4bd0-a3a9-f91db001d20b-advanced + risk: The presence of sophisticated threats necessitates a robust defense strategy + where application inputs are meticulously scrutinized for security breaches, + including advanced persistent threats and zero-day vulnerabilities. + measure: |- + An advanced WAF protection level includes rigorous input validation, rejecting any parameters not explicitly required, and custom rule sets that are dynamically updated in response to emerging threats. + The advanced WAF setup is designed to ensure all data is in the correct format and any superfluous input parameters are automatically rejected. It includes machine learning algorithms to detect anomalies, custom-developed rules for real-time traffic analysis, and seamless integration with existing security infrastructures to adapt to the ever-changing threat landscape. + description: | + This advanced configuration goes beyond typical WAF implementations by enforcing strict input format checks and parameter validation to prevent any unauthorized or malformed data from compromising the application. + + Sample Steps: + - Implement strict data type and format validation rules to ensure only correctly formatted data is processed. + - Establish a denylist for all parameters that are not explicitly required, blocking them by default. + - Develop and continuously refine custom rulesets based on the application's traffic patterns, user behavior, and known vulnerabilities. + - Integrate machine learning algorithms to enhance anomaly detection and automatic rule adjustment. + - Correlate and analyze WAF logs with other security systems like SIEM for comprehensive threat intelligence. + - Conduct regular red team exercises to test and validate the effectiveness of the WAF configurations against simulated advanced attack scenarios. + - Activate automated threat response mechanisms to immediately neutralize detected threats. + + Embracing an advanced WAF setup requires a proactive approach, with continuous improvement and updating of security measures to ensure all inputs are scrutinized and validated, thus maintaining a resilient security posture against sophisticated attacks. + + There are debates on how useful a WAF is for APIs. difficultyOfImplementation: - knowledge: 2 - time: 2 - resources: 1 + knowledge: 5 + time: 5 + resources: 5 usefulness: 4 - level: 1 - implementation: "" - references: - samm2: - - I-SD-2-B - iso27001-2017: - - 10.1 + level: 5 + dependsOn: + - f0e01814-3b88-4bd0-a3a9-f91db001d20b-medium # WAF medium + implementation: + - uuid: 6150533e-58ca-4b52-a9b2-6226545d9ea0 + name: Top 5 API Security Myths That Are Crushing Your Business + tags: + - documentation + - waf + url: https://thehackernews.com/2022/11/top-5-api-security-myths-that-are.html + description: | + There are several myths and misconceptions about API security. These myths about securing APIs are crushing your business + references: + samm2: + - O-EM-A-2 + iso27001-2017: + - Hardening is not explicitly covered by ISO 27001 - too specific + - 13.1.3 iso27001-2022: - - 8.24 + - Hardening is not explicitly covered by ISO 27001 - too specific + - 8.22 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Infrastructure%20Hardening/subsection/WAF%20Advanced + comments: ~ + tags: + - none +Information Gathering: + Logging: + Centralized system logging: + uuid: 4eced38a-7904-4c45-adb0-50b663065540 + description: | + Centralized system logging involves collecting and storing system logs from multiple sources in a secure, central location. This approach improves log integrity, simplifies monitoring, and enables efficient incident response. + risk: | + Locally stored system logs can be manipulated by attackers unauthorized or might be corrupt or lost after an incident. In addition, it is hard to perform aggregation of logs. + measure: | + - Implement a centralized logging solution for all critical systems. + - System logs must be stored in a central repository, protected from unauthorized access and modification. + - Ensure that log collection is automated and covers all relevant system events. + level: 1 + difficultyOfImplementation: + knowledge: 1 + time: 1 + resources: 1 + usefulness: 2 + implementation: + - uuid: 79f88310-d63e-471d-8e63-8c77f2281b66 + name: rsyslog + url: https://www.rsyslog.com/ + tags: + - tool + - logging + - uuid: 7a8fad2e-d642-4972-8501-74591b23feab + name: logstash + url: https://www.elastic.co/docs/reference/logstash/getting-started-with-logstash + tags: + - tool + - logging + references: + samm2: + - O-IM-A-1 + iso27001-2017: + - Not explicitly covered by ISO 27001 - too specific + - 12.4.1 + iso27001-2022: + - Not explicitly covered by ISO 27001 - too specific + - 8.15 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Logging/subsection/Centralized%20system%20logging isImplemented: false evidence: "" comments: "" tags: - none - Usage of encryption at rest: - uuid: 0ff45fb8-7eef-46ed-9b3a-84c955cd7060 - risk: Evil actors might be able to access data and read information, e.g. from - physical hard disks. - measure: By using encryption at rest, it is impossible or at least harder to - to read information. + Centralized application logging: + uuid: fe875e17-ae4a-45f8-a359-244aa4fcbc04 + risk: Local stored logs can be unauthorized manipulated by attackers with system + access or might be corrupt after an incident. In addition, it is hard to perform + an correlation of logs. This leads attacks, which can be performed silently. + measure: A centralized logging system is used and applications logs (including + application exceptions) are shipped to it. difficultyOfImplementation: - knowledge: 2 - time: 2 + knowledge: 1 + time: 1 resources: 1 - usefulness: 4 + usefulness: 5 level: 2 - implementation: "" + dependsOn: + - 8a442d8e-0eb1-4793-a513-571aef982edd # Alerting + implementation: [] references: samm2: - - I-SD-2-B + - O-IM-A-1 iso27001-2017: - - 10.1 + - Not explicitly covered by ISO 27001 - too specific + - 12.4.1 iso27001-2022: - - 8.24 - isImplemented: false - evidence: "" - comments: "" + - Not explicitly covered by ISO 27001 - too specific + - 8.15 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Logging/subsection/Centralized%20application%20logging tags: - none - Usage of internal encryption at transit: - uuid: ecb0184c-6bc9-45da-bbbb-a983797ffc93 - risk: Evil actors within the organization of traffic in transit might be able - to perform a man in the middle attack and sniff confidential information (e.g. - authentication factors like passwords) - measure: By using encryption internally, e.g. inside of a cluster, it is impossible - or at least harder to sniff credentials. + Logging of security events: + uuid: ccfdd0a8-991e-4269-ad77-c0a54ca655cb + description: | + Implement logging of security relevant events. The following events tend to be security relevant: + - successful/failed login/logout + - creation, change, and deletion of users + - errors during input validation and output creation + - exceptions and errors with security in their name + - transactions of value (e.g., financial transactions, costly operations) + - :unicorn: (special things of your application) + measure: Security-relevant events like login/logout or creation, change, deletion + of users should be logged. + assessment: | + - Show which events are logged. + - Show a test for one event logging. difficultyOfImplementation: - knowledge: 3 - time: 4 - resources: 3 + knowledge: 1 + time: 1 + resources: 1 usefulness: 4 - level: 3 - implementation: "" + level: 2 + credits: | + [AppSecure-nrw](https://github.com/AppSecure-nrw/security-belts/blob/master/orange/logging-of-security-events.md) + implementation: + - uuid: 7a8fad2e-d642-4972-8501-74591b23feab + name: logstash + url: https://www.elastic.co/docs/reference/logstash/getting-started-with-logstash + tags: + - tool + - logging + - uuid: f5da3a20-ab64-4ecf-b4e1-660c80036e45 + name: fluentd + tags: + - tool + url: https://www.fluentd.org/ + - uuid: 6226f8bc-2f6e-45c2-9232-98d2027e4531 + name: bash + tags: + - tool + url: https://www.gnu.org/software/bash/ + - uuid: 5a5c7d99-41e8-454a-86ae-a638c9787d8c + name: OWASP Logging CheatSheet + url: https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html + tags: + - logging + - documentation references: samm2: - - I-SD-2-B + - O-IM-A-1 iso27001-2017: - - 10.1 + - 12.4.1 iso27001-2022: - - 8.24 + - 8.15 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Logging/subsection/Logging%20of%20security%20events + risk: |- + * No track of security-relevant events makes it harder to analyze an incident. + * Security incident analysis takes significantly less time with proper security events, such that an attack can be stopped before the attacker reaches his goal. isImplemented: false evidence: "" comments: "" tags: - none - Usage of security by default for components: - uuid: 11b3848e-e931-4146-a35d-35409ada24ee - risk: Components (images, libraries, applications) are not hardened. - measure: Hardening of components is important, specially for image on which - other teams base on. Hardening should be performed on the operation system - and on the services inside (e.g. Nginx or a Java-Application). + Analyze logs: + uuid: b217c8bb-5d61-4b41-a675-1083993f83b1 + risk: Not aware of attacks happening. + measure: Check logs for keywords. difficultyOfImplementation: - knowledge: 4 - time: 3 - resources: 1 + knowledge: 2 + time: 2 + resources: 2 usefulness: 3 level: 3 implementation: - - uuid: d7fb1f5a-05e3-49f7-ae67-00bfb8f8410c - name: 'For applications: Check default encoding' - tags: [] - - uuid: 7e744f11-976e-46b6-88d4-f39b2965dfaf - name: managing secrets - tags: [] - url: https://d3fend.mitre.org/technique/d3f:CredentialHardening/ - - uuid: 520517ef-2911-4efc-8e1b-dcc9389aca45 - name: crypto - tags: [] - - uuid: ba6bd46c-2069-4f4d-b26c-7334a7553339 - name: authentication + - uuid: 1adf1ac0-8572-407b-a358-3976d9a225e2 + name: SigmaHQ tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:Authentication/ - dependsOn: - - Defined build process + url: https://github.com/SigmaHQ/sigma references: samm2: - - O-EM-1-A + - O-IM-A-1 iso27001-2017: - - not explicitly covered by ISO 27001 - too specific + - ISO 27001:2017 mapping is missing iso27001-2022: - ISO 27001:2022 mapping is missing - isImplemented: false - evidence: "" - comments: "" + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Logging/subsection/Analyze%20logs tags: - none - Usage of test and production environments: - uuid: bfdacb52-1e3f-431d-ae72-d844a5e86415 - risk: Security tests are not running regularly because test environments are - missing - measure: A test and a production like environment is used + Visualized logging: + uuid: 7c735089-6a83-419f-8b27-c1e676cedea1 + risk: System and application protocols are not visualized properly which leads + to no or very limited logging assessment. Specially developers might have + difficulty to read applications logs with unusually tools like the Linux tool + 'cat' + measure: Protocols are visualized in a simple to use real time monitoring system. + The GUI gives the ability to search for special attributes in the protocol. difficultyOfImplementation: - knowledge: 3 + knowledge: 1 time: 3 - resources: 5 + resources: 3 usefulness: 4 - level: 2 + level: 3 dependsOn: - - Defined deployment process - implementation: [] + - 4eced38a-7904-4c45-adb0-50b663065540 # Centralized system logging + - fe875e17-ae4a-45f8-a359-244aa4fcbc04 # Centralized application logging + implementation: + - uuid: 38fe9d00-df8b-44b6-910d-ca0f02b5c5d3 + name: ELK-Stack + tags: [] + url: https://www.elastic.co/elastic-stack/ references: samm2: - - O-EM-1-A + - O-IM-A-1 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - - 12.1.4 - - 17.2.1 + - 12.4.1 iso27001-2022: - Not explicitly covered by ISO 27001 - too specific - - 8.31 - - 8.14 + - 8.15 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Logging/subsection/Visualized%20logging isImplemented: false evidence: "" comments: "" tags: - none - Virtual environments are limited: - uuid: 760f1056-b0ee-4f22-a35b-f65446f944ca - risk: Denial of service (internally by an attacker or unintentionally by a bug) - on one service effects other services - measure: All virtual environments are using resource limits on hard disks, memory - and CPU + Correlation of security events: + uuid: ccf4561d-253f-4762-adcb-bc4622fd6fc5 + risk: Detection of security related events with hints on different systems/tools/metrics + is not possible. + measure: Events are correlated on one system. For example the correlation and + visualization of failed login attempts combined with successful login attempts. difficultyOfImplementation: - knowledge: 2 - time: 2 - resources: 3 + knowledge: 4 + time: 4 + resources: 4 usefulness: 3 - level: 2 + level: 5 dependsOn: - - Applications are running in virtualized environments + - 7c735089-6a83-419f-8b27-c1e676cedea1 # Visualized logging + - 8a442d8e-0eb1-4793-a513-571aef982edd # Alerting implementation: [] references: samm2: - - O-EM-1-A + - O-IM-A-2 iso27001-2017: - - Virtual environments are not explicitly covered by ISO 27001 - too specific - - 12.1.3 - - 13.1.3 - - 17.2.1 + - Not explicitly covered by ISO 27001 - too specific + - 12.4.1 iso27001-2022: - - Virtual environments are not explicitly covered by ISO 27001 - too specific - - 8.6 - - 8.22 - - 8.14 + - Not explicitly covered by ISO 27001 - too specific + - 8.15 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Logging/subsection/Correlation%20of%20security%20events isImplemented: false evidence: "" comments: "" tags: - none - WAF Advanced: - uuid: f0e01814-3b88-4bd0-a3a9-f91db001d20b-advanced - risk: The presence of sophisticated threats necessitates a robust defense strategy - where application inputs are meticulously scrutinized for security breaches, - including advanced persistent threats and zero-day vulnerabilities. - measure: An advanced WAF protection level includes rigorous input validation, - rejecting any parameters not explicitly required, and custom rule sets that - are dynamically updated in response to emerging threats. - description: | - The advanced WAF setup is designed to ensure all data is in the correct format and any superfluous input parameters are automatically rejected. It includes machine learning algorithms to detect anomalies, custom-developed rules for real-time traffic analysis, and seamless integration with existing security infrastructures to adapt to the ever-changing threat landscape. - difficultyOfImplementation: - knowledge: 5 - time: 5 - resources: 5 - usefulness: 4 - level: 5 - dependsOn: - - WAF medium - implementation: [] - references: - samm2: - - D-SR-3-A - iso27001-2017: - - Hardening is not explicitly covered by ISO 27001 - too specific - - 13.1.3 - iso27001-2022: - - Hardening is not explicitly covered by ISO 27001 - too specific - - 8.22 - comments: ~ - tags: - - none - WAF baseline: - uuid: f0e01814-3b88-4bd0-a3a9-f91db001d20b - risk: Vulnerable input, such as exploits, can infiltrate the application via - numerous entry points, posing a significant security threat. - measure: Implementing a web application firewall (WAF) is a critical security - control. At a baseline level, the objective is to finely balance the reduction - of false positives, maintaining user experience, against a potential increase - in the less noticeable false negatives. - description: | - Begin with the WAF in a monitoring state to understand the traffic and threats. Progressively enforce blocking actions based on intelligence gathered, ensuring minimal disruption to legitimate traffic. - difficultyOfImplementation: - knowledge: 3 - time: 4 - resources: 3 - usefulness: 3 - level: 3 - dependsOn: - - Contextualized encoding - implementation: [] - references: - samm2: - - D-SR-3-A - iso27001-2017: - - Hardening is not explicitly covered by ISO 27001 - too specific - - 13.1.3 - iso27001-2022: - - Hardening is not explicitly covered by ISO 27001 - too specific - - 8.22 - comments: ~ - tags: - - none - WAF medium: - uuid: f0e01814-3b88-4bd0-a3a9-f91db001d20b - risk: The threat from malicious inputs remains high, with exploits seeking to - exploit any vulnerabilities present at the various points of entry to the - application. - measure: A WAF deployed with a medium level of protection strengthens the security - posture by striking a more advanced balance between the detection of genuine - threats and the minimization of false alarms. - description: | - Maintain the WAF in alert mode initially to ensure a comprehensive understanding of potential threats. With a medium-level configuration, the WAF settings are refined for greater precision in threat detection, with a stronger emphasis on security without significantly impacting legitimate traffic. - difficultyOfImplementation: - knowledge: 4 - time: 5 - resources: 4 - usefulness: 3 - level: 4 - dependsOn: - - WAF baseline - implementation: [] - references: - samm2: - - D-SR-3-A - iso27001-2017: - - Hardening is not explicitly covered by ISO 27001 - too specific - - 13.1.3 - iso27001-2022: - - Hardening is not explicitly covered by ISO 27001 - too specific - - 8.22 - comments: ~ - tags: - - none -Information Gathering: - Logging: - Centralized application logging: - uuid: fe875e17-ae4a-45f8-a359-244aa4fcbc04 - risk: Local stored logs can be unauthorized manipulated by attackers with system - access or might be corrupt after an incident. In addition, it is hard to perform - an correlation of logs. This leads attacks, which can be performed silently. - measure: A centralized logging system is used and applications logs (including - application exceptions) are shipped to it. - difficultyOfImplementation: - knowledge: 1 - time: 1 - resources: 1 - usefulness: 5 - level: 3 - dependsOn: - - Visualized logging - - Alerting - implementation: [] - references: - samm2: - - O-IM-1-A - iso27001-2017: - - Not explicitly covered by ISO 27001 - too specific - - 12.4.1 - iso27001-2022: - - Not explicitly covered by ISO 27001 - too specific - - 8.15 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Centralized system logging: - uuid: 4eced38a-7904-4c45-adb0-50b663065540 - risk: Local stored system logs can be unauthorized manipulated by attackers - or might be corrupt after an incident. In addition, it is hard to perform - a aggregation of logs. - measure: By using centralized logging logs are protected against unauthorized - modification. + PII logging concept: + uuid: 613a73dc-4f60-49db-a6ce-4fb7bf8519f9 + risk: Personal identifiable information (PII) is logged and the privacy law + (e.g. General Data Protection Regulation) is not followed. + measure: A concept how to log PII is documented and applied. difficultyOfImplementation: knowledge: 1 time: 1 resources: 1 - usefulness: 2 - level: 1 + usefulness: 1 + level: 5 implementation: - uuid: 79f88310-d63e-471d-8e63-8c77f2281b66 name: rsyslog @@ -4623,281 +4646,268 @@ Information Gathering: - logging - uuid: 7a8fad2e-d642-4972-8501-74591b23feab name: logstash - url: https://www.elastic.co/guide/en/logstash/current/getting-started-with-logstash.html + url: https://www.elastic.co/docs/reference/logstash/getting-started-with-logstash tags: - tool - logging + - uuid: f5da3a20-ab64-4ecf-b4e1-660c80036e45 + name: fluentd + tags: + - tool + url: https://www.fluentd.org/ + - uuid: 6226f8bc-2f6e-45c2-9232-98d2027e4531 + name: bash + tags: + - tool + url: https://www.gnu.org/software/bash/ references: samm2: - - O-IM-1-A + - O-OM-A-1 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 12.4.1 + - 18.1.1 iso27001-2022: - Not explicitly covered by ISO 27001 - too specific - 8.15 + - 5.31 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Logging/subsection/PII%20logging%20concept isImplemented: false evidence: "" comments: "" tags: - none - Correlation of security events: - uuid: ccf4561d-253f-4762-adcb-bc4622fd6fc5 - risk: Detection of security related events with hints on different systems/tools/metrics - is not possible. - measure: Events are correlated on one system. For example the correlation and - visualization of failed login attempts combined with successful login attempts. + Monitoring: + Simple application metrics: + uuid: e9a6d403-a467-445e-b98a-74f0c29da0b1 + description: | + Collecting basic operational data from applications, such as authentication attempts, transaction volumes, and resource usage, will help detect abnormal patterns that may indicate security incidents or system issues. + risk: | + Without monitoring application metrics, attacks or abnormal behaviors may go undetected, increasing the risk of successful exploitation, data breaches, and delayed incident response. + measure: | + Gathering of application metrics helps to identify incidents like brute force attacks, login/logout patterns, and unusual spikes in activity. Key metrics to monitor include: + - Authentication attempts (successful/failed logins) + - Transaction volumes and patterns (e.g. orders, payments) + - API call rates and response times + - User session metrics + - Resource utilization + + Example: An e-commerce application normally processes 100 orders per hour. A sudden spike to 1000 orders per hour could indicate either: + - A legitimate event (unannounced marketing campaign, viral social media post) + - A security incident (automated bulk purchase bots, credential stuffing attack) + + By monitoring these basic metrics, teams can quickly investigate abnormal patterns and determine if they represent security incidents requiring response. + assessment: | + - Basic application metrics are collected and reviewed. + level: 1 difficultyOfImplementation: - knowledge: 4 - time: 4 - resources: 4 - usefulness: 3 - level: 5 - dependsOn: - - Visualized logging - - Alerting - implementation: [] + knowledge: 2 + time: 2 + resources: 2 + usefulness: 5 + implementation: + - uuid: ddf221df-3517-42e4-b23d-c1d9a162744c + name: Prometheus + tags: [] + url: https://prometheus.io/ references: samm2: - - O-IM-2-A + - O-IM-A-1 iso27001-2017: - - Not explicitly covered by ISO 27001 - too specific - 12.4.1 iso27001-2022: - - Not explicitly covered by ISO 27001 - too specific - 8.15 - isImplemented: false - evidence: "" + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Monitoring/subsection/Simple%20application%20metrics comments: "" tags: - none - Logging of security events: - uuid: ccfdd0a8-991e-4269-ad77-c0a54ca655cb + Simple budget metrics: + uuid: f08a3219-6941-43ec-8762-4aff739f4664 description: | - Implement logging of security relevant events. The following events tend to be security relevant: - - successful/failed login/logout - - creation, change, and deletion of users - - errors during input validation and output creation - - exceptions and errors with security in their name - - transactions of value (e.g., financial transactions, costly operations) - - :unicorn: (special things of your application) - measure: Security-relevant events like login/logout or creation, change, deletion - of users should be logged. + Monitoring resource usage and costs to prevent unexpected expenses. This is especially important in cloud environments where resource consumption can quickly exceed planned budgets. + risk: | + Failure to monitor budget metrics can result in unexpected costs, financial loss, and potential service disruption due to resource exhaustion or denial-of-service attacks. + measure: | + Set up budget monitoring and alerting for all critical resources. Use provider tools to track spending and configure alerts when thresholds are reached. Implement hard limits where possible to prevent budget overruns. assessment: | - - Show which events are logged. - - Show a test for one event logging. + - The organization regularly monitors budget metrics + - Alerting outside given thresholds are implemented + level: 1 difficultyOfImplementation: knowledge: 1 time: 1 resources: 1 - usefulness: 4 - level: 2 - credits: | - [AppSecure-nrw](https://github.com/AppSecure-nrw/security-belts/blob/master/orange/logging-of-security-events.md) + usefulness: 5 implementation: - - uuid: 7a8fad2e-d642-4972-8501-74591b23feab - name: logstash - url: https://www.elastic.co/guide/en/logstash/current/getting-started-with-logstash.html - tags: - - tool - - logging - - uuid: f5da3a20-ab64-4ecf-b4e1-660c80036e45 - name: fluentd - tags: - - tool - url: https://www.fluentd.org/ - - uuid: 6226f8bc-2f6e-45c2-9232-98d2027e4531 - name: bash - tags: - - tool - url: https://www.gnu.org/software/bash/ - - uuid: 5a5c7d99-41e8-454a-86ae-a638c9787d8c - name: OWASP Logging CheatSheet - url: https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html - tags: - - logging - - documentation + - uuid: 73f6a52c-4fc2-45dc-991b-d5911b6c1ef8 + name: collected + tags: [] references: samm2: - - O-IM-1-A + - O-IM-A-1 iso27001-2017: - - 12.4.1 + - 12.1.3 iso27001-2022: - - 8.15 - risk: |- - * No track of security-relevant events makes it harder to analyze an incident. - * Security incident analysis takes significantly less time with proper security events, such that an attack can be stopped before the attacker reaches his goal. + - 8.6 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Monitoring/subsection/Simple%20budget%20metrics isImplemented: false evidence: "" comments: "" tags: - none - PII logging concept: - uuid: 613a73dc-4f60-49db-a6ce-4fb7bf8519f9 - risk: Personal identifiable information (PII) is logged and the privacy law - (e.g. General Data Protection Regulation) is not followed. - measure: A concept how to log PII is documented and applied. + Simple system metrics: + uuid: 3d1f4c3b-f713-46d9-933a-54a014a26c03 + description: | + Monitoring basic system performance data, such as CPU, memory, and disk usage, will help identify performance bottlenecks and potential security incidents. + risk: | + Without monitoring system metrics, it is difficult to detect incidents or performance issues, leading to delayed response, reduced availability, and increased risk of undetected attacks. + measure: | + Collect and monitor key system metrics, including CPU, memory, and disk usage. + assessment: | + - Basic system metrics are monitored and reviewed regularly + level: 1 difficultyOfImplementation: - knowledge: 1 - time: 1 - resources: 1 - usefulness: 1 - level: 5 + knowledge: 2 + time: 2 + resources: 2 + usefulness: 5 implementation: - - uuid: 79f88310-d63e-471d-8e63-8c77f2281b66 - name: rsyslog - url: https://www.rsyslog.com/ - tags: - - tool - - logging - - uuid: 7a8fad2e-d642-4972-8501-74591b23feab - name: logstash - url: https://www.elastic.co/guide/en/logstash/current/getting-started-with-logstash.html - tags: - - tool - - logging - - uuid: f5da3a20-ab64-4ecf-b4e1-660c80036e45 - name: fluentd - tags: - - tool - url: https://www.fluentd.org/ - - uuid: 6226f8bc-2f6e-45c2-9232-98d2027e4531 - name: bash - tags: - - tool - url: https://www.gnu.org/software/bash/ + - uuid: 73f6a52c-4fc2-45dc-991b-d5911b6c1ef8 + name: collected + tags: [] references: samm2: - - O-IM-1-A + - O-IM-A-1 iso27001-2017: - - Not explicitly covered by ISO 27001 - too specific - - 12.4.1 - - 18.1.1 + - 12.1.3 iso27001-2022: - - Not explicitly covered by ISO 27001 - too specific - - 8.15 - - 5.31 + - 8.6 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Monitoring/subsection/Simple%20system%20metrics isImplemented: false evidence: "" comments: "" tags: - none - Visualized logging: - uuid: 7c735089-6a83-419f-8b27-c1e676cedea1 - risk: System and application protocols are not visualized properly which leads - to no or very limited logging assessment. Specially developers might have - difficulty to read applications logs with unusually tools like the Linux tool - 'cat' - measure: Protocols are visualized in a simple to use real time monitoring system. - The GUI gives the ability to search for special attributes in the protocol. + Alerting: + uuid: 8a442d8e-0eb1-4793-a513-571aef982edd + risk: Incidents are discovered after they happened. + measure: | + Thresholds for metrics are set. In case the thresholds are reached, alarms are send out. Which should get attention due to the critically. difficultyOfImplementation: - knowledge: 1 - time: 3 - resources: 3 - usefulness: 4 + knowledge: 2 + time: 5 + resources: 5 + usefulness: 5 level: 2 dependsOn: - - Centralized system logging - - Centralized application logging - implementation: - - uuid: 38fe9d00-df8b-44b6-910d-ca0f02b5c5d3 - name: ELK-Stack - tags: [] - url: https://www.elastic.co/elk-stack + - ded39bcf-4eaa-4c5f-9c94-09acde0a4734 # Visualized metrics + implementation: [] references: samm2: - - O-IM-1-A + - O-IM-A-2 + - I-DM-A-3 iso27001-2017: - - Not explicitly covered by ISO 27001 - too specific - - 12.4.1 + - 16.1.2 + - 16.1.4 + - 12.1.4 iso27001-2022: - - Not explicitly covered by ISO 27001 - too specific - - 8.15 + - 6.8 + - 5.25 + - 8.31 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Monitoring/subsection/Alerting isImplemented: false evidence: "" comments: "" tags: - none - Monitoring: - Advanced app. metrics: - uuid: d03bc410-74a7-4e92-82cb-d01a020cb6bf - risk: People are not looking into tests results. Vulnerabilities not recolonized, - even they are detected by tools. - measure: All defects from the dimension Test- and Verification are instrumented. + Monitoring of costs: + uuid: 10e23a8c-22ff-4487-a706-87ccc9d0798e + risk: Not monitoring costs might lead to unexpected high resource consumption + and a high invoice. + measure: Implement cost budgets. Setting of an alert threshold and sending out + errors when it is reached. In the best case, a second threshold with a limit + is set so that the cost can not go higher. difficultyOfImplementation: - knowledge: 3 - time: 3 + knowledge: 1 + time: 2 resources: 2 - usefulness: 4 - level: 4 + usefulness: 3 + level: 2 dependsOn: - - Simple application metrics - - Visualized metrics + - e9a6d403-a467-445e-b98a-74f0c29da0b1 # Simple application metrics + - 3d1f4c3b-f713-46d9-933a-54a014a26c03 # Simple system metrics implementation: [] references: samm2: - - O-IM-2-A + - O-IM-A-2 iso27001-2017: - - 12.6.1 + - 12.1.3 iso27001-2022: - - 8.8 + - 8.6 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Monitoring/subsection/Monitoring%20of%20costs isImplemented: false evidence: "" comments: "" tags: - none - Advanced availability and stability metrics: - uuid: ed715b38-c34b-40cd-83fd-ce807f306fc1 - risk: Trends and advanced attacks are not detected. - measure: Advanced metrics are gathered in relation to availability and stability. - For example unplanned downtime's per year. + Visualized metrics: + uuid: ded39bcf-4eaa-4c5f-9c94-09acde0a4734 + risk: Not visualized metrics lead to restricted usage of metrics. + measure: Metrics are visualized in real time in a user friendly way. difficultyOfImplementation: - knowledge: 3 - time: 3 + knowledge: 1 + time: 2 resources: 2 - usefulness: 4 - level: 3 + usefulness: 3 + level: 2 dependsOn: - - Simple application metrics - - Visualized metrics + - e9a6d403-a467-445e-b98a-74f0c29da0b1 # Simple application metrics + - 3d1f4c3b-f713-46d9-933a-54a014a26c03 # Simple system metrics implementation: [] references: samm2: - - O-IM-2-A + - O-IM-A-2 iso27001-2017: - 12.1.3 iso27001-2022: - 8.6 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Monitoring/subsection/Visualized%20metrics isImplemented: false evidence: "" comments: "" tags: - none - Alerting: - uuid: 8a442d8e-0eb1-4793-a513-571aef982edd - risk: Incidents are discovered after they happened. - measure: | - Thresholds for metrics are set. In case the thresholds are reached, alarms are send out. Which should get attention due to the critically. + Advanced availability and stability metrics: + uuid: ed715b38-c34b-40cd-83fd-ce807f306fc1 + risk: Trends and advanced attacks are not detected. + measure: Advanced metrics are gathered in relation to availability and stability. + For example unplanned downtime's per year. difficultyOfImplementation: - knowledge: 2 - time: 5 - resources: 5 - usefulness: 5 - level: 2 + knowledge: 3 + time: 3 + resources: 2 + usefulness: 4 + level: 3 dependsOn: - - Visualized metrics + - e9a6d403-a467-445e-b98a-74f0c29da0b1 # Simple application metrics + - ded39bcf-4eaa-4c5f-9c94-09acde0a4734 # Visualized metrics implementation: [] references: samm2: - - I-DM-A 3 + - O-IM-A-2 iso27001-2017: - - 16.1.2 - - 16.1.4 - - 12.1.4 + - 12.1.3 iso27001-2022: - - 6.8 - - 5.25 - - 8.31 + - 8.6 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Monitoring/subsection/Advanced%20availability%20and%20stability%20metrics isImplemented: false evidence: "" comments: "" @@ -4914,7 +4924,7 @@ Information Gathering: usefulness: 4 level: 3 dependsOn: - - Visualized metrics + - ded39bcf-4eaa-4c5f-9c94-09acde0a4734 # Visualized metrics implementation: - uuid: 32b64e6e-5187-45e3-b4f3-f5f9a9739012 name: Falco @@ -4927,56 +4937,80 @@ Information Gathering: Falco makes it easy to consume kernel events, and enrich those events with information from Kubernetes and the rest of the cloud native stack. references: samm2: - - O-IM-2-A + - O-IM-A-2 iso27001-2017: - 12.6.1 iso27001-2022: - 8.8 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Monitoring/subsection/Audit%20of%20system%20events isImplemented: false evidence: "" comments: "" tags: - none - Coverage and control metrics: - uuid: d0d681e7-d6de-4829-ac64-a9eb2546aa0d - risk: The effectiveness of configuration, patch and vulnerability management - is unknown. - measure: "Usage of Coverage- and control-metrics to show the effectiveness of - the security program. Coverage is the degree in \n which a specific - security control for a specific target group is applied with all resources.\n - \ The control degree shows the actual application of security standards - and security-guidelines. Examples are gathering information on anti-virus, - anti-rootkits, patch management, server configuration and vulnerability management." + Deactivation of unused metrics: + uuid: 7f36b9ba-bc05-4fd6-9a2a-73344c249722 + risk: High resources are used while gathering unused metrics. + measure: Deactivation of unused metrics helps to free resources. difficultyOfImplementation: - knowledge: 3 + knowledge: 2 time: 5 - resources: 2 - usefulness: 4 - level: 4 + resources: 5 + usefulness: 5 + level: 3 dependsOn: - - Visualized metrics - implementation: - - uuid: 84ef86ea-ada4-4e10-ae4f-a5bb77dcae5d - name: https://ht.transpare - tags: [] - url: https://ht.transparencytoolkit.org/FileServer/FileServer/OLD - description: https://ht.transparencytoolkit.org/FileServer/FileServer/OLD%20Fileserver/books/SICUREZZA/Addison.Wesley.Security.Metrics.Mar.2007.pdf + - ded39bcf-4eaa-4c5f-9c94-09acde0a4734 # Visualized metrics + implementation: [] references: samm2: - - O-IM-2-A + - O-IM-A-1 iso27001-2017: - - not explicitly covered by ISO 27001 - too specific + - Not explicitly covered by ISO 27001 - too specific + - 12.1.3 iso27001-2022: - - ISO 27001:2022 mapping is missing + - Not explicitly covered by ISO 27001 - too specific + - 8.6 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Monitoring/subsection/Deactivation%20of%20unused%20metrics isImplemented: false evidence: "" comments: "" tags: - none - Deactivation of unused metrics: - uuid: 7f36b9ba-bc05-4fd6-9a2a-73344c249722 - risk: High resources are used while gathering unused metrics. - measure: Deactivation of unused metrics helps to free resources. + Grouping of metrics: + uuid: 42170a71-d4c8-47af-bd71-bf36875fd05b + risk: The analysis of metrics takes long. + measure: Meaningful grouping of metrics helps to speed up analysis. + difficultyOfImplementation: + knowledge: 2 + time: 4 + resources: 2 + usefulness: 2 + level: 3 + implementation: [] + references: + samm2: + - O-IM-A-2 + iso27001-2017: + - Not explicitly covered by ISO 27001 - too specific + - 12.1.3 + iso27001-2022: + - Not explicitly covered by ISO 27001 - too specific + - 8.6 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Monitoring/subsection/Grouping%20of%20metrics + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Targeted alerting: + uuid: d6f06ae8-401a-4f44-85df-1079247fa030 + risk: People are bored (ignorant) of incident alarm messages, as they are not + responsible to react. + measure: By the definition of target groups for incidents people are only getting + alarms for incidents they are in charge for. difficultyOfImplementation: knowledge: 2 time: 5 @@ -4984,17 +5018,82 @@ Information Gathering: usefulness: 5 level: 3 dependsOn: - - Visualized metrics + - 8a442d8e-0eb1-4793-a513-571aef982edd # Alerting implementation: [] references: samm2: - - O-IM-1-A + - O-IM-A-2 + - I-DM-A-3 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - - 12.1.3 + - 16.1.5 iso27001-2022: - Not explicitly covered by ISO 27001 - too specific - - 8.6 + - 5.26 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Monitoring/subsection/Targeted%20alerting + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Advanced app. metrics: + uuid: d03bc410-74a7-4e92-82cb-d01a020cb6bf + risk: People are not looking into tests results. Vulnerabilities not recolonized, + even they are detected by tools. + measure: All defects from the dimension Test- and Verification are instrumented. + difficultyOfImplementation: + knowledge: 3 + time: 3 + resources: 2 + usefulness: 4 + level: 4 + dependsOn: + - e9a6d403-a467-445e-b98a-74f0c29da0b1 # Simple application metrics + - ded39bcf-4eaa-4c5f-9c94-09acde0a4734 # Visualized metrics + implementation: [] + references: + samm2: + - O-IM-A-2 + iso27001-2017: + - 12.6.1 + iso27001-2022: + - 8.8 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Monitoring/subsection/Advanced%20app.%20metrics + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Coverage and control metrics: + uuid: d0d681e7-d6de-4829-ac64-a9eb2546aa0d + risk: The effectiveness of configuration, patch and vulnerability management + is unknown. + measure: "Usage of Coverage- and control-metrics to show the effectiveness of + the security program. Coverage is the degree in \n which a specific + security control for a specific target group is applied with all resources.\n + \ The control degree shows the actual application of security standards + and security-guidelines. Examples are gathering information on anti-virus, + anti-rootkits, patch management, server configuration and vulnerability management." + difficultyOfImplementation: + knowledge: 3 + time: 5 + resources: 2 + usefulness: 4 + level: 4 + dependsOn: + - ded39bcf-4eaa-4c5f-9c94-09acde0a4734 # Visualized metrics + implementation: [] + references: + samm2: + - O-IM-A-2 + iso27001-2017: + - not explicitly covered by ISO 27001 - too specific + iso27001-2022: + - ISO 27001:2022 mapping is missing + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Monitoring/subsection/Coverage%20and%20control%20metrics isImplemented: false evidence: "" comments: "" @@ -5014,45 +5113,50 @@ Information Gathering: usefulness: 4 level: 4 dependsOn: - - Visualized metrics - - Filter outgoing traffic + - ded39bcf-4eaa-4c5f-9c94-09acde0a4734 # Visualized metrics + - 6df508ef-86fc-4c22-bd9f-646c3127ce7d # Filter outgoing traffic implementation: [] references: samm2: - - O-IM-2-A + - O-IM-A-2 iso27001-2017: - 12.4.1 - 13.1.1 iso27001-2022: - 8.15 - 8.2 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Monitoring/subsection/Defense%20metrics isImplemented: false evidence: "" comments: "" tags: - none - Grouping of metrics: - uuid: 42170a71-d4c8-47af-bd71-bf36875fd05b - risk: The analysis of metrics takes long. - measure: Meaningful grouping of metrics helps to speed up analysis. + Screens with metric visualization: + uuid: 8746647c-638c-473f-8e17-82c068e4c311 + risk: Security related information is discovered too late during an incident. + measure: By having an internal accessible screen with a security related dashboards + helps to visualize incidents. difficultyOfImplementation: knowledge: 2 - time: 4 - resources: 2 - usefulness: 2 - level: 3 + time: 1 + resources: 1 + usefulness: 5 + level: 4 + dependsOn: + - 42170a71-d4c8-47af-bd71-bf36875fd05b # Grouping of metrics implementation: [] references: samm2: - - O-IM-2-A + - O-IM-A-2 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - - 12.1.3 + - 16.1.5 iso27001-2022: - Not explicitly covered by ISO 27001 - too specific - - 8.6 - isImplemented: false - evidence: "" + - 5.26 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Monitoring/subsection/Screens%20with%20metric%20visualization comments: "" tags: - none @@ -5067,246 +5171,398 @@ Information Gathering: usefulness: 5 level: 5 dependsOn: - - Grouping of metrics + - 42170a71-d4c8-47af-bd71-bf36875fd05b # Grouping of metrics implementation: [] references: samm2: - - O-IM-2-A + - O-IM-A-2 iso27001-2017: - not explicitly covered by ISO 27001 iso27001-2022: - ISO 27001:2022 mapping is missing + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Monitoring/subsection/Metrics%20are%20combined%20with%20tests isImplemented: false evidence: "" comments: "" tags: - none - Monitoring of costs: - uuid: 10e23a8c-22ff-4487-a706-87ccc9d0798e - risk: Not monitoring costs might lead to unexpected high resource consumption - and a high invoice. - measure: Implement cost budgets. Setting of an alert threshold and sending out - errors when it is reached. In the best case, a second threshold with a limit - is set so that the cost can not go higher. + Test KPI: + Number of vulnerabilities/severity: + uuid: bc548cba-cb82-4f76-bd4b-325d9d256279 + risk: Failing to convey the number of vulnerabilities by severity might undermine + the effectiveness of product teams. This might lead to ignorance of findings. + measure: Measurement and communication of vulnerabilities per severity for components + like applications. At least quarterly. + description: |- + Communication can be performed in a simple way, e.g. text based during the build process. + This activity depends on at least one security testing implementation. difficultyOfImplementation: - knowledge: 1 + knowledge: 2 time: 2 resources: 2 usefulness: 3 level: 2 - dependsOn: - - Simple application metrics - - Simple system metrics + dependsOn: [] implementation: [] references: samm2: - - O-IM-2-A - iso27001-2017: - - 12.1.3 + - I-DM-B-2 iso27001-2022: - - 8.6 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Screens with metric visualization: - uuid: 8746647c-638c-473f-8e17-82c068e4c311 - risk: Security related information is discovered too late during an incident. - measure: By having an internal accessible screen with a security related dashboards - helps to visualize incidents. + - 5.25 + - 5.12 + - 5.13 + - 5.1 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Test%20KPI/subsection/Number%20of%20vulnerabilities%2Fseverity + tags: + - vulnerability-mgmt + - metrics + - vmm-measurement + Number of vulnerabilities/severity/layer: + uuid: 0ec92899-a5cb-4649-984b-2fb1d6c784ad + risk: Failing to convey the number of vulnerabilities by severity and layer + (app/infra) might undermine the effectiveness of product teams. This might + lead to ignorance of findings. + measure: Measurement and communication of vulnerabilities per severity for components + like applications and split it depending on the layer (e.g. app/infra). At + least quarterly. + description: |- + Communication can be performed in a simple way, e.g. text based during the build process. + This activity depends on at least one security testing implementation. + Layers to consider (SCA): + - Cloud provider (if insights are possible) + - Runtimes, e.g. Kubernetes nodes + - Base images and container images + - Application + + Layers to consider SAST/DAST: + - Cloud provider + - Runtime, e.g. Kubernetes + - Base images and container images + - Application difficultyOfImplementation: knowledge: 2 + time: 2 + resources: 2 + usefulness: 3 + level: 2 + dependsOn: [] + implementation: [] + references: + samm2: + - I-DM-B-2 + iso27001-2022: + - 5.25 + - 5.12 + - 5.13 + - 5.1 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Test%20KPI/subsection/Number%20of%20vulnerabilities%2Fseverity%2Flayer + tags: + - vulnerability-mgmt + - metrics + - vmm-measurement + Patching mean time to resolution via PR: + uuid: 86d490b9-d798-4a5b-a011-ab9688014c46 + risk: Without measuring Mean Time to Resolution (MTTR) related to patching, + it is challenging to identify delays in the patching process. Unaddressed + vulnerabilities can be exploited by attackers, leading to potential security + breaches and data loss. + measure: "Measurement and communication of patching Mean Time to Resolution + (MTTR) in alignment with Service Level Agreements (SLAs), conducted at least + on a quarterly basis.\nThis includes the measurement of the existence of a + properly configured automated pull request (PR) tool (e.g., Dependabot or + Renovate) in a repository. \nIn addition, the measurement of the time from + opening an automated PR to merging it.\n\nAverage time to patch is visualized + per component/project/team." + difficultyOfImplementation: + knowledge: 1 time: 1 - resources: 1 - usefulness: 5 - level: 4 + resources: 2 + usefulness: 3 + level: 2 dependsOn: - - Grouping of metrics + - 8ae0b92c-10e0-4602-ba22-7524d6aed488 # Automated PRs for patches implementation: [] references: samm2: - - O-IM-2-A - iso27001-2017: - - Not explicitly covered by ISO 27001 - too specific - - 16.1.5 + - I-DM-B-2 iso27001-2022: - - Not explicitly covered by ISO 27001 - too specific - - 5.26 - isImplemented: false - evidence: "" - comments: "" + - 5.25 + - 5.12 + - 5.13 + - 5.1 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Test%20KPI/subsection/Patching%20mean%20time%20to%20resolution%20via%20PR tags: - - none - Simple application metrics: - uuid: e9a6d403-a467-445e-b98a-74f0c29da0b1 - risk: Attacks on an application are not recognized. - measure: Gathering of application metrics helps to identify incidents like brute - force attacks, login/logout. + - patching + - metrics + - vmm-measurements + Fix rate per repo/product: + uuid: cf0d600e-114d-4887-9059-d81c53805f0d + risk: "Not communicating how many applications are adhering to SLAs based on + the criticality of vulnerabilities can lead to delayed remediation of \ncritical + security issues, increasing the risk of exploitation and potential damage + to the organization." + measure: "Measurement and communication of the number of vulnerabilities handled + per severity level for components such as applications, ensuring alignment + with SLAs. \nThe rate should be broken down by team, product, application, + repository, and/or service. This analysis should be conducted at least quarterly." difficultyOfImplementation: knowledge: 2 time: 2 resources: 2 - usefulness: 5 - level: 1 + usefulness: 3 + level: 3 implementation: - - uuid: ddf221df-3517-42e4-b23d-c1d9a162744c - name: Prometheus - tags: [] - url: https://prometheus.io/ + - uuid: 227d786c-dd76-4b81-b0b2-62389ab8f0fb + name: OWASP DefectDojo + tags: + - vulnerability management system + - owasp + url: https://github.com/DefectDojo/django-DefectDojo + description: | + DefectDojo is a security program and vulnerability management tool. DefectDojo allows you to manage your application security program, maintain product and application information, triage vulnerabilities and push findings into defect trackers. Consolidate your findings into one source of truth with DefectDojo. + - uuid: d2eb592d-c9b5-4c39-bff7-bb313a58e3a9 + name: Purify + tags: + - vulnerability management system + url: https://github.com/faloker/purify/ + description: | + The goal of Purify to be an easy-in-use and efficient tool to simplify a workflow of managing vulnerabilities delivered from various (even custom) tools. + - uuid: 3b99799c-e875-4cc2-aad7-5ce4564a1cde + name: Business friendly vulnerability management metrics + url: https://medium.com/uber-security-privacy/business-friendly-vulnerability-management-metrics-cfd702fd7705 + test-url-expects: + - 403 + tags: + - documentation + - vulnerability + - vulnerability management system + - uuid: 7ec30b0e-9681-427a-80ee-ab811d9e476f + name: DefectDojo Client + tags: + - Defectdojo + - statistics + url: https://github.com/SDA-SE/defectdojo-client + description: | + This projects contains the DefectDojo upload client and statistics client. It is for example used within the ClusterImageScanner. references: samm2: - - O-IM-1-A - iso27001-2017: - - 12.4.1 + - I-DM-B-2 iso27001-2022: - - 8.15 - isImplemented: false - evidence: "" - comments: "" + - 5.25 + - 5.12 + - 5.13 + - 5.1 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Test%20KPI/subsection/Fix%20rate%20per%20repo%2Fproduct tags: - - none - Simple budget metrics: - uuid: f08a3219-6941-43ec-8762-4aff739f4664 - risk: Not getting notified about reaching the end of the budget (e.g. due to - a denial of service) creates unexpected costs. - measure: Cloud providers often provide insight into budgets. A threshold and - alarming for the budget is set. + - vulnerability-mgmt + - metrics + - vmm-measurements + Generation of response statistics: + uuid: c922981b-65ed-40f3-a947-96fee9a0125f + risk: No or delayed reaction to findings leads to potential exploitation of + findings. + measure: Creation and response statistics (e.g. Mean Time to Resolution) of + findings. This is also referred to as _Mean Time to Resolve_. difficultyOfImplementation: - knowledge: 1 - time: 1 + knowledge: 2 + time: 2 resources: 1 - usefulness: 5 - level: 1 + usefulness: 3 + dependsOn: + - 85ba5623-84be-4219-8892-808837be582d # Usage of a vulnerability management system + level: 3 implementation: - - uuid: 73f6a52c-4fc2-45dc-991b-d5911b6c1ef8 - name: collected - tags: [] + - uuid: 227d786c-dd76-4b81-b0b2-62389ab8f0fb + name: OWASP DefectDojo + tags: + - vulnerability management system + - owasp + url: https://github.com/DefectDojo/django-DefectDojo + description: | + DefectDojo is a security program and vulnerability management tool. DefectDojo allows you to manage your application security program, maintain product and application information, triage vulnerabilities and push findings into defect trackers. Consolidate your findings into one source of truth with DefectDojo. + - uuid: d2eb592d-c9b5-4c39-bff7-bb313a58e3a9 + name: Purify + tags: + - vulnerability management system + url: https://github.com/faloker/purify/ + description: | + The goal of Purify to be an easy-in-use and efficient tool to simplify a workflow of managing vulnerabilities delivered from various (even custom) tools. + - uuid: 3b99799c-e875-4cc2-aad7-5ce4564a1cde + name: Business friendly vulnerability management metrics + url: https://medium.com/uber-security-privacy/business-friendly-vulnerability-management-metrics-cfd702fd7705 + test-url-expects: + - 403 + tags: + - documentation + - vulnerability + - vulnerability management system + - uuid: 7ec30b0e-9681-427a-80ee-ab811d9e476f + name: DefectDojo Client + tags: + - Defectdojo + - statistics + url: https://github.com/SDA-SE/defectdojo-client + description: | + This projects contains the DefectDojo upload client and statistics client. It is for example used within the ClusterImageScanner. references: samm2: - - O-IM-1-A + - I-DM-B-2 + - I-SB-B-3 iso27001-2017: - - 12.1.3 + - 16.1.4 + - 8.2.3 iso27001-2022: - - 8.6 - isImplemented: false - evidence: "" - comments: "" + - 5.25 + - 5.1 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Test%20KPI/subsection/Generation%20of%20response%20statistics tags: - - none - Simple system metrics: - uuid: 3d1f4c3b-f713-46d9-933a-54a014a26c03 - risk: Without simple metrics analysis of incidents are hard. In case an application - uses a lot of CPU from time to time, it is hard for a developer to find out - the source with Linux commands. - measure: Gathering of system metrics helps to identify incidents and specially - bottlenecks like in CPU usage, memory usage and hard disk usage. + - vulnerability-mgmt + - metrics + - vmm-measurements + comments: The [DefectDojo-Client](https://github.com/SDA-SE/defectdojo-client/tree/master/statistic-client) + generates statistics from OWASP DefectDojo and places the results in a [Github + repository](https://github.com/pagel-pro/cluster-image-scanner-all-results). + SLA per criticality: + uuid: 51f3fce5-b5c8-4683-8c41-e785fe4f3b5f + risk: "Not communicating how many applications are adhering to SLAs based on + the criticality of vulnerabilities can lead to delayed remediation of \ncritical + security issues, increasing the risk of exploitation and potential damage + to the organization." + measure: "Measurement and communication of how many of the vulnerabilities handling + per severity for components like applications are aligned to SLAs. \nThis + is performed for the hole organization and doesn't need to be broken down + (yet) on team/product/application. \nAt least quarterly." difficultyOfImplementation: knowledge: 2 time: 2 resources: 2 - usefulness: 5 - assessment: | - Are system metrics gathered? - level: 1 - implementation: - - uuid: 73f6a52c-4fc2-45dc-991b-d5911b6c1ef8 - name: collected - tags: [] - references: - samm2: - - O-IM-1-A - iso27001-2017: - - 12.1.3 - iso27001-2022: - - 8.6 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Targeted alerting: - uuid: d6f06ae8-401a-4f44-85df-1079247fa030 - risk: People are bored (ignorant) of incident alarm messages, as they are not - responsible to react. - measure: By the definition of target groups for incidents people are only getting - alarms for incidents they are in charge for. - difficultyOfImplementation: - knowledge: 2 - time: 5 - resources: 5 - usefulness: 5 + usefulness: 3 level: 3 - dependsOn: - - Alerting - implementation: [] + dependsOn: [] + implementation: + - uuid: 227d786c-dd76-4b81-b0b2-62389ab8f0fb + name: OWASP DefectDojo + tags: + - vulnerability management system + - owasp + url: https://github.com/DefectDojo/django-DefectDojo + description: | + DefectDojo is a security program and vulnerability management tool. DefectDojo allows you to manage your application security program, maintain product and application information, triage vulnerabilities and push findings into defect trackers. Consolidate your findings into one source of truth with DefectDojo. + - uuid: d2eb592d-c9b5-4c39-bff7-bb313a58e3a9 + name: Purify + tags: + - vulnerability management system + url: https://github.com/faloker/purify/ + description: | + The goal of Purify to be an easy-in-use and efficient tool to simplify a workflow of managing vulnerabilities delivered from various (even custom) tools. + - uuid: 3b99799c-e875-4cc2-aad7-5ce4564a1cde + name: Business friendly vulnerability management metrics + url: https://medium.com/uber-security-privacy/business-friendly-vulnerability-management-metrics-cfd702fd7705 + test-url-expects: + - 403 + tags: + - documentation + - vulnerability + - vulnerability management system + - uuid: 7ec30b0e-9681-427a-80ee-ab811d9e476f + name: DefectDojo Client + tags: + - Defectdojo + - statistics + url: https://github.com/SDA-SE/defectdojo-client + description: | + This projects contains the DefectDojo upload client and statistics client. It is for example used within the ClusterImageScanner. references: samm2: - - I-DM-A 3 - iso27001-2017: - - Not explicitly covered by ISO 27001 - too specific - - 16.1.5 + - I-DM-B-2 iso27001-2022: - - Not explicitly covered by ISO 27001 - too specific - - 5.26 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Visualized metrics: - uuid: ded39bcf-4eaa-4c5f-9c94-09acde0a4734 - risk: Not visualized metrics lead to restricted usage of metrics. - measure: Metrics are visualized in real time in a user friendly way. + - 5.25 + - 5.12 + - 5.13 + - 5.1 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Test%20KPI/subsection/SLA%20per%20criticality + tags: + - vulnerability-mgmt + - metrics + - vmm-measurements + Patching mean time to resolution via production: + uuid: 77ffc53e-9f3d-41f4-92d3-02f04f9b6b0f + risk: Without measuring Mean Time to Resolution (MTTR) related to patching, + it is challenging to identify delays in the patching process. Unaddressed + vulnerabilities can be exploited by attackers, leading to potential security + breaches and data loss. + measure: |- + Measurement and communication of the time from the availability of a patch to its deployment in production in alignment with Service Level Agreements (SLAs), conducted at least on a quarterly basis. + Average time to patch is visualized per component/project/team. difficultyOfImplementation: knowledge: 1 - time: 2 + time: 1 resources: 2 usefulness: 3 - level: 2 + level: 4 dependsOn: - - Simple application metrics - - Simple system metrics + - 86d490b9-d798-4a5b-a011-ab9688014c46 # Patching mean time to resolution via PR + - 8ae0b92c-10e0-4602-ba22-7524d6aed488 # Automated PRs for patches implementation: [] references: samm2: - - O-IM-2-A + - I-DM-B-2 iso27001-2017: - - 12.1.3 + - 16.1.4 iso27001-2022: - - 8.6 - isImplemented: false - evidence: "" - comments: "" + - 5.25 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Test%20KPI/subsection/Patching%20mean%20time%20to%20resolution%20via%20production tags: - - none + - patching + - metrics + - vmm-measurements Test and Verification: Application tests: - High coverage of security related module and integration tests: - uuid: 67667c97-c33e-4306-a4e5-e7b1d8e10c5a - risk: Vulnerabilities are rising due to code changes in a complex microservice - environment in not important components. - measure: Implementation of security related tests via unit tests and integration - tests. Including the test of libraries, in case the are not tested already. + Security unit tests for important components: + uuid: eb2c7f9d-d0bd-4253-a2ba-cff2ace4a075 + risk: Vulnerabilities are rising due to code changes. + measure: Usage of unit tests to test important security related features like + authentication and authorization. difficultyOfImplementation: - knowledge: 5 - time: 5 - resources: 3 + knowledge: 3 + time: 4 + resources: 2 usefulness: 3 - level: 5 - implementation: [] + level: 2 + comments: | + The integration of module tests takes place during development instead, it highlights vulnerabilities in sub-routines, functions, modules, libraries etc. checked. + A sample implementation of unit tests are explained in the video [Shift-Left-Security with the Security Test Pyramid - Andreas Falk](https://www.youtube.com/watch?v=TzFZy3f7d8E) starting with minute 9. + implementation: + - uuid: cc2eec82-f3a7-4ae5-9ccb-3d75352b2e4d + name: JUnit + tags: + - unittest + url: https://junit.org/ + - uuid: fd56720a-ad4b-487c-b4c3-897a688672c4 + name: Karma + tags: [] + url: https://karma-runner.github.io references: samm2: - - V-ST-3-B + - V-RT-A-3 iso27001-2017: - 14.2.3 - 14.2.8 iso27001-2022: - 8.32 - 8.29 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Application%20tests/subsection/Security%20unit%20tests%20for%20important%20components isImplemented: false evidence: "" - comments: "" tags: - none Security integration tests for important components: @@ -5319,57 +5575,22 @@ Test and Verification: knowledge: 3 time: 4 resources: 2 - usefulness: 2 - level: 3 - references: - samm2: - - V-ST-3-B - iso27001-2017: - - 14.2.3 - - 14.2.8 - iso27001-2022: - - 8.32 - - 8.29 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Security unit tests for important components: - uuid: eb2c7f9d-d0bd-4253-a2ba-cff2ace4a075 - risk: Vulnerabilities are rising due to code changes. - measure: Usage of unit tests to test important security related features like - authentication and authorization. - difficultyOfImplementation: - knowledge: 3 - time: 4 - resources: 2 - usefulness: 3 - level: 2 - comments: | - The integration of module tests takes place during development instead, it highlights vulnerabilities in sub-routines, functions, modules, libraries etc. checked. - A sample implementation of unit tests are explained in the video [Shift-Left-Security with the Security Test Pyramid - Andreas Falk](https://www.youtube.com/watch?v=TzFZy3f7d8E) starting with minute 9. - implementation: - - uuid: cc2eec82-f3a7-4ae5-9ccb-3d75352b2e4d - name: JUnit - tags: - - unittest - url: https://junit.org/junit5/ - - uuid: fd56720a-ad4b-487c-b4c3-897a688672c4 - name: Karma - tags: [] - url: https://karma-runner.github.io + usefulness: 2 + level: 3 references: samm2: - - V-ST-3-B + - V-RT-A-3 iso27001-2017: - 14.2.3 - 14.2.8 iso27001-2022: - 8.32 - 8.29 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Application%20tests/subsection/Security%20integration%20tests%20for%20important%20components isImplemented: false evidence: "" + comments: "" tags: - none Smoke Test: @@ -5386,33 +5607,85 @@ Test and Verification: level: 4 implementation: [] dependsOn: - - Defined deployment process + - 67e1a9aa-9fbf-4ec5-a2de-400f01960c51 # Automated deployment process + references: + samm2: + - V-RT-A-3 + iso27001-2017: + - 14.2.3 + - 14.2.8 + iso27001-2022: + - 8.32 + - 8.29 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Application%20tests/subsection/Smoke%20Test + isImplemented: false + evidence: "" + comments: "" + tags: + - none + High coverage of security related module and integration tests: + uuid: 67667c97-c33e-4306-a4e5-e7b1d8e10c5a + risk: Vulnerabilities are rising due to code changes in a complex microservice + environment in not important components. + measure: Implementation of security related tests via unit tests and integration + tests. Including the test of libraries, in case the are not tested already. + difficultyOfImplementation: + knowledge: 5 + time: 5 + resources: 3 + usefulness: 3 + level: 5 + implementation: [] references: samm2: - - V-ST-3-B + - V-RT-B-3 iso27001-2017: - 14.2.3 - 14.2.8 iso27001-2022: - 8.32 - 8.29 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Application%20tests/subsection/High%20coverage%20of%20security%20related%20module%20and%20integration%20tests isImplemented: false evidence: "" comments: "" tags: - none Consolidation: - Advanced visualization of defects: - uuid: 7a82020c-94d1-471c-bbd3-5f7fe7df4876 - risk: Correlation of the vulnerabilities of different tools to have an overview - of the the overall security level per component/project/team is not given. - measure: Findings are visualized per component/project/team. + Simple false positive treatment: + uuid: c1acc8af-312e-4503-a817-a26220c993a0 + description: | + Security tests may produce false positives (or _"false alarms"_), findings that are incorrectly identified as vulnerabilities. + + It is important distinguish these from true positive vulnerabilities to avoid wasting time and resources on non-issues. + + False positive treatment ensures that findings from security tests are triaged and documented, allowing teams to distinguish between real vulnerabilities and false positives. This reduces unnecessary work and helps maintain focus on true risks. + + Some positive findings might be considered an _accepted risk_ by the organization. This must also be documented. + risk: | + If false positives are not managed, teams may ignore all findings, leading to real vulnerabilities being overlooked and increasing the risk of exploitation. Specially, if tests are automated an run daily. + measure: | + Findings from security tests must be triaged and outcomes persisted/documented to: + - Prevent re-analysis of known issues in subsequent test runs + - Track accepted risks vs false positives + - Enable consistent decision-making across teams + + At this maturity level, a simple tracking system suffices - tools need only distinguish between "triaged" and "untriaged" findings, without complex categorization. Some tools refer to this as "suppression" of findings. + + Samples for false positive handling: + - [OWASP Dependency Check](https://jeremylong.github.io/DependencyCheck/general/suppression.html) + - [Kubescape with VEX](https://kubescape.io/blog/2023/12/07/kubescape-support-for-vex-generation/) + - [OWASP DefectDojo Risk Acceptance](https://docs.defectdojo.com/en/working_with_findings/findings_workflows/risk_acceptances/) and [False Positive Handling](https://docs.defectdojo.com/en/working_with_findings/intro_to_findings/#triage-vulnerabilities-using-finding-status) + assessment: | + A process is defined for triaging and documenting false positives and accepted risks + level: 1 difficultyOfImplementation: - knowledge: 2 - time: 4 + knowledge: 1 + time: 1 resources: 1 - usefulness: 2 - level: 4 + usefulness: 4 implementation: - uuid: 227d786c-dd76-4b81-b0b2-62389ab8f0fb name: OWASP DefectDojo @@ -5429,45 +5702,94 @@ Test and Verification: url: https://github.com/faloker/purify/ description: | The goal of Purify to be an easy-in-use and efficient tool to simplify a workflow of managing vulnerabilities delivered from various (even custom) tools. - - uuid: 3b99799c-e875-4cc2-aad7-5ce4564a1cde - name: Business friendly vulnerability management metrics - url: https://medium.com/uber-security-privacy/business-friendly-vulnerability-management-metrics-cfd702fd7705 - tags: - - documentation - - vulnerability - - vulnerability management system references: samm2: - - I-DM-3-B + - I-DM-A-1 iso27001-2017: - - 16.1.4 - - 8.2.1 - - 8.2.2 - - 8.2.3 + - Not explicitly covered by ISO 27001 - too specific + - 16.1.6 iso27001-2022: - - 5.25 - - 5.12 - - 5.13 - - 5.1 + - Not explicitly covered by ISO 27001 - too specific + - 5.27 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Consolidation/subsection/Simple%20false%20positive%20treatment isImplemented: false + tags: + - false-positive + - defect-management + - scanning + - sca + - sats + - dast evidence: "" comments: "" - tags: - - none - Generation of Patch Management Statistics: - uuid: 785e34ef-40c6-487a-984c-3e7706c9bc1f - risk: Delays in patch response lead to an increased attack surface through longer - exposure of known vulnerabilities. - measure: Average time to patch is visualized per component/project/team. + Treatment of defects with high or critical severity: + uuid: 44f2c8a9-4aaa-4c72-942d-63f78b89f385 + description: | + All security problems that are rated as "high" or "critical" must be fixed before the software can be released or used in production. This means that if a serious vulnerability is found, it cannot be ignored or postponed. + risk: | + If serious security problems are not fixed, attackers could exploit them to steal data, disrupt services, or cause other harm. Ignoring these issues puts the organization, its customers, and its reputation at risk. + measure: | + - Make it a rule that all _high_ or _critical_ security findings must be fixed before the software is approved for release or use. + - Track these issues and make sure they are resolved quickly. + assessment: | + - Provide evidence that vulnerabilities are treated within the defined time frame in production. For example via the DSOMM activity [Number of vulnerabilities/severity](./activity-description?uuid=bc548cba-cb82-4f76-bd4b-325d9d256279) or [Patching mean time to resolution via PR](./activity-description?uuid=86d490b9-d798-4a5b-a011-ab9688014c46) with extra deployment statistics. + comments: False positive analysis, specially for static analysis, is time consuming. + level: 1 difficultyOfImplementation: knowledge: 2 time: 2 resources: 1 - usefulness: 2 - level: 3 + usefulness: 4 + references: + samm2: + - I-DM-A-2 + iso27001-2017: + - 16.1.4 + - 12.6.1 + iso27001-2022: + - 8.8 + - 5.25 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Consolidation/subsection/Treatment%20of%20defects%20with%20high%20or%20critical%20severity + implementation: + - uuid: 7f500e95-2110-44c4-a1f8-cd7ef5d9eb6b + name: Trivy + tags: [] + url: https://github.com/aquasecurity/trivy + - uuid: 7970af6e-a7d3-4359-a6ea-301d26b16329 + name: Grype + tags: + - sbom + - dependency + - vulnerability + url: https://github.com/anchore/grype + tags: + - vuln-action + - defect-management + evidence: "" + Artifact-based false positive treatment: + uuid: 8f2b4d5a-3c1e-4b7a-9d8f-2e6c4a1b5d7f + risk: Without artifact-specific false positive handling, teams must repeatedly + triage the same findings across different versions or deployments of the same + component, leading to inefficient use of security resources. + measure: "Implement false positive marking and temporary acceptance of findings + \nbased on specific artifacts (applications, components, or repositories).\nThis + allows teams to suppress findings for specific versions or builds\nwhile maintaining + visibility for future releases." + description: |- + Artifact-based false positive treatment enables more granular control + over finding suppression by linking decisions to specific code artifacts, + container images, or application versions. This approach helps maintain + security oversight while reducing repeated analysis overhead. + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 2 + usefulness: 3 + level: 2 dependsOn: - - A patch policy is defined - - Automated PRs for patches + - c1acc8af-312e-4503-a817-a26220c993a0 # Simple false positive treatment implementation: - uuid: 227d786c-dd76-4b81-b0b2-62389ab8f0fb name: OWASP DefectDojo @@ -5484,40 +5806,72 @@ Test and Verification: url: https://github.com/faloker/purify/ description: | The goal of Purify to be an easy-in-use and efficient tool to simplify a workflow of managing vulnerabilities delivered from various (even custom) tools. - - uuid: 3b99799c-e875-4cc2-aad7-5ce4564a1cde - name: Business friendly vulnerability management metrics - url: https://medium.com/uber-security-privacy/business-friendly-vulnerability-management-metrics-cfd702fd7705 + - uuid: 500399bd-7dfc-47fd-99d8-b55cefb760a9 + name: Dependency-Track + description: | + Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track takes a unique and highly beneficial approach by leveraging the capabilities of Software Bill of Materials (SBOM). + url: https://github.com/DependencyTrack/dependency-track tags: - - documentation + - sca + - inventory + - OpenSource + - Supply Chain - vulnerability - - vulnerability management system + - inventory references: samm2: - - I-DM-3-B + - I-DM-A-2 + - I-DM-B-2 + - I-SB-B-3 iso27001-2017: - 16.1.4 + - 16.1.6 iso27001-2022: - 5.25 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Generation of Response Statistics: - uuid: c922981b-65ed-40f3-a947-96fee9a0125f - risk: No or delayed reaction to findings leads to potential exploitation of - findings. - measure: Creation and response statistics of findings. This is also referred - to as _Mean Time to Resolve_. + - 5.27 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Consolidation/subsection/Artifact-based%20false%20positive%20treatment + tags: + - false-positive + - defect-management + - scanning + - sca + - sats + - dast + Simple visualization of defects: + uuid: 55f4c916-3a34-474d-ad96-9a9f7a4f6a83 + risk: The security level of a component is not visible. Therefore, the motivation + to enhance the security is not give. + measure: Vulnerabilities are simple visualized. difficultyOfImplementation: knowledge: 2 time: 2 resources: 1 usefulness: 3 - dependsOn: - - Usage of a vulnerability management system - level: 3 + level: 2 implementation: + - uuid: 06334caf-8be6-487a-96b1-d41c7ed5f207 + name: OWASP Dependency Check + tags: + - OpenSource + - Supply Chain + - vulnerability + url: https://owasp.org/www-project-dependency-check/ + - uuid: 500399bd-7dfc-47fd-99d8-b55cefb760a9 + name: Dependency-Track + description: | + Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track takes a unique and highly beneficial approach by leveraging the capabilities of Software Bill of Materials (SBOM). + url: https://github.com/DependencyTrack/dependency-track + tags: + - sca + - inventory + - OpenSource + - Supply Chain + - vulnerability + - inventory + - uuid: ef80cd34-d3ba-4406-a4fa-4cf6f30c2e81 + name: LogParser Jenkins Plugins + tags: [] - uuid: 227d786c-dd76-4b81-b0b2-62389ab8f0fb name: OWASP DefectDojo tags: @@ -5533,98 +5887,51 @@ Test and Verification: url: https://github.com/faloker/purify/ description: | The goal of Purify to be an easy-in-use and efficient tool to simplify a workflow of managing vulnerabilities delivered from various (even custom) tools. - - uuid: 3b99799c-e875-4cc2-aad7-5ce4564a1cde - name: Business friendly vulnerability management metrics - url: https://medium.com/uber-security-privacy/business-friendly-vulnerability-management-metrics-cfd702fd7705 - tags: - - documentation - - vulnerability - - vulnerability management system - - uuid: 7ec30b0e-9681-427a-80ee-ab811d9e476f - name: DefectDojo Client - tags: - - Defectdojo - - statistics - url: https://github.com/SDA-SE/defectdojo-client - description: | - This projects contains the DefectDojo upload client and statistics client. It is for example used within the ClusterImageScanner. references: samm2: - - I-DM-2-B + - I-DM-A-2 iso27001-2017: - 16.1.4 + - 8.2.1 + - 8.2.2 - 8.2.3 iso27001-2022: - 5.25 + - 5.12 + - 5.13 - 5.1 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Consolidation/subsection/Simple%20visualization%20of%20defects isImplemented: false evidence: "" - comments: The [DefectDojo-Client](https://github.com/SDA-SE/defectdojo-client/tree/master/statistic-client) - generates statistics from OWASP DefectDojo and places the results in a [Github - repository](https://github.com/pagel-pro/cluster-image-scanner-all-results). + comments: "" tags: - none - Integration of vulnerability issues into the development process: - uuid: ce970c9b-da94-41cf-bd78-8c15357b7e8e - risk: To read console output of the build server to search for vulnerabilities - might be difficult. Also, to check a vulnerability management system might - not be a daily task for a developer. - measure: Vulnerabilities are tracked in the teams issue system (e.g. jira). + Fix based on accessibility: + uuid: 0c10a7f7-f78f-49f2-943d-19fdef248fed + risk: Overwhelming volume of security findings from automated testing tools. + This might lead to ignorance of findings. + measure: Implement a simple risk-based prioritization framework for vulnerability + remediation based on accessibility of the applications. difficultyOfImplementation: knowledge: 2 time: 2 resources: 1 - usefulness: 2 + usefulness: 4 level: 3 - implementation: - - uuid: aaad322e-806e-4c51-b78d-6551f7dc376a - name: SAST - tags: [] - description: 'At SAST (Static Application Security Testing): Server-side / - client-side teams can easily be recorded. With microservice architecture - individual microservices can be used usually Teams.' - url: https://d3fend.mitre.org/dao/artifact/d3f:StaticAnalysisTool/ - - uuid: 9d4bd377-11ec-4054-9c9e-9bfb99ac9609 - name: DAST - tags: [] - description: 'At DAST (Dynamic Application Security Testing): vulnerabilities - are classified and can be assigned to server-side and client-side teams.' - url: https://d3fend.mitre.org/dao/artifact/d3f:DynamicAnalysisTool/ - references: - samm2: - - I-DM-2-B - iso27001-2017: - - Not explicitly covered by ISO 27001 - too specific - - 16.1.4 - - 16.1.5 - - 16.1.6 - iso27001-2022: - - Not explicitly covered by ISO 27001 - too specific - - 5.25 - - 5.26 - - 5.27 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Reproducible defect tickets: - uuid: 27337442-e4b1-4e87-8dc9-ce86fbb79a39 - risk: Vulnerability descriptions are hard to understand by staff from operations - and development. - measure: Vulnerabilities include the test procedure to give the staff from operations - and development the ability to reproduce vulnerabilities. This enhances the - understanding of vulnerabilities and therefore the fix have a higher quality. - difficultyOfImplementation: - knowledge: 3 - time: 2 - resources: 2 - usefulness: 2 - level: 4 - implementation: [] + meta: + implementationGuide: |- + Develop a scoring system for asset accessibility, considering factors like: + - Whether the asset is internet-facing (highly recommended) + - The number of network hops required to reach the asset (recommended) + - Authentication requirements for access (recommended) + dependsOn: + - 44f2c8a9-4aaa-4c72-942d-63f78b89f385 # Treatment of defects with high or critical severity + - 2a44b708-734f-4463-b0cb-86dc46344b2f # Inventory of production components + implementation: ~ references: samm2: - - I-DM-2-B + - I-DM-A-3 iso27001-2017: - 16.1.4 - 8.2.1 @@ -5635,84 +5942,96 @@ Test and Verification: - 5.12 - 5.13 - 5.1 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Simple false positive treatment: - uuid: c1acc8af-312e-4503-a817-a26220c993a0 - risk: As false positive occur during each test, all vulnerabilities might be - ignored. - measure: False positives are suppressed so they will not show up on the next - tests again. Most security tools have the possibility to suppress false positives. - A Vulnerability Management System might be used. + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Consolidation/subsection/Fix%20based%20on%20accessibility + tags: + - vuln-action + - defect-management + Global false positive treatment: + uuid: 9e3a7c2f-1b4d-4e8a-a5c6-7f2b9d1e3a8c + risk: Without centralized false positive management across environments, organizations + face inconsistent security decisions, duplicated analysis efforts, and potential + security gaps when the same findings are handled differently across applications + and teams. + measure: "Implement global false positive and acceptance management that applies + \nconsistently across all applications. This enables organization-wide security + decisions and reduces redundant \nanalysis of common false positives." + description: "Global false positive treatment allows (security) teams to make + \norganization-wide decisions about specific vulnerabilities or finding \npatterns. + When a finding is marked as a false positive or temporarily \naccepted at + the global level, this decision automatically applies to \nall applications + in the specified environment, ensuring consistency \nand operational efficiency." difficultyOfImplementation: - knowledge: 1 - time: 1 - resources: 1 - usefulness: 4 - level: 1 - implementation: - - uuid: bb9d0f2d-f8bc-46b5-bbc7-7dbcf927191c - name: OWASP Defect Dojo - tags: [] - url: https://github.com/DefectDojo/django-DefectDojo - - uuid: d2eb592d-c9b5-4c39-bff7-bb313a58e3a9 - name: Purify - tags: - - vulnerability management system - url: https://github.com/faloker/purify/ - description: | - The goal of Purify to be an easy-in-use and efficient tool to simplify a workflow of managing vulnerabilities delivered from various (even custom) tools. + knowledge: 3 + time: 3 + resources: 2 + usefulness: 4 + level: 3 + dependsOn: + - 8f2b4d5a-3c1e-4b7a-9d8f-2e6c4a1b5d7f # Artifact-based false positive treatment + - 85ba5623-84be-4219-8892-808837be582d # Usage of a vulnerability management system + implementation: ~ references: samm2: - - I-DM-2-A + - I-DM-B-2 + - I-DM-A-3 + - I-SB-B-3 iso27001-2017: - - Not explicitly covered by ISO 27001 - too specific + - 16.1.3 + - 16.1.4 - 16.1.6 iso27001-2022: - - Not explicitly covered by ISO 27001 - too specific + - 6.8 + - 5.25 - 5.27 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Simple visualization of defects: - uuid: 55f4c916-3a34-474d-ad96-9a9f7a4f6a83 - risk: The security level of a component is not visible. Therefore, the motivation - to enhance the security is not give. - measure: Vulnerabilities are simple visualized. + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Consolidation/subsection/Global%20false%20positive%20treatment + tags: + - false-positive + - defect-management + Integration in development process: + uuid: aaffa73f-59f6-4267-b0ab-732f3d13e90d + risk: "Not integrating vulnerability handling into the development process may + result in product teams ignoring findings. \n\nSecurity joke: We will gain + 100% false negatives." + measure: Integration of findings into the development process. E.g. adding findings + to the backlog of products teams. + description: |- + Validating Findings by Security Engineers Pros: + - Ensures accuracy and relevance of findings before they reach product teams + - Reduces false positives, saving development teams time and effort + - Might provides a layer of expertise in assessing the severity and impact of vulnerabilities + + Validating Findings by Security Engineers Cons: + - Requires a sufficient number of skilled security engineers, which might be challenging for some organizations + - May slow down the process if security engineers are overloaded with validation tasks + - For Software Composition Analysis findings (known vulnerabilities) I, as a sec. eng., struggle to analysis if it is a false positive/true positive due to a lack of insights in the application + + Pushing Findings Directly to Product Teams Pros: + - Accelerates the process by immediately notifying product teams of potential vulnerabilities + - Empowers product teams to take swift action in addressing security issues + Pushing Findings Directly to Product Teams Cons: + - Increases the workload on product teams, potentially leading to frustration difficultyOfImplementation: knowledge: 2 time: 2 - resources: 1 + resources: 2 usefulness: 3 - level: 2 + level: 3 + dependsOn: [] implementation: - - uuid: 06334caf-8be6-487a-96b1-d41c7ed5f207 - name: OWASP Dependency Check + - uuid: 889444eb-de68-4367-bada-a66f8cb9733a + name: Jira tags: - - OpenSource - - Supply Chain - - vulnerability - url: https://owasp.org/www-project-dependency-check/ - - uuid: 500399bd-7dfc-47fd-99d8-b55cefb760a9 - name: Dependency-Track is an intelligent Component Analysis platform that - allows organizations to identify and reduce risk in the software supply - chain. Dependency-Track takes a unique and highly beneficial approach by - leveraging the capabilities of Software Bill of Materials (SBOM). - url: https://github.com/DependencyTrack/dependency-track - tags: - - sca - - inventory - - OpenSource - - Supply Chain - - vulnerability - - uuid: ef80cd34-d3ba-4406-a4fa-4cf6f30c2e81 - name: LogParser Jenkins Plugins - tags: [] + - documentation + - issue + - proprietary + url: https://jira.atlassian.com/ + description: Jira is a bug tracking and project management tool developed + by Atlassian, used by development teams for tracking issues, planning sprints, + and managing software releases. It offers features for creating and managing + tasks, assigning them to team members, and monitoring progress through customizable + workflows and dashboards. - uuid: 227d786c-dd76-4b81-b0b2-62389ab8f0fb name: OWASP DefectDojo tags: @@ -5728,76 +6047,143 @@ Test and Verification: url: https://github.com/faloker/purify/ description: | The goal of Purify to be an easy-in-use and efficient tool to simplify a workflow of managing vulnerabilities delivered from various (even custom) tools. + - uuid: 7ec30b0e-9681-427a-80ee-ab811d9e476f + name: DefectDojo Client + tags: + - Defectdojo + - statistics + url: https://github.com/SDA-SE/defectdojo-client + description: | + This projects contains the DefectDojo upload client and statistics client. It is for example used within the ClusterImageScanner. references: samm2: - - I-DM-1-B - iso27001-2017: - - 16.1.4 - - 8.2.1 - - 8.2.2 - - 8.2.3 + - I-DM-A-2 iso27001-2022: - 5.25 - 5.12 - 5.13 - 5.1 - isImplemented: false - evidence: "" - comments: "" + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Consolidation/subsection/Integration%20in%20development%20process tags: - - none - Treatment of all defects: - uuid: b2f77606-3e6c-41e9-b72d-7c0b1d3d581d - risk: Vulnerabilities with severity low are not visible. - measure: All vulnerabilities are added to the quality gate. + - vulnerability-mgmt + - vmm-measurements + Integration of vulnerability issues into the development process: + uuid: ce970c9b-da94-41cf-bd78-8c15357b7e8e + risk: To read console output of the build server to search for vulnerabilities + might be difficult. Also, to check a vulnerability management system might + not be a daily task for a developer. + measure: Vulnerabilities are tracked in the teams issue system (e.g. jira). difficultyOfImplementation: - knowledge: 3 - time: 4 + knowledge: 2 + time: 2 resources: 1 usefulness: 2 - level: 5 - implementation: [] + level: 3 + implementation: + - uuid: aaad322e-806e-4c51-b78d-6551f7dc376a + name: SAST + tags: [] + description: 'At SAST (Static Application Security Testing): Server-side / + client-side teams can easily be recorded. With microservice architecture + individual microservices can be used usually Teams.' + url: https://d3fend.mitre.org/dao/artifact/d3f:StaticAnalysisTool/ + - uuid: 9d4bd377-11ec-4054-9c9e-9bfb99ac9609 + name: DAST + tags: [] + description: 'At DAST (Dynamic Application Security Testing): vulnerabilities + are classified and can be assigned to server-side and client-side teams.' + url: https://d3fend.mitre.org/dao/artifact/d3f:DynamicAnalysisTool/ references: samm2: - - I-DM-2-B + - I-DM-A-2 iso27001-2017: + - Not explicitly covered by ISO 27001 - too specific - 16.1.4 - - 12.6.1 + - 16.1.5 + - 16.1.6 iso27001-2022: - - 8.8 + - Not explicitly covered by ISO 27001 - too specific - 5.25 + - 5.26 + - 5.27 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Consolidation/subsection/Integration%20of%20vulnerability%20issues%20into%20the%20development%20process isImplemented: false evidence: "" comments: "" tags: - none - Treatment of defects with severity high or higher: - uuid: 44f2c8a9-4aaa-4c72-942d-63f78b89f385 - risk: Vulnerabilities with severity high or higher are not visible. - measure: Vulnerabilities with severity high or higher are added to the quality - gate. + Treatment of defects per protection requirement: + uuid: 2b7cc923-bdaf-43e3-8fb4-a995b7783969 + risk: "Not defining the protection requirement of applications can lead to wrong + prioritization, delayed remediation of \ncritical security issues, increasing + the risk of exploitation and potential damage to the organization." + measure: "Defining the protection requirement and the corresponding handling + of vulnerabilities per severity for components like applications are aligned + to SLAs. \n This is performed for the hole organization and doesn't need to + be broken down (yet) on team/product/application. \n At least quarterly." + description: |- + The protection requirements for an application should consider: + - Data criticality + - Application accessibility (internal vs. external) + - Regulatory compliance + - Other relevant factors difficultyOfImplementation: knowledge: 2 time: 2 - resources: 1 - usefulness: 4 - level: 1 - comments: False positive analysis, specially for static analysis, is time consuming. + resources: 2 + usefulness: 3 + level: 3 + dependsOn: [] + implementation: + - uuid: 227d786c-dd76-4b81-b0b2-62389ab8f0fb + name: OWASP DefectDojo + tags: + - vulnerability management system + - owasp + url: https://github.com/DefectDojo/django-DefectDojo + description: | + DefectDojo is a security program and vulnerability management tool. DefectDojo allows you to manage your application security program, maintain product and application information, triage vulnerabilities and push findings into defect trackers. Consolidate your findings into one source of truth with DefectDojo. + - uuid: d2eb592d-c9b5-4c39-bff7-bb313a58e3a9 + name: Purify + tags: + - vulnerability management system + url: https://github.com/faloker/purify/ + description: | + The goal of Purify to be an easy-in-use and efficient tool to simplify a workflow of managing vulnerabilities delivered from various (even custom) tools. + - uuid: 3b99799c-e875-4cc2-aad7-5ce4564a1cde + name: Business friendly vulnerability management metrics + url: https://medium.com/uber-security-privacy/business-friendly-vulnerability-management-metrics-cfd702fd7705 + test-url-expects: + - 403 + tags: + - documentation + - vulnerability + - vulnerability management system + - uuid: 7ec30b0e-9681-427a-80ee-ab811d9e476f + name: DefectDojo Client + tags: + - Defectdojo + - statistics + url: https://github.com/SDA-SE/defectdojo-client + description: | + This projects contains the DefectDojo upload client and statistics client. It is for example used within the ClusterImageScanner. references: samm2: - - I-DM-2-B - iso27001-2017: - - 16.1.4 - - 12.6.1 + - I-DM-A-2 iso27001-2022: - - 8.8 - 5.25 - implementation: [] - isImplemented: false - evidence: "" + - 5.12 + - 5.13 + - 5.1 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Consolidation/subsection/Treatment%20of%20defects%20per%20protection%20requirement tags: - - none - Treatment of defects with severity middle: + - vulnerability-mgmt + - metrics + - vmm-measurements + Treatment of defects with medium severity: uuid: 9cac3341-fe83-4079-bef2-bfc4279eb594 risk: Vulnerabilities with severity middle are not visible. measure: Vulnerabilities with severity middle are added to the quality gate. @@ -5810,31 +6196,94 @@ Test and Verification: comments: False positive analysis, specially for static analysis, is time consuming. references: samm2: - - I-DM-2-B + - I-DM-A-2 iso27001-2017: - 16.1.4 - 12.6.1 iso27001-2022: - 8.8 - 5.25 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Consolidation/subsection/Treatment%20of%20defects%20with%20medium%20severity implementation: [] - isImplemented: false - evidence: "" tags: - - none + - vuln-action + - defect-management Usage of a vulnerability management system: uuid: 85ba5623-84be-4219-8892-808837be582d risk: Maintenance of false positives in each tool enforces a high workload. In addition a correlation of the same finding from different tools is not possible. - measure: Aggregation of vulnerabilities in one tool reduce the workload to mark - false positives. + measure: Aggregation of vulnerabilities in one tool reduce the workload to handle + them, e.g. mark as false positives. difficultyOfImplementation: knowledge: 3 time: 3 resources: 2 usefulness: 2 + dependsOn: + - f2f0f274-c1a0-4501-92fe-7fc4452bc8ad # Exploit likelihood estimation + - 6217fe11-5ed7-4cf4-9de4-555bcfa6fe87 # Each team has a security champion + - 185d5a74-19dc-4422-be07-44ea35226783 # Office Hours level: 3 + description: "For known vulnerabilities a processes to estimate the exploit + ability of a vulnerability is recommended.\n\nTo implement a security culture + including training, office hours and security champions can help integrating + \nsecurity scanning at scale. Such activities help to understand why a vulnerability + is potentially critical and needs handling." + implementation: + - uuid: 227d786c-dd76-4b81-b0b2-62389ab8f0fb + name: OWASP DefectDojo + tags: + - vulnerability management system + - owasp + url: https://github.com/DefectDojo/django-DefectDojo + description: | + DefectDojo is a security program and vulnerability management tool. DefectDojo allows you to manage your application security program, maintain product and application information, triage vulnerabilities and push findings into defect trackers. Consolidate your findings into one source of truth with DefectDojo. + - uuid: d2eb592d-c9b5-4c39-bff7-bb313a58e3a9 + name: Purify + tags: + - vulnerability management system + url: https://github.com/faloker/purify/ + description: | + The goal of Purify to be an easy-in-use and efficient tool to simplify a workflow of managing vulnerabilities delivered from various (even custom) tools. + - uuid: d899488c-5799-4df1-a14c-3bb92fec3ac3 + name: SecObserve + tags: + - vulnerability management system + url: https://github.com/SecObserve/SecObserve + description: | + SecObserve is an open source vulnerability and license management system for software development teams and cloud environments. It supports a variety of open source vulnerability scanners and integrates into CI/CD pipelines. + references: + samm2: + - I-DM-A-3 + iso27001-2017: + - 12.6.1 + - 16.1.3 + - 16.1.4 + - 16.1.5 + - 16.1.6 + iso27001-2022: + - 8.8 + - 6.8 + - 5.25 + - 5.26 + - 5.27 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Consolidation/subsection/Usage%20of%20a%20vulnerability%20management%20system + tags: + - none + Advanced visualization of defects: + uuid: 7a82020c-94d1-471c-bbd3-5f7fe7df4876 + risk: Correlation of the vulnerabilities of different tools to have an overview + of the the overall security level per component/project/team is not given. + measure: Findings are visualized per component/project/team. + difficultyOfImplementation: + knowledge: 2 + time: 4 + resources: 1 + usefulness: 2 + level: 4 implementation: - uuid: 227d786c-dd76-4b81-b0b2-62389ab8f0fb name: OWASP DefectDojo @@ -5851,92 +6300,211 @@ Test and Verification: url: https://github.com/faloker/purify/ description: | The goal of Purify to be an easy-in-use and efficient tool to simplify a workflow of managing vulnerabilities delivered from various (even custom) tools. + - uuid: 3b99799c-e875-4cc2-aad7-5ce4564a1cde + name: Business friendly vulnerability management metrics + url: https://medium.com/uber-security-privacy/business-friendly-vulnerability-management-metrics-cfd702fd7705 + test-url-expects: + - 403 + tags: + - documentation + - vulnerability + - vulnerability management system + references: + samm2: + - I-DM-A-3 + iso27001-2017: + - 16.1.4 + - 8.2.1 + - 8.2.2 + - 8.2.3 + iso27001-2022: + - 5.25 + - 5.12 + - 5.13 + - 5.1 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Consolidation/subsection/Advanced%20visualization%20of%20defects + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Reproducible defect tickets: + uuid: 27337442-e4b1-4e87-8dc9-ce86fbb79a39 + risk: Vulnerability descriptions are hard to understand by staff from operations + and development. + measure: Vulnerabilities include the test procedure to give the staff from operations + and development the ability to reproduce vulnerabilities. This enhances the + understanding of vulnerabilities and therefore the fix have a higher quality. + difficultyOfImplementation: + knowledge: 3 + time: 2 + resources: 2 + usefulness: 2 + level: 4 + implementation: [] + references: + samm2: + - I-DM-A-2 + iso27001-2017: + - 16.1.4 + - 8.2.1 + - 8.2.2 + - 8.2.3 + iso27001-2022: + - 5.25 + - 5.12 + - 5.13 + - 5.1 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Consolidation/subsection/Reproducible%20defect%20tickets + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Treatment of all defects: + uuid: b2f77606-3e6c-41e9-b72d-7c0b1d3d581d + risk: Vulnerabilities with severity low are not visible. + measure: All vulnerabilities are added to the quality gate. + difficultyOfImplementation: + knowledge: 3 + time: 4 + resources: 1 + usefulness: 2 + level: 5 + implementation: [] references: samm2: - - I-DM-1-B + - I-DM-A-2 iso27001-2017: - - 12.6.1 - - 16.1.3 - 16.1.4 - - 16.1.5 - - 16.1.6 + - 12.6.1 iso27001-2022: - 8.8 - - 6.8 - 5.25 - - 5.26 - - 5.27 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Consolidation/subsection/Treatment%20of%20all%20defects + tags: + - vuln-action + - defect-management + comments: "" + Dynamic depth for applications: + Coverage of client side dynamic components: + uuid: 9711f871-f79d-4573-8d4f-d2c98fd0d18e + risk: Parts of the service are not covered during the scan, because JavaScript + is not getting executed. Therefore, the coverage of client-side dynamic components + is limited, leading to potential security risks and undetected vulnerabilities. + measure: Usage of a spider which executes dynamic content like JavaScript, e.g. + via Selenium. + difficultyOfImplementation: + knowledge: 3 + time: 3 + resources: 1 + usefulness: 4 + level: 2 + dependsOn: + - 65a2d7d9-5441-46bf-a4e3-f76919857750 # Usage of different roles + references: + samm2: + - V-ST-A-2 + iso27001-2017: + - 14.2.3 + - 14.2.8 + iso27001-2022: + - 8.32 + - 8.29 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Dynamic%20depth%20for%20applications/subsection/Coverage%20of%20client%20side%20dynamic%20components + implementation: + - uuid: 6583fd5f-4314-4b39-9265-de72f861c8cb + name: Ajax Spider + tags: [] + url: https://www.zaproxy.org/docs/desktop/addons/ajax-spider/ isImplemented: false evidence: "" comments: "" tags: - none - Dynamic depth for applications: - Coverage analysis: - uuid: d0ba0be5-c573-405f-b905-b7a8f87a9cc7 - risk: Parts of the service are not still covered by tests. - measure: Check that there are no missing paths in the application with coverage-tools. + Simple Scan: + uuid: 07796811-37f9-467c-9ff2-48f346e77ff3 + risk: Deficient security tests are performed. Simple vulnerabilities are not + detected and missing security configurations (e.g. headers) are not set. Fast + feedback is not given. + measure: A simple scan is performed to get a security baseline. In case the + test is done in under 10 minutes, it should be part of the build and deployment + process. difficultyOfImplementation: - knowledge: 4 - time: 5 - resources: 3 - usefulness: 4 - level: 5 + knowledge: 2 + time: 2 + resources: 1 + usefulness: 1 + level: 2 + dependsOn: + - f6f7737f-25a9-4317-8de2-09bf59f29b5b # Defined build process implementation: - - uuid: 7063cf8c-cd98-480f-8ef7-11cf241d2366 - name: OWASP Code Pulse - tags: [] - url: https://www.owasp.org/index.php/OWASP_Code_Pulse - - uuid: f011de6e-ab7c-4ec7-af55-03427271ab32 - name: Coverage.py + - uuid: 42a87524-ec35-4de2-a30c-1a7c7d045801 + name: OWASP Zap tags: - - testing - - coverage - url: https://github.com/nedbat/coveragepy + - vulnerability + - scanner + url: https://github.com/zaproxy/zaproxy description: | - Code coverage measurement for Python + The OWASP Zed Attack Proxy (ZAP) is one of the world's most popular free security tools and is actively maintained by a dedicated international team of ... + - uuid: 83ae1e92-5eb9-4467-b3d3-fd2f96e6ab63 + name: Arachni + url: https://github.com/Arachni/arachni references: samm2: - - V-ST-2-A + - V-ST-A-1 iso27001-2017: - - not explicitly covered by ISO 27001 - too specific - - part of periodic review, PDCA + - 14.2.3 + - 14.2.8 iso27001-2022: - - ISO 27001:2022 mapping is missing + - 8.32 + - 8.29 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Dynamic%20depth%20for%20applications/subsection/Simple%20Scan isImplemented: false evidence: "" comments: "" tags: - none - Coverage of client side dynamic components: - uuid: 9711f871-f79d-4573-8d4f-d2c98fd0d18e - risk: Parts of the service are not covered during the scan, because JavaScript - is not getting executed. Therefore, the co - measure: Usage of a spider which executes dynamic content like JavaScript, e.g. - via Selenium. + Usage of different roles: + uuid: 65a2d7d9-5441-46bf-a4e3-f76919857750 + risk: Parts of the service are not covered during the scan, because a login + is not performed. + measure: Integration of authentication with all roles used in the service. difficultyOfImplementation: knowledge: 3 time: 3 resources: 1 - usefulness: 4 + usefulness: 2 level: 2 dependsOn: - - Usage of different roles + - 07796811-37f9-467c-9ff2-48f346e77ff3 # Simple Scan references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: + - not explicitly covered by ISO 27001 - too specific - 14.2.3 - 14.2.8 iso27001-2022: - 8.32 - 8.29 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Dynamic%20depth%20for%20applications/subsection/Usage%20of%20different%20roles implementation: - - uuid: 6583fd5f-4314-4b39-9265-de72f861c8cb - name: Ajax Spider - tags: [] - url: https://www.zaproxy.org/docs/desktop/addons/ajax-spider/ + - uuid: 7eb37566-02d5-4fff-8dcf-8fcd1c8197f3 + name: Zest + url: https://www.zaproxy.org/docs/desktop/addons/zest/ + tags: + - zap + description: | + Zest is an experimental specialized scripting language (also known as a domain-specific language) originally developed by the Mozilla security team and is intended to be used in web oriented security tools. isImplemented: false + assessment: For REST APIs, multiple OAuth2 scopes are used. evidence: "" comments: "" tags: @@ -5979,14 +6547,16 @@ Test and Verification: description: | Schemathesis is a tool for testing web applications and services by sending requests based on the Open API / Swagger schema. dependsOn: - - Usage of different roles + - 65a2d7d9-5441-46bf-a4e3-f76919857750 # Usage of different roles references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - not explicitly covered by ISO 27001 - too specific iso27001-2022: - ISO 27001:2022 mapping is missing + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Dynamic%20depth%20for%20applications/subsection/Coverage%20of%20hidden%20endpoints isImplemented: false evidence: "" comments: "" @@ -6006,14 +6576,16 @@ Test and Verification: usefulness: 4 level: 3 dependsOn: - - Usage of different roles + - 65a2d7d9-5441-46bf-a4e3-f76919857750 # Usage of different roles references: samm2: - - V-ST-2-A + - V-RT-B-1 iso27001-2017: - not explicitly covered by ISO 27001 - too specific iso27001-2022: - ISO 27001:2022 mapping is missing + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Dynamic%20depth%20for%20applications/subsection/Coverage%20of%20more%20input%20vectors implementation: - uuid: c9bbecf2-567b-4422-b29a-67b16385f32b name: Schemathesis @@ -6047,2279 +6619,19 @@ Test and Verification: tags: [] url: https://curl.se/ dependsOn: - - Usage of different roles - references: - samm2: - - V-ST-2-A - iso27001-2017: - - 14.2.8 - - 14.2.3 - iso27001-2022: - - 8.32 - - 8.29 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Coverage of service to service communication: - uuid: 22aab0ef-76ce-4b8c-979c-3699784330db - risk: Service to service communication is not covered. - measure: Service to service communication is dumped and checked. - difficultyOfImplementation: - knowledge: 4 - time: 5 - resources: 2 - usefulness: 3 - level: 5 - dependsOn: - - Simple Scan - references: - samm2: - - V-ST-2-A - iso27001-2017: - - 14.2.3 - - 14.2.8 - iso27001-2022: - - 8.32 - - 8.29 - implementation: - - argocd: - uuid: fdb0e7cc-d3dd-4a2b-9f45-7d403001294f - name: argoCD - tags: - - deployment - url: https://argo-cd.readthedocs.io/en/stable/ - signing-of-commits-protection: - uuid: 86c6bdba-73c0-4c99-bbda-81b85c9fe2a4 - name: Enforcement of commit signing - tags: - - signing - url: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/defining-the-mergeability-of-pull-requests/managing-a-branch-protection-rule - description: Usage of branch protection rules - signing-of-commits: - uuid: d6d755d3-b9f1-4942-a084-e62b266541df - name: Signing of commits - tags: - - signing - url: https://git-scm.com/book/en/v2/Git-Tools-Signing-Your-Work - description: Signing of commits in git - ci-cd-tools: - uuid: b4bfead3-5fb6-4dd0-ba44-5da713bd22e4 - name: CI/CD tools - tags: - - ci-cd - url: https://martinfowler.com/articles/continuousIntegration.html - description: CI/CD tools such as jenkins, gitlab-ci or github-actions - apimaturity: - uuid: 596cb528-8981-4723-bcc3-22c261f26114 - name: API Security Maturity Model for Authorization - tags: - - api - url: https://curity.io/resources/learn/the-api-security-maturity-model/ - container-technologi: - uuid: ed6b6340-6c7f-4e13-8937-f560d3f5db11 - name: Container technologies and orchestration like Docker, Kubernetes - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:ContainerOrchestrationSoftware/ - cwe25: - uuid: c77f7ecd-76de-4611-bd6d-5b249f910c39 - name: CWE Top 25 Most Dangerous Software Weaknesses - tags: - - documentation - - threat - url: https://cwe.mitre.org/top25/archive/2020/2020_cwe_top25.html - docker-content-trust: - uuid: ee81f93f-8230-4cfb-a132-ae4ec61cb8e6 - name: Docker Content Trust - tags: [] - url: https://docs.docker.com/engine/security/trust/ - in-toto: - uuid: 6e9d8c14-ba3b-4698-afc3-365b4ab6fb1f - name: in-toto - tags: [] - url: https://in-toto.github.io/ - a-complete-backup-of: - uuid: ba7348e5-1abf-4c7d-8fbc-49f99460930b - name: A complete backup of persisted data might be performed*. - tags: [] - a-point-in-time-reco: - uuid: 9af7624e-0729-4eeb-b257-ebaf65f70355 - name: A Point in Time Recovery for databases should be implemented. - tags: [] - blue-green-deploymen: - uuid: 4fb3d95c-07c0-4cbb-b396-5054aba751c2 - name: Blue/Green Deployments - tags: [] - url: https://martinfowler.com/bliki/BlueGreenDeployment.html - docker: - uuid: cc47b2e3-6ee5-4926-af3a-d418ef91c8ba - name: Docker - url: https://github.com/moby/moby - tags: [] - webserver: - uuid: a71ce8f8-fd4a-4240-8b46-64a6cdb5dfdb - name: Webserver - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:WebServer/ - rolling-update: - uuid: ee2eb94b-7204-40d8-97da-43c7b1296e2e - name: rolling update - tags: [] - kubernetes-admission: - uuid: 2a76300f-6b1f-4a51-b925-134c36b723af - name: Kubernetes Admission Controller can whitelist registries and/or whitelist - a signing key. - tags: [] - url: https://medium.com/slalom-technology/build-a-kubernetes-dynamic-admission-controller-for-container-registry-whitelisting-b46fe020e22d - dependabot: - uuid: d6292c7d-aab7-43d3-a7c6-1e443b5c1aa4 - name: dependabot - tags: - - auto-pr - - patching - url: https://dependabot.com/ - renovate: - uuid: 8228266e-e04f-40ba-94c8-bfadc5310920 - name: renovate - tags: - - auto-pr - - patching - url: https://github.com/renovatebot/renovate - jenkins: - uuid: 42ddb49f-48f2-4a3a-b76a-e73104ac6971 - name: Jenkins - tags: [] - url: https://www.jenkins.io/ - sample-concept-1: - uuid: 1a463242-b480-46f6-a912-b51ec1c1558d - name: "Sample concept: \n(1" - tags: [] - description: "Sample concept: \n(1) each container has a set lifetime and - is killed / replaced with a new container multiple times a day where you - have some form of a graceful replacement to ensure no (short) service - outage will occur to the end users. \n(2) twice a day a rebuild of images - is done. The rebuilds are put into a automated testing pipeline. If the - testing has no blocking issues the new images will be released for deployment - during the next \"restart\" of a container. What has to be done, is to - ensure the new containers are deployed in some canary deployment manner, - this will ensure that if (and only if) something buggy has been introduced - which breaks functionality the canary deployment will make sure the \"older - version\" is being used and not the buggy newer one." - distroless: - uuid: ef647044-b675-47d3-9720-3ebc144ef37b - name: Distroless - tags: [] - url: https://github.com/GoogleContainerTools/distroless - fedora-coreos: - uuid: be757cb3-63d6-4a63-9c4e-e10b746fd47a - name: Fedora CoreOS - tags: [] - url: https://getfedora.org/coreos - distroless-usage: - uuid: a92c4f8f-a918-406a-b1e5-70acfc0477bd - name: Distroless or Alpine - tags: [] - url: https://itnext.io/which-container-images-to-use-distroless-or-alpine-96e3dab43a22 - threat-modeling-play: - uuid: fd0f282b-a065-4464-beed-770c604a5f52 - name: Threat Modeling Playbook - tags: - - owasp - - defender - - threat-modeling - - whiteboard - url: https://github.com/Toreon/threat-model-playbook - owasp-samm: - uuid: b5eaf710-e05f-49e5-a649-13afde9aeb52 - name: OWASP SAMM - tags: - - threat-modeling - - owasp - - defender - url: https://owaspsamm.org/model/design/threat-assessment/stream-b/ - whiteboard: - uuid: c0533602-11b7-4838-93cc-a40556398163 - name: Whiteboard - tags: - - defender - - threat-modeling - - collaboration - - whiteboard - url: https://en.wikipedia.org/wiki/Whiteboard - miro-or-any-other-c: - uuid: 965c3814-b6df-4ead-a096-1ed78ce1c7c1 - name: Miro (or any other collaborative board) - tags: - - defender - - threat-modeling - - collaboration - - whiteboard - url: https://miro.com/ - draw-io: - uuid: 088794c4-3424-40d4-9084-4151587fc84d - name: Draw.io - tags: - - defender - - threat-modeling - - whiteboard - url: https://github.com/jgraph/drawio-desktop - threagile: - uuid: e8332407-5149-459e-a2fe-c5c78c7ec55c - name: Threagile - tags: - - threat-modeling - url: https://github.com/Threagile/threagile - don-t-forget-evil-u: - uuid: bb5b8988-021b-452a-a914-bd36887b6860 - name: '[Don''t Forget EVIL U' - tags: [] - url: https://www.owasp.org/index.php/Agile_Software_Development - description: '[Do not Forget EVIL User Stories](https://www.owasp.org/index.php/Agile_Software_Development:_Don%27t_Forget_EVIL_User_Stories) - and [Practical Security Stories and Security Tasks for Agile Development - Environments](http://safecode.org/publication/SAFECode_Agile_Dev_Security0712.pdf)' - libyear: - uuid: 2fff917f-205e-4eab-2e0e-1fab8c04bf33 - name: libyear - tags: - - patching - - build - url: https://libyear.com/ - description: A simple measure of software dependency freshness. It is a - single number telling you how up-to-date your dependencies are. - owasp-juice-shop: - uuid: 1fff917f-205e-4eab-ae0e-1fab8c04bf3a - name: OWASP Juice Shop - tags: - - training - url: https://github.com/bkimminich/juice-shop - description: In case you do not have the budget to hire an external security - expert, an option is to use the OWASP JuiceShop on a "hacking Friday" - owasp-cheatsheet-ser: - uuid: 1c3f2f7a-5031-4687-9d69-76c5178c74e1 - name: OWASP Cheatsheet Series - tags: - - secure coding - url: https://cheatsheetseries.owasp.org/ - owasp-juiceshop: - uuid: 81476121-67dd-4ba9-a67b-e78a23050c28 - name: OWASP JuiceShop - tags: [] - url: https://github.com/bkimminich/juice-shop - description: |- - In case you do not have the budget to hire an external security expert, an option - is to use the [OWASP JuiceShop](https://github.com/bkimminich/juice-shop) on a "hacking Friday" - https-cheatsheetse: - uuid: 99080ac7-60cd-46af-93a1-a53a33597cba - name: https://cheatsheetseries.owasp.org/ - tags: - - training - - secure coding - url: https://cheatsheetseries.owasp.org/ - owasp-security-champ: - uuid: c191a515-3c10-4903-a889-70c8021f2ea1 - name: OWASP Security Champions Playbook - tags: - - security champions - url: https://github.com/c0rdis/security-champions-playbook - build-it-break-it-fi: - uuid: 8d4c1849-f310-4c42-8148-2810b382bc6f - name: Build it Break it Fix it Contest - tags: [] - url: https://builditbreakit.org/ - motivate-people: - uuid: 8e1b4a8a-c53b-4b1e-90f6-c60b7e225098 - name: Motivate people - tags: - - security champions - - gamification - - nudging - url: https://github.com/wurstbrot/security-pins - description: |- - Enhance motivation can be performed with the distribution of pins - as a reward, see [OWASP Security Pins Project](https://github.com/wurstbrot/security-pins) - owasp-top-10-maturit: - uuid: 22b63bdb-2003-4ac0-969d-b1e5268c2510 - name: OWASP Top 10 Maturity Categories for Security Champions - tags: - - security champions - url: https://owaspsamm.org/presentations/OWASP_Top_10_Maturity_Categories_for_Security_Champions.pptx - involve-security-sme: - uuid: 8a044b74-17f2-4ffa-9dee-6b3bb6e4baf3 - name: Involve Security SME - tags: [] - description: Security SME are involved in discussion for requirements analysis, - software design and sprint planning to provide guidance and suggestions. - damn-vulnerable-web: - uuid: a8cd9acb-ad22-44d6-b177-1154c65a8529 - name: Damn Vulnerable Web Application - tags: - - training - description: Simple Application with intended vulnerabilities. HTML based. - example-all-docker: - uuid: 349cf64c-abea-40bb-bd07-9c98ce648fa4 - name: 'Example: All docker images used by teams need to be based on standard - images.' - tags: [] - owasp-asvs: - uuid: 88767cde-1610-402e-98ec-bc3575377183 - name: OWASP ASVS - tags: [] - url: https://owasp.org/www-project-application-security-verification-standard/ - owasp-masvs: - uuid: 7bf90650-a53a-4581-a214-1afd5de3a059 - name: OWASP MASVS - tags: [] - url: https://github.com/OWASP/owasp-masvs - cis-kubernetes-bench: - uuid: edaec98d-dac7-4dfd-8ab3-42c471d5b9ff - name: CIS Kubernetes Bench for Security - tags: [] - url: https://www.cisecurity.org/cis-benchmarks/ - cis-docker-bench-for: - uuid: 4dd23c4a-5a7e-4917-82cf-d00e0f04482f - name: CIS Docker Bench for Security - tags: [] - url: https://www.cisecurity.org/cis-benchmarks/ - for-example-for-cont: - uuid: f4d7c796-8574-4a88-ab00-98d245a115ef - name: For example for Cont - tags: [] - description: 'For example for Containers: Deny running containers as root, - deny using advanced privileges, deny mounting of the hole filesystem, - ...' - url: https://d3fend.mitre.org/technique/d3f:ExecutionIsolation/ - attack-matrix-cloud: - uuid: 3b7df373-2ad9-456e-9abe-439cdc9d4d8b - name: Attack Matrix Cloud - tags: - - mitre - url: https://attack.mitre.org/matrices/enterprise/cloud/ - description: Attack matrix for cloud - attack-matrix-contai: - uuid: 59881520-4c69-4922-a44e-99044a77de2b - name: Attack Matrix Containers - tags: - - mitre - url: https://attack.mitre.org/matrices/enterprise/cloud/ - description: Attack matrix for containers - attack-matrix-kubern: - uuid: 9fbc47ad-82bc-46d1-bba9-66815ab79935 - name: Attack Matrix Kubernetes - tags: - - mitre - url: https://www.microsoft.com/security/blog/2020/04/02/attack-matrix-kubernetes/ - description: Attack matrix for kubernetes - istio: - uuid: 9429d52c-203d-49ae-814f-1401210887cd - name: istio - tags: [] - url: https://istio.io/ - bridges: - uuid: fc0eda30-2bf7-466f-948e-e17584db9f30 - name: bridges - tags: [] - firewalls: - uuid: e3c6fb92-3f7d-471f-9308-c62359f4f1b7 - name: firewalls - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:Firewall/ - open-policy-agent: - uuid: 4a024319-4510-4a53-a8b6-8f35b6c01867 - name: Open Policy Agent - tags: [] - url: https://www.openpolicyagent.org/ - gitops: - uuid: b0931397-2402-44f1-814b-63292ab4a339 - name: GitOps - tags: [] - url: https://www.redhat.com/en/topics/devops/what-is-gitops - ansible: - uuid: 73747d35-2185-4f22-94a0-723288fa283c - name: Ansible - tags: [] - url: https://github.com/ansible/ansible - chef: - uuid: 691c443f-b6e2-498d-94dc-778d8d51cfce - name: Chef - tags: [] - url: https://github.com/chef/chef - puppet: - uuid: eb7f76a8-87e5-4394-af4c-c09487c85982 - name: Puppet - tags: [] - url: https://github.com/puppetlabs/puppet - jenkinsfile: - uuid: 321dcfe4-d2fc-4dd2-85bf-aac563958458 - name: Jenkinsfile - tags: [] - url: https://www.jenkins.io/doc/book/pipeline/jenkinsfile/ - seccomp: - uuid: 0cc7e68b-f7d9-4e66-8065-47d076129ffd - name: seccomp - tags: [] - url: https://man7.org/linux/man-pages/man2/seccomp.2.html - strace: - uuid: 73ab2e3d-11a7-459d-8b57-9337662bd1ff - name: strace - tags: [] - url: https://man7.org/linux/man-pages/man1/strace.1.html - remove-direct-access: - uuid: b206481f-9c66-45e2-843c-37c5730580cd - name: Remove direct access to infrastructure - tags: [] - directory-service: - uuid: 04edc63e-d389-48dd-b365-552aaf4ea004 - name: Directory Service - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:DirectoryService/ - plugins: - uuid: cc55cba1-ea0a-466e-99c5-337c9da2b00e - name: Plugins - tags: [] - smartcard: - uuid: e76a395a-8d6a-4e25-a175-6cf25409b755 - name: Smartcard - tags: [] - url: https://d3fend.mitre.org/technique/d3f:Multi-factorAuthentication/ - yubikey: - uuid: d5981117-9bc2-45ed-b4a4-383135dc13d8 - name: YubiKey - tags: [] - url: https://d3fend.mitre.org/technique/d3f:Multi-factorAuthentication/ - sms: - uuid: 6151cfb3-c894-421e-83da-cac0b2bfaec8 - name: SMS - tags: [] - totp: - uuid: f69f5d03-691f-4e14-8fbc-ad66e2e5a12d - name: TOTP - tags: [] - url: https://d3fend.mitre.org/technique/d3f:One-timePassword/ - http-basic-authentic: - uuid: 41fda224-2980-443c-bfd4-0a1d4b520cb9 - name: HTTP-Basic Authentication - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:WebAuthentication/ - vpn: - uuid: e506f60b-747b-44b1-8fe8-f67ccd8f290e - name: VPN - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:VPN/ - for-applications-ch: - uuid: d7fb1f5a-05e3-49f7-ae67-00bfb8f8410c - name: 'For applications: Check default encoding' - tags: [] - managing-secrets: - uuid: 7e744f11-976e-46b6-88d4-f39b2965dfaf - name: managing secrets - tags: [] - url: https://d3fend.mitre.org/technique/d3f:CredentialHardening/ - crypto: - uuid: 520517ef-2911-4efc-8e1b-dcc9389aca45 - name: crypto - tags: [] - authentication: - uuid: ba6bd46c-2069-4f4d-b26c-7334a7553339 - name: authentication - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:Authentication/ - rsyslog: - uuid: 79f88310-d63e-471d-8e63-8c77f2281b66 - name: rsyslog - url: https://www.rsyslog.com/ - tags: - - tool - - logging - logstash: - uuid: 7a8fad2e-d642-4972-8501-74591b23feab - name: logstash - url: https://www.elastic.co/guide/en/logstash/current/getting-started-with-logstash.html - tags: - - tool - - logging - fluentd: - uuid: f5da3a20-ab64-4ecf-b4e1-660c80036e45 - name: fluentd - tags: - - tool - url: https://www.fluentd.org/ - bash: - uuid: 6226f8bc-2f6e-45c2-9232-98d2027e4531 - name: bash - tags: - - tool - url: https://www.gnu.org/software/bash/ - owasp-logging-cheats: - uuid: 5a5c7d99-41e8-454a-86ae-a638c9787d8c - name: OWASP Logging CheatSheet - url: https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html - tags: - - logging - - documentation - elk-stack: - uuid: 38fe9d00-df8b-44b6-910d-ca0f02b5c5d3 - name: ELK-Stack - tags: [] - url: https://www.elastic.co/elk-stack - https-ht-transpare: - uuid: 84ef86ea-ada4-4e10-ae4f-a5bb77dcae5d - name: https://ht.transpare - tags: [] - url: https://ht.transparencytoolkit.org/FileServer/FileServer/OLD - description: https://ht.transparencytoolkit.org/FileServer/FileServer/OLD%20Fileserver/books/SICUREZZA/Addison.Wesley.Security.Metrics.Mar.2007.pdf - prometheus: - uuid: ddf221df-3517-42e4-b23d-c1d9a162744c - name: Prometheus - tags: [] - url: https://prometheus.io/ - collected: - uuid: 73f6a52c-4fc2-45dc-991b-d5911b6c1ef8 - name: collected - tags: [] - httpunit: - uuid: 3bd40005-f180-4b95-907d-ec5b58ac1f20 - name: HttpUnit - tags: [] - url: http://httpunit.sourceforge.net/ - junit: - uuid: cc2eec82-f3a7-4ae5-9ccb-3d75352b2e4d - name: JUnit - tags: - - unittest - url: https://junit.org/junit5/ - karma: - uuid: fd56720a-ad4b-487c-b4c3-897a688672c4 - name: Karma - tags: [] - url: https://karma-runner.github.io - owasp-defectdojo: - uuid: 227d786c-dd76-4b81-b0b2-62389ab8f0fb - name: OWASP DefectDojo - tags: - - vulnerability management system - - owasp - url: https://github.com/DefectDojo/django-DefectDojo - description: | - DefectDojo is a security program and vulnerability management tool. DefectDojo allows you to manage your application security program, maintain product and application information, triage vulnerabilities and push findings into defect trackers. Consolidate your findings into one source of truth with DefectDojo. - purify: - uuid: d2eb592d-c9b5-4c39-bff7-bb313a58e3a9 - name: Purify - tags: - - vulnerability management system - url: https://github.com/faloker/purify/ - description: | - The goal of Purify to be an easy-in-use and efficient tool to simplify a workflow of managing vulnerabilities delivered from various (even custom) tools. - see-other-actions-e: - uuid: 44c08670-78dc-47ee-a4c1-2503ca6b6cf8 - name: See other actions, e.g. "Treatment of defects with severity high". - tags: [] - sast: - uuid: aaad322e-806e-4c51-b78d-6551f7dc376a - name: SAST - tags: [] - description: 'At SAST (Static Application Security Testing): Server-side - / client-side teams can easily be recorded. With microservice architecture - individual microservices can be used usually Teams.' - url: https://d3fend.mitre.org/dao/artifact/d3f:StaticAnalysisTool/ - dast: - uuid: 9d4bd377-11ec-4054-9c9e-9bfb99ac9609 - name: DAST - tags: [] - description: 'At DAST (Dynamic Application Security Testing): vulnerabilities - are classified and can be assigned to server-side and client-side teams.' - url: https://d3fend.mitre.org/dao/artifact/d3f:DynamicAnalysisTool/ - owasp-defect-dojo: - uuid: bb9d0f2d-f8bc-46b5-bbc7-7dbcf927191c - name: OWASP Defect Dojo - tags: [] - url: https://github.com/DefectDojo/django-DefectDojo - owasp-dependency-che: - uuid: 06334caf-8be6-487a-96b1-d41c7ed5f207 - name: OWASP Dependency Check - tags: - - OpenSource - - Supply Chain - - vulnerability - url: https://owasp.org/www-project-dependency-check/ - logparser-jenkins-pl: - uuid: ef80cd34-d3ba-4406-a4fa-4cf6f30c2e81 - name: LogParser Jenkins Plugins - tags: [] - owasp-code-pulse: - uuid: 7063cf8c-cd98-480f-8ef7-11cf241d2366 - name: OWASP Code Pulse - tags: [] - url: https://www.owasp.org/index.php/OWASP_Code_Pulse - ajax-spider: - uuid: 6583fd5f-4314-4b39-9265-de72f861c8cb - name: Ajax Spider - tags: [] - url: https://www.zaproxy.org/docs/desktop/addons/ajax-spider/ - curl: - uuid: f2a5f642-43b3-4b2c-97d5-b14d5964981b - name: cURL - tags: [] - url: https://curl.se/ - openapi: - uuid: 7ce77258-bf65-4e7a-9627-daf765ee1d77 - name: OpenAPI Specifications - tags: [] - url: https://spec.openapis.org/ - owasp-zap: - uuid: 42a87524-ec35-4de2-a30c-1a7c7d045801 - name: OWASP Zap - tags: - - vulnerability - - scanner - url: https://github.com/zaproxy/zaproxy - description: | - The OWASP Zed Attack Proxy (ZAP) is one of the world's most popular free security tools and is actively maintained by a dedicated international team of ... - arachni: - uuid: 83ae1e92-5eb9-4467-b3d3-fd2f96e6ab63 - name: Arachni - url: https://github.com/Arachni/arachni - zest: - uuid: 7eb37566-02d5-4fff-8dcf-8fcd1c8197f3 - name: Zest - url: https://www.zaproxy.org/docs/desktop/addons/zest/ - tags: - - zap - description: | - Zest is an experimental specialized scripting language (also known as a domain-specific language) originally developed by the Mozilla security team and is intended to be used in web oriented security tools. - owasp-securecodebox: - uuid: f220b299-0917-4750-96c5-d81cd402b4df - name: OWASP secureCodeBox - tags: - - vulnerability - - scanner-orchestration - url: https://github.com/secureCodeBox/secureCodeBox - description: | - secureCodeBox is a kubernetes based, modularized toolchain for continuous security scans of your software project. Its goal is to orchestrate and easily automate a bunch of security-testing tools out of the box. - kube-hunter: - uuid: 2af7204c-a25c-4625-9775-889978386407 - name: kube-hunter - tags: [] - url: https://github.com/aquasecurity/kube-hunter - openvas: - uuid: d45fba7d-f176-4f06-a33c-434b17ec8a8f - name: openVAS - tags: [] - url: https://www.openvas.org/ - htc-hydra: - uuid: b99c9d52-dd1a-4aef-8699-65173cf978ce - name: HTC Hydra - tags: - - password - url: https://www.htc-cs.com/en/products/htc-hydra/ - netassert: - uuid: fffa6fb9-1fae-4852-88dc-c7086961330c - name: netassert - tags: [] - url: https://github.com/controlplaneio/netassert - nmap: - uuid: 08111dc3-bdc4-47d8-8f2e-10bb50a86882 - name: nmap - tags: [] - url: https://nmap.org/ - owasp-amass: - uuid: f085295e-46a3-4c8d-bbc3-1ac6b9dfcf2a - name: OWASP Amass - tags: [] - url: https://github.com/OWASP/Amass - k8spurger: - uuid: 8fea20ad-e332-4aa8-b1f1-aa9deb635dc1 - name: K8sPurger - tags: - - vulnerability - - scanner - - dast - - infrastructure - url: https://github.com/yogeshkk/K8sPurger - description: | - Hunt Unused Resources In Kubernetes. - pmd: - uuid: 00702aca-04d9-49ca-90d0-c32c199b26cb - name: PMD - tags: [] - eslint: - uuid: 6a0948a7-4781-4858-9766-f4303971b28b - name: eslint - tags: [] - url: https://eslint.org/ - findsecuritybugs: - uuid: f911d2b4-3e0c-424c-acf9-3bd363ef5078 - name: FindSecurityBugs - tags: [] - jsprime: - uuid: cccc2882-62ab-4175-afa1-58471017e8ed - name: jsprime - tags: [] - url: https://github.com/dpnishant/jsprime - bdd-mobile-security: - uuid: 3a8ba0ea-37dc-4124-983b-bbf9b4443d75 - name: '[bdd-mobile-security' - tags: [] - url: https://github.com/ing-bank/bdd-mobile-security-automation-framework - description: '[bdd-mobile-security-automation-framework](https://github.com/ing-bank/bdd-mobile-security-automation-framework)' - retire-js: - uuid: aa54a82c-d628-4d42-9bc8-1aa269cd91c7 - name: retire.js - tags: [] - url: https://github.com/RetireJS/retire.js/ - npm-audit: - uuid: 7c26484a-763c-437d-b953-d482a4fd7cf3 - name: npm audit - tags: [] - url: https://docs.npmjs.com/cli/audit - sigmahq: - uuid: 1adf1ac0-8572-407b-a358-3976d9a225e2 - name: SigmaHQ - tags: [] - url: https://github.com/SigmaHQ/sigma - dive-to-inspect-a-co: - uuid: 73419fb5-b13d-4242-83ec-86f36c7d73d5 - name: Dive to inspect a container images - tags: [] - url: https://github.com/wagoodman/dive - clusterscanner: - url: https://github.com/SDA-SE/clusterscanner - uuid: 3c9ac78c-0fd4-43f4-8211-c915f9ef685f - name: ClusterScanner - tags: - - docker - - image - - container - - vulnerability - - misconfiguration - - security-tools - - scanning - description: Discover vulnerabilities and container image misconfiguration - in production environments. - dockerfile-with-hado: - uuid: 94d993ad-ef6e-4d9f-b7a8-27ea68dc3005 - name: Dockerfile with hadolint - tags: [] - url: https://github.com/hadolint/hadolint - deployment-with-kube: - uuid: 95b717cd-5ad3-40b5-993b-13a63c382b1b - name: Deployment with kube-score - tags: [] - url: https://github.com/zegl/kube-score - kubesec: - uuid: 1e58f8d2-61e2-45bb-a17c-51516d0cc9ba - name: kubesec - tags: [] - url: https://kubesec.io - anchore-io: - uuid: fab2765d-8d96-4fc6-af96-dc9304ca41dc - name: Anchore.io - tags: [] - url: https://anchore.com/ - clair: - uuid: f10f5423-4dff-4bb7-99c8-9ce214645071 - name: Clair - tags: [] - url: https://github.com/quay/clair - openscap: - uuid: d0c6b3a0-b073-44d7-a187-c4ad8eaa6531 - name: OpenSCAP - tags: [] - url: https://www.open-scap.org/ - vuls: - uuid: 04261564-2fcf-4b73-8847-83b0d855e1c5 - name: Vuls - tags: [] - url: https://github.com/future-architect/vuls - kube-bench: - uuid: 8aeefd29-6220-45bf-aead-83eba2e9d055 - name: kube-bench - tags: [] - url: https://github.com/aquasecurity/kube-bench - trufflehog: - uuid: d90fefc9-4e5d-420f-ac87-eeb165bf0ee6 - name: truffleHog - tags: [] - url: https://github.com/dxa4481/truffleHog - go-pillage-registrie: - uuid: 382873e2-8604-4410-ae5e-b0f5ccdee835 - name: go-pillage-registries - tags: [] - url: https://github.com/nccgroup/go-pillage-registries - https-github-com-a: - uuid: 7f500e95-2110-44c4-a1f8-cd7ef5d9eb6b - name: https://github.com/aquasecurity/trivy - tags: [] - url: https://github.com/aquasecurity/trivy - registries-like-quay: - uuid: 8737c6c0-4e90-400a-bf9a-f8e399913b57 - name: Registries like quay - tags: [] - description: Registries like quay, dockerhub provide (commercial) offerings, - often not suitable for distroless images - dockerfilelint: - uuid: eba2685d-2d25-4961-8e4e-2957e7c07c30 - name: dockerfilelint - tags: - - sast - - docker - - dockerfile - url: https://github.com/replicatedhq/dockerfilelint - description: dockerfilelint is an node module that analyzes a Dockerfile - and looks for common traps, mistakes and helps enforce best practices. - threat-matrix-for-storage: - uuid: 1c56dbea-e067-44e2-8d3b-0a1205a70617 - name: Threat Matrix for Storage - url: https://www.microsoft.com/security/blog/2021/04/08/threat-matrix-for-storage/ - tags: - - documentation - - storage - - cluster - - kubernetes - defend-the-core-kubernetes: - uuid: b7a92886-aec9-4bf4-94c4-07cc191a97af - name: Defend the core kubernetes security at every layer - url: https://thenewstack.io/defend-the-core-kubernetes-security-at-every-layer/ - tags: - - documentation - - cluster - - kubernetes - business-friendly-vulnerability-metrics: - uuid: 3b99799c-e875-4cc2-aad7-5ce4564a1cde - name: Business friendly vulnerability management metrics - url: https://medium.com/uber-security-privacy/business-friendly-vulnerability-management-metrics-cfd702fd7705 - tags: - - documentation - - vulnerability - - vulnerability management system - kubescape: - uuid: 893d9f37-2142-4490-996c-e43b55064d3d - name: kubescape - url: https://github.com/armosec/kubescape - tags: - - kubernetes - - vulnerability - - misconfiguration - description: _Testing if Kubernetes is deployed securely as defined in Kubernetes - Hardening Guidance by to NSA and CISA_ - azuredevops: - uuid: b1b88bc5-5a22-4888-a27b-acce3d9fe29a - name: Improve code quality with branch policies - url: https://docs.microsoft.com/en-us/azure/devops/repos/git/branch-policies?view=azure-devops - tags: - - source-code-protection - - scm - github-policies: - uuid: 99211481-de9c-4358-880e-628366416a27 - name: About protected branches - url: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/defining-the-mergeability-of-pull-requests/about-protected-branches - tags: - - source-code-protection - - scm - sonarqube: - uuid: aa5ded61-5380-4da6-9474-afc36a397682 - name: In-Depth Linting of Your TypeScript While Coding - url: https://blog.sonarsource.com/in-depth-linting-of-your-typescript-while-coding - tags: - - ide - - linting - stylecop: - uuid: 0b7ec352-0c36-4de1-8912-617fc6c608fe - name: How to enforce a consistent coding style in your projects - url: https://www.meziantou.net/how-to-enforce-a-consistent-coding-style-in-your-projects.htm - tags: - - ide - - linting - fortify-vscode-extension: - uuid: 5b52a841-c281-45fd-b68f-0a93aa6fa398 - name: Fortify Extension for Visual Studio Code - url: https://marketplace.visualstudio.com/items?itemName=fortifyvsts.fortify-extension-for-vs-code - tags: - - ide - - sast - appscan-vscode-extension: - uuid: 3f5a493d-12d0-4468-b9fa-c3e4eae89ffb - name: HCL AppScan CodeSweep - url: https://marketplace.visualstudio.com/items?itemName=HCLTechnologies.hclappscancodesweep - tags: - - ide - - sast - checkmarx-vscode-extension: - uuid: cf1213fd-8bfa-4a97-bf8b-937c93f31005 - name: Setting Up the Visual Studio Code Extension Plugin - url: https://checkmarx.atlassian.net/wiki/spaces/SD/pages/1759216424/Setting+Up+the+Visual+Studio+Code+Extension+Plugin - tags: - - ide - - sast - pre-commit-microsoft: - uuid: 58ac9dea-b6c7-4698-904e-df89a9451c82 - name: DevSecOps control Pre-commit - url: https://docs.microsoft.com/en-us/azure/cloud-adoption-framework/secure/devsecops-controls#plan-and-develop - tags: - - pre-commit - pre-commit-synopsis: - uuid: 8da8d115-0f4e-40f0-a3ce-484a49e845fb - name: Building your DevSecOps pipeline 5 essential activities - url: https://www.synopsys.com/blogs/software-security/devsecops-pipeline-checklist/ - tags: - - pre-commit - dependencyTrack: - uuid: 500399bd-7dfc-47fd-99d8-b55cefb760a9 - name: Dependency-Track is an intelligent Component Analysis platform that - allows organizations to identify and reduce risk in the software supply - chain. Dependency-Track takes a unique and highly beneficial approach - by leveraging the capabilities of Software Bill of Materials (SBOM). - url: https://github.com/DependencyTrack/dependency-track - tags: - - sca - - inventory - - OpenSource - - Supply Chain - - vulnerability - juice-shop: - uuid: c021aa72-c71c-43e4-9573-717b74d6c19d - name: OWASP Juice Shop - tags: - - training - url: https://github.com/bkimminich/juice-shop - description: In case you do not have the budget to hire an external security - expert, an option is to use the OWASP JuiceShop on a "hacking Friday" - dvwa: - uuid: e1282ab3-7ffd-4ee5-a564-8e9af070979d - name: Damn Vulnerable Web Application - tags: - - training - description: Simple Application with intended vulnerabilities. HTML based. - loggingCheatSheet: - uuid: 032ca7cc-67dc-46bc-9702-3580a3c9d1a9 - name: OWASP Logging CheatSheet - url: https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html - tags: - - logging - - documentation - zap: - uuid: 84a2a907-a6fb-4ceb-8e21-f65c0d633445 - name: OWASP Zap - tags: - - vulnerability - - scanner - url: https://github.com/zaproxy/zaproxy - description: | - The OWASP Zed Attack Proxy (ZAP) is one of the world's most popular free security tools and is actively maintained by a dedicated international team of ... - secureCodeBox: - uuid: dc0995a5-ff13-4cfc-b95f-07bf8a30b6ab - name: OWASP secureCodeBox - tags: - - vulnerability - - scanner-orchestration - url: https://github.com/secureCodeBox/secureCodeBox - description: | - secureCodeBox is a kubernetes based, modularized toolchain for continuous security scans of your software project. Its goal is to orchestrate and easily automate a bunch of security-testing tools out of the box. - K8sPurger: - uuid: 7a019f5e-a77d-4f4a-89a6-d5107054a2cb - name: K8sPurger - tags: - - vulnerability - - scanner - - dast - - infrastructure - url: https://github.com/yogeshkk/K8sPurger - description: | - Hunt Unused Resources In Kubernetes. - hashicorp-vault: - uuid: e3a2ffc8-313f-437e-9663-b24591568209 - name: Hashicorp Vault - tags: - - authentication - - authorization - - secrets - - infrastructure - url: https://github.com/hashicorp/vault - description: | - A tool for secrets management, encryption as a service, and privileged access management. - stoplight-spectral: - uuid: 261f243e-f89c-4169-b076-b22a03ec00be - name: Spectral - tags: - - linting - - api - - documentation - url: https://github.com/stoplightio/spectral - description: | - Spectral is a flexible JSON/YAML linter built with extensibility in mind. - It uses JSON/YAML path rules to describe the problems you want to find. - api-oas-checker: - uuid: d2c9403d-9da2-4518-b33f-8b74b9c5ca3f - name: API OAS Checker - tags: - - linting - - api - - documentation - url: https://github.com/italia/api-oas-checker - description: | - A tool to check OpenAPI specifications using a comprehensive ruleset based - on API best practices. - coveragepy: - uuid: f011de6e-ab7c-4ec7-af55-03427271ab32 - name: Coverage.py - tags: - - testing - - coverage - url: https://github.com/nedbat/coveragepy - description: | - Code coverage measurement for Python - github-dependabot: - uuid: 5c0e817b-204e-4301-a315-2f7cc180c240 - name: Dependabot - tags: - - dependency - - dependency-management - - scm - url: https://github.com/dependabot/dependabot-core - description: | - Dependabot creates pull requests to keep your dependencies secure and up-to-date. - github-super-linter: - uuid: 94a7a85e-8064-46b4-929a-9e03fa292a9f - name: Super-Linter - tags: - - linting - - scm - url: https://github.com/github/super-linter - description: | - Lint code bases to catch common errors and enforce code style - schemathesis: - uuid: c9bbecf2-567b-4422-b29a-67b16385f32b - name: Schemathesis - tags: - - testing - - api - - documentation - url: https://github.com/schemathesis/schemathesis - description: | - Schemathesis is a tool for testing web applications and services by sending requests based on the Open API / Swagger schema. - martin-feature-toggles: - uuid: 83be6c60-6633-4c32-98de-7ae065c143c9 - name: Feature Toggles - tags: - - development - - architecture - url: https://martinfowler.com/articles/feature-toggles.html - description: | - Feature Toggles are a powerful technique, allowing teams to modify system behavior without changing code. (Pete Hodgson) - defectdojo-client: - uuid: 7ec30b0e-9681-427a-80ee-ab811d9e476f - name: DefectDojo Client - tags: - - Defectdojo - - statistics - url: https://github.com/SDA-SE/defectdojo-client - description: | - This projects contains the DefectDojo upload client and statistics client. It is for example used within the ClusterImageScanner. - falco: - uuid: 32b64e6e-5187-45e3-b4f3-f5f9a9739012 - name: Falco - tags: - - falco - - systemcall - - monitoring - url: https://github.com/falcosecurity/falco - description: | - Falco makes it easy to consume kernel events, and enrich those events with information from Kubernetes and the rest of the cloud native stack. - sammancoaching: - uuid: 9223be73-00da-400e-a910-3871734cff2f - name: sammancoaching - tags: - - documentation - - coaching - - education - url: https://sammancoaching.org/ - description: | - Security coaches work with software development teams to help them adopt better security practices. - terraform: - uuid: 0d63f907-37fe-4375-88a5-a5e252732618 - name: terraform - tags: - - IaC - url: https://www.terraform.io/ - description: | - Terraform enables infrastructure automation for provisioning, compliance, and management of any cloud, datacenter, and service. - packj: - uuid: 5d8b27ac-286e-47a5-b23f-769eb6d74e4a - name: packj - tags: - - OpenSource - - Supply Chain - - vulnerability - url: https://github.com/ossillate-inc/packj - description: | - Packj is a tool to detect software supply chain attacks. It can detect malicious, vulnerable, abandoned, typo-squatting, and other "risky" packages from popular open-source package registries, such as NPM, RubyGems, and PyPI. - apiMyth: - uuid: 6150533e-58ca-4b52-a9b2-6226545d9ea0 - name: Top 5 API Security Myths That Are Crushing Your Business - tags: - - documentation - - waf - url: https://thehackernews.com/2022/11/top-5-api-security-myths-that-are.html - description: | - There are several myths and misconceptions about API security. These myths about securing APIs are crushing your business - - argocd: - uuid: fdb0e7cc-d3dd-4a2b-9f45-7d403001294f - name: argoCD - tags: - - deployment - url: https://argo-cd.readthedocs.io/en/stable/ - signing-of-commits-protection: - uuid: 86c6bdba-73c0-4c99-bbda-81b85c9fe2a4 - name: Enforcement of commit signing - tags: - - signing - url: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/defining-the-mergeability-of-pull-requests/managing-a-branch-protection-rule - description: Usage of branch protection rules - signing-of-commits: - uuid: d6d755d3-b9f1-4942-a084-e62b266541df - name: Signing of commits - tags: - - signing - url: https://git-scm.com/book/en/v2/Git-Tools-Signing-Your-Work - description: Signing of commits in git - ci-cd-tools: - uuid: b4bfead3-5fb6-4dd0-ba44-5da713bd22e4 - name: CI/CD tools - tags: - - ci-cd - url: https://martinfowler.com/articles/continuousIntegration.html - description: CI/CD tools such as jenkins, gitlab-ci or github-actions - apimaturity: - uuid: 596cb528-8981-4723-bcc3-22c261f26114 - name: API Security Maturity Model for Authorization - tags: - - api - url: https://curity.io/resources/learn/the-api-security-maturity-model/ - container-technologi: - uuid: ed6b6340-6c7f-4e13-8937-f560d3f5db11 - name: Container technologies and orchestration like Docker, Kubernetes - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:ContainerOrchestrationSoftware/ - cwe25: - uuid: c77f7ecd-76de-4611-bd6d-5b249f910c39 - name: CWE Top 25 Most Dangerous Software Weaknesses - tags: - - documentation - - threat - url: https://cwe.mitre.org/top25/archive/2020/2020_cwe_top25.html - docker-content-trust: - uuid: ee81f93f-8230-4cfb-a132-ae4ec61cb8e6 - name: Docker Content Trust - tags: [] - url: https://docs.docker.com/engine/security/trust/ - in-toto: - uuid: 6e9d8c14-ba3b-4698-afc3-365b4ab6fb1f - name: in-toto - tags: [] - url: https://in-toto.github.io/ - a-complete-backup-of: - uuid: ba7348e5-1abf-4c7d-8fbc-49f99460930b - name: A complete backup of persisted data might be performed*. - tags: [] - a-point-in-time-reco: - uuid: 9af7624e-0729-4eeb-b257-ebaf65f70355 - name: A Point in Time Recovery for databases should be implemented. - tags: [] - blue-green-deploymen: - uuid: 4fb3d95c-07c0-4cbb-b396-5054aba751c2 - name: Blue/Green Deployments - tags: [] - url: https://martinfowler.com/bliki/BlueGreenDeployment.html - docker: - uuid: cc47b2e3-6ee5-4926-af3a-d418ef91c8ba - name: Docker - url: https://github.com/moby/moby - tags: [] - webserver: - uuid: a71ce8f8-fd4a-4240-8b46-64a6cdb5dfdb - name: Webserver - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:WebServer/ - rolling-update: - uuid: ee2eb94b-7204-40d8-97da-43c7b1296e2e - name: rolling update - tags: [] - kubernetes-admission: - uuid: 2a76300f-6b1f-4a51-b925-134c36b723af - name: Kubernetes Admission Controller can whitelist registries and/or whitelist - a signing key. - tags: [] - url: https://medium.com/slalom-technology/build-a-kubernetes-dynamic-admission-controller-for-container-registry-whitelisting-b46fe020e22d - dependabot: - uuid: d6292c7d-aab7-43d3-a7c6-1e443b5c1aa4 - name: dependabot - tags: - - auto-pr - - patching - url: https://dependabot.com/ - renovate: - uuid: 8228266e-e04f-40ba-94c8-bfadc5310920 - name: renovate - tags: - - auto-pr - - patching - url: https://github.com/renovatebot/renovate - jenkins: - uuid: 42ddb49f-48f2-4a3a-b76a-e73104ac6971 - name: Jenkins - tags: [] - url: https://www.jenkins.io/ - sample-concept-1: - uuid: 1a463242-b480-46f6-a912-b51ec1c1558d - name: "Sample concept: \n(1" - tags: [] - description: "Sample concept: \n(1) each container has a set lifetime and - is killed / replaced with a new container multiple times a day where you - have some form of a graceful replacement to ensure no (short) service - outage will occur to the end users. \n(2) twice a day a rebuild of images - is done. The rebuilds are put into a automated testing pipeline. If the - testing has no blocking issues the new images will be released for deployment - during the next \"restart\" of a container. What has to be done, is to - ensure the new containers are deployed in some canary deployment manner, - this will ensure that if (and only if) something buggy has been introduced - which breaks functionality the canary deployment will make sure the \"older - version\" is being used and not the buggy newer one." - distroless: - uuid: ef647044-b675-47d3-9720-3ebc144ef37b - name: Distroless - tags: [] - url: https://github.com/GoogleContainerTools/distroless - fedora-coreos: - uuid: be757cb3-63d6-4a63-9c4e-e10b746fd47a - name: Fedora CoreOS - tags: [] - url: https://getfedora.org/coreos - distroless-usage: - uuid: a92c4f8f-a918-406a-b1e5-70acfc0477bd - name: Distroless or Alpine - tags: [] - url: https://itnext.io/which-container-images-to-use-distroless-or-alpine-96e3dab43a22 - threat-modeling-play: - uuid: fd0f282b-a065-4464-beed-770c604a5f52 - name: Threat Modeling Playbook - tags: - - owasp - - defender - - threat-modeling - - whiteboard - url: https://github.com/Toreon/threat-model-playbook - owasp-samm: - uuid: b5eaf710-e05f-49e5-a649-13afde9aeb52 - name: OWASP SAMM - tags: - - threat-modeling - - owasp - - defender - url: https://owaspsamm.org/model/design/threat-assessment/stream-b/ - whiteboard: - uuid: c0533602-11b7-4838-93cc-a40556398163 - name: Whiteboard - tags: - - defender - - threat-modeling - - collaboration - - whiteboard - url: https://en.wikipedia.org/wiki/Whiteboard - miro-or-any-other-c: - uuid: 965c3814-b6df-4ead-a096-1ed78ce1c7c1 - name: Miro (or any other collaborative board) - tags: - - defender - - threat-modeling - - collaboration - - whiteboard - url: https://miro.com/ - draw-io: - uuid: 088794c4-3424-40d4-9084-4151587fc84d - name: Draw.io - tags: - - defender - - threat-modeling - - whiteboard - url: https://github.com/jgraph/drawio-desktop - threagile: - uuid: e8332407-5149-459e-a2fe-c5c78c7ec55c - name: Threagile - tags: - - threat-modeling - url: https://github.com/Threagile/threagile - don-t-forget-evil-u: - uuid: bb5b8988-021b-452a-a914-bd36887b6860 - name: '[Don''t Forget EVIL U' - tags: [] - url: https://www.owasp.org/index.php/Agile_Software_Development - description: '[Do not Forget EVIL User Stories](https://www.owasp.org/index.php/Agile_Software_Development:_Don%27t_Forget_EVIL_User_Stories) - and [Practical Security Stories and Security Tasks for Agile Development - Environments](http://safecode.org/publication/SAFECode_Agile_Dev_Security0712.pdf)' - libyear: - uuid: 2fff917f-205e-4eab-2e0e-1fab8c04bf33 - name: libyear - tags: - - patching - - build - url: https://libyear.com/ - description: A simple measure of software dependency freshness. It is a - single number telling you how up-to-date your dependencies are. - owasp-juice-shop: - uuid: 1fff917f-205e-4eab-ae0e-1fab8c04bf3a - name: OWASP Juice Shop - tags: - - training - url: https://github.com/bkimminich/juice-shop - description: In case you do not have the budget to hire an external security - expert, an option is to use the OWASP JuiceShop on a "hacking Friday" - owasp-cheatsheet-ser: - uuid: 1c3f2f7a-5031-4687-9d69-76c5178c74e1 - name: OWASP Cheatsheet Series - tags: - - secure coding - url: https://cheatsheetseries.owasp.org/ - owasp-juiceshop: - uuid: 81476121-67dd-4ba9-a67b-e78a23050c28 - name: OWASP JuiceShop - tags: [] - url: https://github.com/bkimminich/juice-shop - description: |- - In case you do not have the budget to hire an external security expert, an option - is to use the [OWASP JuiceShop](https://github.com/bkimminich/juice-shop) on a "hacking Friday" - https-cheatsheetse: - uuid: 99080ac7-60cd-46af-93a1-a53a33597cba - name: https://cheatsheetseries.owasp.org/ - tags: - - training - - secure coding - url: https://cheatsheetseries.owasp.org/ - owasp-security-champ: - uuid: c191a515-3c10-4903-a889-70c8021f2ea1 - name: OWASP Security Champions Playbook - tags: - - security champions - url: https://github.com/c0rdis/security-champions-playbook - build-it-break-it-fi: - uuid: 8d4c1849-f310-4c42-8148-2810b382bc6f - name: Build it Break it Fix it Contest - tags: [] - url: https://builditbreakit.org/ - motivate-people: - uuid: 8e1b4a8a-c53b-4b1e-90f6-c60b7e225098 - name: Motivate people - tags: - - security champions - - gamification - - nudging - url: https://github.com/wurstbrot/security-pins - description: |- - Enhance motivation can be performed with the distribution of pins - as a reward, see [OWASP Security Pins Project](https://github.com/wurstbrot/security-pins) - owasp-top-10-maturit: - uuid: 22b63bdb-2003-4ac0-969d-b1e5268c2510 - name: OWASP Top 10 Maturity Categories for Security Champions - tags: - - security champions - url: https://owaspsamm.org/presentations/OWASP_Top_10_Maturity_Categories_for_Security_Champions.pptx - involve-security-sme: - uuid: 8a044b74-17f2-4ffa-9dee-6b3bb6e4baf3 - name: Involve Security SME - tags: [] - description: Security SME are involved in discussion for requirements analysis, - software design and sprint planning to provide guidance and suggestions. - damn-vulnerable-web: - uuid: a8cd9acb-ad22-44d6-b177-1154c65a8529 - name: Damn Vulnerable Web Application - tags: - - training - description: Simple Application with intended vulnerabilities. HTML based. - example-all-docker: - uuid: 349cf64c-abea-40bb-bd07-9c98ce648fa4 - name: 'Example: All docker images used by teams need to be based on standard - images.' - tags: [] - owasp-asvs: - uuid: 88767cde-1610-402e-98ec-bc3575377183 - name: OWASP ASVS - tags: [] - url: https://owasp.org/www-project-application-security-verification-standard/ - owasp-masvs: - uuid: 7bf90650-a53a-4581-a214-1afd5de3a059 - name: OWASP MASVS - tags: [] - url: https://github.com/OWASP/owasp-masvs - cis-kubernetes-bench: - uuid: edaec98d-dac7-4dfd-8ab3-42c471d5b9ff - name: CIS Kubernetes Bench for Security - tags: [] - url: https://www.cisecurity.org/cis-benchmarks/ - cis-docker-bench-for: - uuid: 4dd23c4a-5a7e-4917-82cf-d00e0f04482f - name: CIS Docker Bench for Security - tags: [] - url: https://www.cisecurity.org/cis-benchmarks/ - for-example-for-cont: - uuid: f4d7c796-8574-4a88-ab00-98d245a115ef - name: For example for Cont - tags: [] - description: 'For example for Containers: Deny running containers as root, - deny using advanced privileges, deny mounting of the hole filesystem, - ...' - url: https://d3fend.mitre.org/technique/d3f:ExecutionIsolation/ - attack-matrix-cloud: - uuid: 3b7df373-2ad9-456e-9abe-439cdc9d4d8b - name: Attack Matrix Cloud - tags: - - mitre - url: https://attack.mitre.org/matrices/enterprise/cloud/ - description: Attack matrix for cloud - attack-matrix-contai: - uuid: 59881520-4c69-4922-a44e-99044a77de2b - name: Attack Matrix Containers - tags: - - mitre - url: https://attack.mitre.org/matrices/enterprise/cloud/ - description: Attack matrix for containers - attack-matrix-kubern: - uuid: 9fbc47ad-82bc-46d1-bba9-66815ab79935 - name: Attack Matrix Kubernetes - tags: - - mitre - url: https://www.microsoft.com/security/blog/2020/04/02/attack-matrix-kubernetes/ - description: Attack matrix for kubernetes - istio: - uuid: 9429d52c-203d-49ae-814f-1401210887cd - name: istio - tags: [] - url: https://istio.io/ - bridges: - uuid: fc0eda30-2bf7-466f-948e-e17584db9f30 - name: bridges - tags: [] - firewalls: - uuid: e3c6fb92-3f7d-471f-9308-c62359f4f1b7 - name: firewalls - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:Firewall/ - open-policy-agent: - uuid: 4a024319-4510-4a53-a8b6-8f35b6c01867 - name: Open Policy Agent - tags: [] - url: https://www.openpolicyagent.org/ - gitops: - uuid: b0931397-2402-44f1-814b-63292ab4a339 - name: GitOps - tags: [] - url: https://www.redhat.com/en/topics/devops/what-is-gitops - ansible: - uuid: 73747d35-2185-4f22-94a0-723288fa283c - name: Ansible - tags: [] - url: https://github.com/ansible/ansible - chef: - uuid: 691c443f-b6e2-498d-94dc-778d8d51cfce - name: Chef - tags: [] - url: https://github.com/chef/chef - puppet: - uuid: eb7f76a8-87e5-4394-af4c-c09487c85982 - name: Puppet - tags: [] - url: https://github.com/puppetlabs/puppet - jenkinsfile: - uuid: 321dcfe4-d2fc-4dd2-85bf-aac563958458 - name: Jenkinsfile - tags: [] - url: https://www.jenkins.io/doc/book/pipeline/jenkinsfile/ - seccomp: - uuid: 0cc7e68b-f7d9-4e66-8065-47d076129ffd - name: seccomp - tags: [] - url: https://man7.org/linux/man-pages/man2/seccomp.2.html - strace: - uuid: 73ab2e3d-11a7-459d-8b57-9337662bd1ff - name: strace - tags: [] - url: https://man7.org/linux/man-pages/man1/strace.1.html - remove-direct-access: - uuid: b206481f-9c66-45e2-843c-37c5730580cd - name: Remove direct access to infrastructure - tags: [] - directory-service: - uuid: 04edc63e-d389-48dd-b365-552aaf4ea004 - name: Directory Service - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:DirectoryService/ - plugins: - uuid: cc55cba1-ea0a-466e-99c5-337c9da2b00e - name: Plugins - tags: [] - smartcard: - uuid: e76a395a-8d6a-4e25-a175-6cf25409b755 - name: Smartcard - tags: [] - url: https://d3fend.mitre.org/technique/d3f:Multi-factorAuthentication/ - yubikey: - uuid: d5981117-9bc2-45ed-b4a4-383135dc13d8 - name: YubiKey - tags: [] - url: https://d3fend.mitre.org/technique/d3f:Multi-factorAuthentication/ - sms: - uuid: 6151cfb3-c894-421e-83da-cac0b2bfaec8 - name: SMS - tags: [] - totp: - uuid: f69f5d03-691f-4e14-8fbc-ad66e2e5a12d - name: TOTP - tags: [] - url: https://d3fend.mitre.org/technique/d3f:One-timePassword/ - http-basic-authentic: - uuid: 41fda224-2980-443c-bfd4-0a1d4b520cb9 - name: HTTP-Basic Authentication - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:WebAuthentication/ - vpn: - uuid: e506f60b-747b-44b1-8fe8-f67ccd8f290e - name: VPN - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:VPN/ - for-applications-ch: - uuid: d7fb1f5a-05e3-49f7-ae67-00bfb8f8410c - name: 'For applications: Check default encoding' - tags: [] - managing-secrets: - uuid: 7e744f11-976e-46b6-88d4-f39b2965dfaf - name: managing secrets - tags: [] - url: https://d3fend.mitre.org/technique/d3f:CredentialHardening/ - crypto: - uuid: 520517ef-2911-4efc-8e1b-dcc9389aca45 - name: crypto - tags: [] - authentication: - uuid: ba6bd46c-2069-4f4d-b26c-7334a7553339 - name: authentication - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:Authentication/ - rsyslog: - uuid: 79f88310-d63e-471d-8e63-8c77f2281b66 - name: rsyslog - url: https://www.rsyslog.com/ - tags: - - tool - - logging - logstash: - uuid: 7a8fad2e-d642-4972-8501-74591b23feab - name: logstash - url: https://www.elastic.co/guide/en/logstash/current/getting-started-with-logstash.html - tags: - - tool - - logging - fluentd: - uuid: f5da3a20-ab64-4ecf-b4e1-660c80036e45 - name: fluentd - tags: - - tool - url: https://www.fluentd.org/ - bash: - uuid: 6226f8bc-2f6e-45c2-9232-98d2027e4531 - name: bash - tags: - - tool - url: https://www.gnu.org/software/bash/ - owasp-logging-cheats: - uuid: 5a5c7d99-41e8-454a-86ae-a638c9787d8c - name: OWASP Logging CheatSheet - url: https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html - tags: - - logging - - documentation - elk-stack: - uuid: 38fe9d00-df8b-44b6-910d-ca0f02b5c5d3 - name: ELK-Stack - tags: [] - url: https://www.elastic.co/elk-stack - https-ht-transpare: - uuid: 84ef86ea-ada4-4e10-ae4f-a5bb77dcae5d - name: https://ht.transpare - tags: [] - url: https://ht.transparencytoolkit.org/FileServer/FileServer/OLD - description: https://ht.transparencytoolkit.org/FileServer/FileServer/OLD%20Fileserver/books/SICUREZZA/Addison.Wesley.Security.Metrics.Mar.2007.pdf - prometheus: - uuid: ddf221df-3517-42e4-b23d-c1d9a162744c - name: Prometheus - tags: [] - url: https://prometheus.io/ - collected: - uuid: 73f6a52c-4fc2-45dc-991b-d5911b6c1ef8 - name: collected - tags: [] - httpunit: - uuid: 3bd40005-f180-4b95-907d-ec5b58ac1f20 - name: HttpUnit - tags: [] - url: http://httpunit.sourceforge.net/ - junit: - uuid: cc2eec82-f3a7-4ae5-9ccb-3d75352b2e4d - name: JUnit - tags: - - unittest - url: https://junit.org/junit5/ - karma: - uuid: fd56720a-ad4b-487c-b4c3-897a688672c4 - name: Karma - tags: [] - url: https://karma-runner.github.io - owasp-defectdojo: - uuid: 227d786c-dd76-4b81-b0b2-62389ab8f0fb - name: OWASP DefectDojo - tags: - - vulnerability management system - - owasp - url: https://github.com/DefectDojo/django-DefectDojo - description: | - DefectDojo is a security program and vulnerability management tool. DefectDojo allows you to manage your application security program, maintain product and application information, triage vulnerabilities and push findings into defect trackers. Consolidate your findings into one source of truth with DefectDojo. - purify: - uuid: d2eb592d-c9b5-4c39-bff7-bb313a58e3a9 - name: Purify - tags: - - vulnerability management system - url: https://github.com/faloker/purify/ - description: | - The goal of Purify to be an easy-in-use and efficient tool to simplify a workflow of managing vulnerabilities delivered from various (even custom) tools. - see-other-actions-e: - uuid: 44c08670-78dc-47ee-a4c1-2503ca6b6cf8 - name: See other actions, e.g. "Treatment of defects with severity high". - tags: [] - sast: - uuid: aaad322e-806e-4c51-b78d-6551f7dc376a - name: SAST - tags: [] - description: 'At SAST (Static Application Security Testing): Server-side - / client-side teams can easily be recorded. With microservice architecture - individual microservices can be used usually Teams.' - url: https://d3fend.mitre.org/dao/artifact/d3f:StaticAnalysisTool/ - dast: - uuid: 9d4bd377-11ec-4054-9c9e-9bfb99ac9609 - name: DAST - tags: [] - description: 'At DAST (Dynamic Application Security Testing): vulnerabilities - are classified and can be assigned to server-side and client-side teams.' - url: https://d3fend.mitre.org/dao/artifact/d3f:DynamicAnalysisTool/ - owasp-defect-dojo: - uuid: bb9d0f2d-f8bc-46b5-bbc7-7dbcf927191c - name: OWASP Defect Dojo - tags: [] - url: https://github.com/DefectDojo/django-DefectDojo - owasp-dependency-che: - uuid: 06334caf-8be6-487a-96b1-d41c7ed5f207 - name: OWASP Dependency Check - tags: - - OpenSource - - Supply Chain - - vulnerability - url: https://owasp.org/www-project-dependency-check/ - logparser-jenkins-pl: - uuid: ef80cd34-d3ba-4406-a4fa-4cf6f30c2e81 - name: LogParser Jenkins Plugins - tags: [] - owasp-code-pulse: - uuid: 7063cf8c-cd98-480f-8ef7-11cf241d2366 - name: OWASP Code Pulse - tags: [] - url: https://www.owasp.org/index.php/OWASP_Code_Pulse - ajax-spider: - uuid: 6583fd5f-4314-4b39-9265-de72f861c8cb - name: Ajax Spider - tags: [] - url: https://www.zaproxy.org/docs/desktop/addons/ajax-spider/ - curl: - uuid: f2a5f642-43b3-4b2c-97d5-b14d5964981b - name: cURL - tags: [] - url: https://curl.se/ - openapi: - uuid: 7ce77258-bf65-4e7a-9627-daf765ee1d77 - name: OpenAPI Specifications - tags: [] - url: https://spec.openapis.org/ - owasp-zap: - uuid: 42a87524-ec35-4de2-a30c-1a7c7d045801 - name: OWASP Zap - tags: - - vulnerability - - scanner - url: https://github.com/zaproxy/zaproxy - description: | - The OWASP Zed Attack Proxy (ZAP) is one of the world's most popular free security tools and is actively maintained by a dedicated international team of ... - arachni: - uuid: 83ae1e92-5eb9-4467-b3d3-fd2f96e6ab63 - name: Arachni - url: https://github.com/Arachni/arachni - zest: - uuid: 7eb37566-02d5-4fff-8dcf-8fcd1c8197f3 - name: Zest - url: https://www.zaproxy.org/docs/desktop/addons/zest/ - tags: - - zap - description: | - Zest is an experimental specialized scripting language (also known as a domain-specific language) originally developed by the Mozilla security team and is intended to be used in web oriented security tools. - owasp-securecodebox: - uuid: f220b299-0917-4750-96c5-d81cd402b4df - name: OWASP secureCodeBox - tags: - - vulnerability - - scanner-orchestration - url: https://github.com/secureCodeBox/secureCodeBox - description: | - secureCodeBox is a kubernetes based, modularized toolchain for continuous security scans of your software project. Its goal is to orchestrate and easily automate a bunch of security-testing tools out of the box. - kube-hunter: - uuid: 2af7204c-a25c-4625-9775-889978386407 - name: kube-hunter - tags: [] - url: https://github.com/aquasecurity/kube-hunter - openvas: - uuid: d45fba7d-f176-4f06-a33c-434b17ec8a8f - name: openVAS - tags: [] - url: https://www.openvas.org/ - htc-hydra: - uuid: b99c9d52-dd1a-4aef-8699-65173cf978ce - name: HTC Hydra - tags: - - password - url: https://www.htc-cs.com/en/products/htc-hydra/ - netassert: - uuid: fffa6fb9-1fae-4852-88dc-c7086961330c - name: netassert - tags: [] - url: https://github.com/controlplaneio/netassert - nmap: - uuid: 08111dc3-bdc4-47d8-8f2e-10bb50a86882 - name: nmap - tags: [] - url: https://nmap.org/ - owasp-amass: - uuid: f085295e-46a3-4c8d-bbc3-1ac6b9dfcf2a - name: OWASP Amass - tags: [] - url: https://github.com/OWASP/Amass - k8spurger: - uuid: 8fea20ad-e332-4aa8-b1f1-aa9deb635dc1 - name: K8sPurger - tags: - - vulnerability - - scanner - - dast - - infrastructure - url: https://github.com/yogeshkk/K8sPurger - description: | - Hunt Unused Resources In Kubernetes. - pmd: - uuid: 00702aca-04d9-49ca-90d0-c32c199b26cb - name: PMD - tags: [] - eslint: - uuid: 6a0948a7-4781-4858-9766-f4303971b28b - name: eslint - tags: [] - url: https://eslint.org/ - findsecuritybugs: - uuid: f911d2b4-3e0c-424c-acf9-3bd363ef5078 - name: FindSecurityBugs - tags: [] - jsprime: - uuid: cccc2882-62ab-4175-afa1-58471017e8ed - name: jsprime - tags: [] - url: https://github.com/dpnishant/jsprime - bdd-mobile-security: - uuid: 3a8ba0ea-37dc-4124-983b-bbf9b4443d75 - name: '[bdd-mobile-security' - tags: [] - url: https://github.com/ing-bank/bdd-mobile-security-automation-framework - description: '[bdd-mobile-security-automation-framework](https://github.com/ing-bank/bdd-mobile-security-automation-framework)' - retire-js: - uuid: aa54a82c-d628-4d42-9bc8-1aa269cd91c7 - name: retire.js - tags: [] - url: https://github.com/RetireJS/retire.js/ - npm-audit: - uuid: 7c26484a-763c-437d-b953-d482a4fd7cf3 - name: npm audit - tags: [] - url: https://docs.npmjs.com/cli/audit - sigmahq: - uuid: 1adf1ac0-8572-407b-a358-3976d9a225e2 - name: SigmaHQ - tags: [] - url: https://github.com/SigmaHQ/sigma - dive-to-inspect-a-co: - uuid: 73419fb5-b13d-4242-83ec-86f36c7d73d5 - name: Dive to inspect a container images - tags: [] - url: https://github.com/wagoodman/dive - clusterscanner: - url: https://github.com/SDA-SE/clusterscanner - uuid: 3c9ac78c-0fd4-43f4-8211-c915f9ef685f - name: ClusterScanner - tags: - - docker - - image - - container - - vulnerability - - misconfiguration - - security-tools - - scanning - description: Discover vulnerabilities and container image misconfiguration - in production environments. - dockerfile-with-hado: - uuid: 94d993ad-ef6e-4d9f-b7a8-27ea68dc3005 - name: Dockerfile with hadolint - tags: [] - url: https://github.com/hadolint/hadolint - deployment-with-kube: - uuid: 95b717cd-5ad3-40b5-993b-13a63c382b1b - name: Deployment with kube-score - tags: [] - url: https://github.com/zegl/kube-score - kubesec: - uuid: 1e58f8d2-61e2-45bb-a17c-51516d0cc9ba - name: kubesec - tags: [] - url: https://kubesec.io - anchore-io: - uuid: fab2765d-8d96-4fc6-af96-dc9304ca41dc - name: Anchore.io - tags: [] - url: https://anchore.com/ - clair: - uuid: f10f5423-4dff-4bb7-99c8-9ce214645071 - name: Clair - tags: [] - url: https://github.com/quay/clair - openscap: - uuid: d0c6b3a0-b073-44d7-a187-c4ad8eaa6531 - name: OpenSCAP - tags: [] - url: https://www.open-scap.org/ - vuls: - uuid: 04261564-2fcf-4b73-8847-83b0d855e1c5 - name: Vuls - tags: [] - url: https://github.com/future-architect/vuls - kube-bench: - uuid: 8aeefd29-6220-45bf-aead-83eba2e9d055 - name: kube-bench - tags: [] - url: https://github.com/aquasecurity/kube-bench - trufflehog: - uuid: d90fefc9-4e5d-420f-ac87-eeb165bf0ee6 - name: truffleHog - tags: [] - url: https://github.com/dxa4481/truffleHog - go-pillage-registrie: - uuid: 382873e2-8604-4410-ae5e-b0f5ccdee835 - name: go-pillage-registries - tags: [] - url: https://github.com/nccgroup/go-pillage-registries - https-github-com-a: - uuid: 7f500e95-2110-44c4-a1f8-cd7ef5d9eb6b - name: https://github.com/aquasecurity/trivy - tags: [] - url: https://github.com/aquasecurity/trivy - registries-like-quay: - uuid: 8737c6c0-4e90-400a-bf9a-f8e399913b57 - name: Registries like quay - tags: [] - description: Registries like quay, dockerhub provide (commercial) offerings, - often not suitable for distroless images - dockerfilelint: - uuid: eba2685d-2d25-4961-8e4e-2957e7c07c30 - name: dockerfilelint - tags: - - sast - - docker - - dockerfile - url: https://github.com/replicatedhq/dockerfilelint - description: dockerfilelint is an node module that analyzes a Dockerfile - and looks for common traps, mistakes and helps enforce best practices. - threat-matrix-for-storage: - uuid: 1c56dbea-e067-44e2-8d3b-0a1205a70617 - name: Threat Matrix for Storage - url: https://www.microsoft.com/security/blog/2021/04/08/threat-matrix-for-storage/ - tags: - - documentation - - storage - - cluster - - kubernetes - defend-the-core-kubernetes: - uuid: b7a92886-aec9-4bf4-94c4-07cc191a97af - name: Defend the core kubernetes security at every layer - url: https://thenewstack.io/defend-the-core-kubernetes-security-at-every-layer/ - tags: - - documentation - - cluster - - kubernetes - business-friendly-vulnerability-metrics: - uuid: 3b99799c-e875-4cc2-aad7-5ce4564a1cde - name: Business friendly vulnerability management metrics - url: https://medium.com/uber-security-privacy/business-friendly-vulnerability-management-metrics-cfd702fd7705 - tags: - - documentation - - vulnerability - - vulnerability management system - kubescape: - uuid: 893d9f37-2142-4490-996c-e43b55064d3d - name: kubescape - url: https://github.com/armosec/kubescape - tags: - - kubernetes - - vulnerability - - misconfiguration - description: _Testing if Kubernetes is deployed securely as defined in Kubernetes - Hardening Guidance by to NSA and CISA_ - azuredevops: - uuid: b1b88bc5-5a22-4888-a27b-acce3d9fe29a - name: Improve code quality with branch policies - url: https://docs.microsoft.com/en-us/azure/devops/repos/git/branch-policies?view=azure-devops - tags: - - source-code-protection - - scm - github-policies: - uuid: 99211481-de9c-4358-880e-628366416a27 - name: About protected branches - url: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/defining-the-mergeability-of-pull-requests/about-protected-branches - tags: - - source-code-protection - - scm - sonarqube: - uuid: aa5ded61-5380-4da6-9474-afc36a397682 - name: In-Depth Linting of Your TypeScript While Coding - url: https://blog.sonarsource.com/in-depth-linting-of-your-typescript-while-coding - tags: - - ide - - linting - stylecop: - uuid: 0b7ec352-0c36-4de1-8912-617fc6c608fe - name: How to enforce a consistent coding style in your projects - url: https://www.meziantou.net/how-to-enforce-a-consistent-coding-style-in-your-projects.htm - tags: - - ide - - linting - fortify-vscode-extension: - uuid: 5b52a841-c281-45fd-b68f-0a93aa6fa398 - name: Fortify Extension for Visual Studio Code - url: https://marketplace.visualstudio.com/items?itemName=fortifyvsts.fortify-extension-for-vs-code - tags: - - ide - - sast - appscan-vscode-extension: - uuid: 3f5a493d-12d0-4468-b9fa-c3e4eae89ffb - name: HCL AppScan CodeSweep - url: https://marketplace.visualstudio.com/items?itemName=HCLTechnologies.hclappscancodesweep - tags: - - ide - - sast - checkmarx-vscode-extension: - uuid: cf1213fd-8bfa-4a97-bf8b-937c93f31005 - name: Setting Up the Visual Studio Code Extension Plugin - url: https://checkmarx.atlassian.net/wiki/spaces/SD/pages/1759216424/Setting+Up+the+Visual+Studio+Code+Extension+Plugin - tags: - - ide - - sast - pre-commit-microsoft: - uuid: 58ac9dea-b6c7-4698-904e-df89a9451c82 - name: DevSecOps control Pre-commit - url: https://docs.microsoft.com/en-us/azure/cloud-adoption-framework/secure/devsecops-controls#plan-and-develop - tags: - - pre-commit - pre-commit-synopsis: - uuid: 8da8d115-0f4e-40f0-a3ce-484a49e845fb - name: Building your DevSecOps pipeline 5 essential activities - url: https://www.synopsys.com/blogs/software-security/devsecops-pipeline-checklist/ - tags: - - pre-commit - dependencyTrack: - uuid: 500399bd-7dfc-47fd-99d8-b55cefb760a9 - name: Dependency-Track is an intelligent Component Analysis platform that - allows organizations to identify and reduce risk in the software supply - chain. Dependency-Track takes a unique and highly beneficial approach - by leveraging the capabilities of Software Bill of Materials (SBOM). - url: https://github.com/DependencyTrack/dependency-track - tags: - - sca - - inventory - - OpenSource - - Supply Chain - - vulnerability - juice-shop: - uuid: c021aa72-c71c-43e4-9573-717b74d6c19d - name: OWASP Juice Shop - tags: - - training - url: https://github.com/bkimminich/juice-shop - description: In case you do not have the budget to hire an external security - expert, an option is to use the OWASP JuiceShop on a "hacking Friday" - dvwa: - uuid: e1282ab3-7ffd-4ee5-a564-8e9af070979d - name: Damn Vulnerable Web Application - tags: - - training - description: Simple Application with intended vulnerabilities. HTML based. - loggingCheatSheet: - uuid: 032ca7cc-67dc-46bc-9702-3580a3c9d1a9 - name: OWASP Logging CheatSheet - url: https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html - tags: - - logging - - documentation - zap: - uuid: 84a2a907-a6fb-4ceb-8e21-f65c0d633445 - name: OWASP Zap - tags: - - vulnerability - - scanner - url: https://github.com/zaproxy/zaproxy - description: | - The OWASP Zed Attack Proxy (ZAP) is one of the world's most popular free security tools and is actively maintained by a dedicated international team of ... - secureCodeBox: - uuid: dc0995a5-ff13-4cfc-b95f-07bf8a30b6ab - name: OWASP secureCodeBox - tags: - - vulnerability - - scanner-orchestration - url: https://github.com/secureCodeBox/secureCodeBox - description: | - secureCodeBox is a kubernetes based, modularized toolchain for continuous security scans of your software project. Its goal is to orchestrate and easily automate a bunch of security-testing tools out of the box. - K8sPurger: - uuid: 7a019f5e-a77d-4f4a-89a6-d5107054a2cb - name: K8sPurger - tags: - - vulnerability - - scanner - - dast - - infrastructure - url: https://github.com/yogeshkk/K8sPurger - description: | - Hunt Unused Resources In Kubernetes. - hashicorp-vault: - uuid: e3a2ffc8-313f-437e-9663-b24591568209 - name: Hashicorp Vault - tags: - - authentication - - authorization - - secrets - - infrastructure - url: https://github.com/hashicorp/vault - description: | - A tool for secrets management, encryption as a service, and privileged access management. - stoplight-spectral: - uuid: 261f243e-f89c-4169-b076-b22a03ec00be - name: Spectral - tags: - - linting - - api - - documentation - url: https://github.com/stoplightio/spectral - description: | - Spectral is a flexible JSON/YAML linter built with extensibility in mind. - It uses JSON/YAML path rules to describe the problems you want to find. - api-oas-checker: - uuid: d2c9403d-9da2-4518-b33f-8b74b9c5ca3f - name: API OAS Checker - tags: - - linting - - api - - documentation - url: https://github.com/italia/api-oas-checker - description: | - A tool to check OpenAPI specifications using a comprehensive ruleset based - on API best practices. - coveragepy: - uuid: f011de6e-ab7c-4ec7-af55-03427271ab32 - name: Coverage.py - tags: - - testing - - coverage - url: https://github.com/nedbat/coveragepy - description: | - Code coverage measurement for Python - github-dependabot: - uuid: 5c0e817b-204e-4301-a315-2f7cc180c240 - name: Dependabot - tags: - - dependency - - dependency-management - - scm - url: https://github.com/dependabot/dependabot-core - description: | - Dependabot creates pull requests to keep your dependencies secure and up-to-date. - github-super-linter: - uuid: 94a7a85e-8064-46b4-929a-9e03fa292a9f - name: Super-Linter - tags: - - linting - - scm - url: https://github.com/github/super-linter - description: | - Lint code bases to catch common errors and enforce code style - schemathesis: - uuid: c9bbecf2-567b-4422-b29a-67b16385f32b - name: Schemathesis - tags: - - testing - - api - - documentation - url: https://github.com/schemathesis/schemathesis - description: | - Schemathesis is a tool for testing web applications and services by sending requests based on the Open API / Swagger schema. - martin-feature-toggles: - uuid: 83be6c60-6633-4c32-98de-7ae065c143c9 - name: Feature Toggles - tags: - - development - - architecture - url: https://martinfowler.com/articles/feature-toggles.html - description: | - Feature Toggles are a powerful technique, allowing teams to modify system behavior without changing code. (Pete Hodgson) - defectdojo-client: - uuid: 7ec30b0e-9681-427a-80ee-ab811d9e476f - name: DefectDojo Client - tags: - - Defectdojo - - statistics - url: https://github.com/SDA-SE/defectdojo-client - description: | - This projects contains the DefectDojo upload client and statistics client. It is for example used within the ClusterImageScanner. - falco: - uuid: 32b64e6e-5187-45e3-b4f3-f5f9a9739012 - name: Falco - tags: - - falco - - systemcall - - monitoring - url: https://github.com/falcosecurity/falco - description: | - Falco makes it easy to consume kernel events, and enrich those events with information from Kubernetes and the rest of the cloud native stack. - sammancoaching: - uuid: 9223be73-00da-400e-a910-3871734cff2f - name: sammancoaching - tags: - - documentation - - coaching - - education - url: https://sammancoaching.org/ - description: | - Security coaches work with software development teams to help them adopt better security practices. - terraform: - uuid: 0d63f907-37fe-4375-88a5-a5e252732618 - name: terraform - tags: - - IaC - url: https://www.terraform.io/ - description: | - Terraform enables infrastructure automation for provisioning, compliance, and management of any cloud, datacenter, and service. - packj: - uuid: 5d8b27ac-286e-47a5-b23f-769eb6d74e4a - name: packj - tags: - - OpenSource - - Supply Chain - - vulnerability - url: https://github.com/ossillate-inc/packj - description: | - Packj is a tool to detect software supply chain attacks. It can detect malicious, vulnerable, abandoned, typo-squatting, and other "risky" packages from popular open-source package registries, such as NPM, RubyGems, and PyPI. - apiMyth: - uuid: 6150533e-58ca-4b52-a9b2-6226545d9ea0 - name: Top 5 API Security Myths That Are Crushing Your Business - tags: - - documentation - - waf - url: https://thehackernews.com/2022/11/top-5-api-security-myths-that-are.html - description: | - There are several myths and misconceptions about API security. These myths about securing APIs are crushing your business - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Simple Scan: - uuid: 07796811-37f9-467c-9ff2-48f346e77ff3 - risk: Deficient security tests are performed. Simple vulnerabilities are not - detected and missing security configurations (e.g. headers) are not set. Fast - feedback is not given. - measure: A simple scan is performed to get a security baseline. In case the - test is done in under 10 minutes, it should be part of the build and deployment - process. - difficultyOfImplementation: - knowledge: 2 - time: 2 - resources: 1 - usefulness: 1 - level: 2 - dependsOn: - - Defined build process - implementation: - - uuid: 42a87524-ec35-4de2-a30c-1a7c7d045801 - name: OWASP Zap - tags: - - vulnerability - - scanner - url: https://github.com/zaproxy/zaproxy - description: | - The OWASP Zed Attack Proxy (ZAP) is one of the world's most popular free security tools and is actively maintained by a dedicated international team of ... - - uuid: 83ae1e92-5eb9-4467-b3d3-fd2f96e6ab63 - name: Arachni - url: https://github.com/Arachni/arachni + - 65a2d7d9-5441-46bf-a4e3-f76919857750 # Usage of different roles references: samm2: - - V-ST-1-A + - V-ST-A-2 iso27001-2017: - - 14.2.3 - 14.2.8 - iso27001-2022: - - 8.32 - - 8.29 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Usage of different roles: - uuid: 65a2d7d9-5441-46bf-a4e3-f76919857750 - risk: Parts of the service are not covered during the scan, because a login - is not performed. - measure: Integration of authentication with all roles used in the service. - difficultyOfImplementation: - knowledge: 3 - time: 3 - resources: 1 - usefulness: 2 - level: 2 - dependsOn: - - Simple Scan - references: - samm2: - - V-ST-2-A - iso27001-2017: - - not explicitly covered by ISO 27001 - too specific - 14.2.3 - - 14.2.8 iso27001-2022: - 8.32 - 8.29 - implementation: - - uuid: 7eb37566-02d5-4fff-8dcf-8fcd1c8197f3 - name: Zest - url: https://www.zaproxy.org/docs/desktop/addons/zest/ - tags: - - zap - description: | - Zest is an experimental specialized scripting language (also known as a domain-specific language) originally developed by the Mozilla security team and is intended to be used in web oriented security tools. + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Dynamic%20depth%20for%20applications/subsection/Coverage%20of%20sequential%20operations isImplemented: false - assessment: For REST APIs, multiple OAuth2 scopes are used. evidence: "" comments: "" tags: @@ -8337,7 +6649,7 @@ Test and Verification: usefulness: 1 level: 4 dependsOn: - - Usage of different roles + - 65a2d7d9-5441-46bf-a4e3-f76919857750 # Usage of different roles implementation: - uuid: f220b299-0917-4750-96c5-d81cd402b4df name: OWASP secureCodeBox @@ -8349,48 +6661,96 @@ Test and Verification: secureCodeBox is a kubernetes based, modularized toolchain for continuous security scans of your software project. Its goal is to orchestrate and easily automate a bunch of security-testing tools out of the box. references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - 12.6.1 - 14.2.5 iso27001-2022: - - 8.8 - - 8.27 + - 8.8 + - 8.27 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Dynamic%20depth%20for%20applications/subsection/Usage%20of%20multiple%20scanners + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Coverage analysis: + uuid: d0ba0be5-c573-405f-b905-b7a8f87a9cc7 + risk: Parts of the service are not still covered by tests. + measure: Check that there are no missing paths in the application with coverage-tools. + difficultyOfImplementation: + knowledge: 4 + time: 5 + resources: 3 + usefulness: 4 + level: 5 + implementation: + - uuid: 7063cf8c-cd98-480f-8ef7-11cf241d2366 + name: OWASP Code Pulse + tags: [] + url: https://owasp.org/www-project-code-pulse/ + - uuid: f011de6e-ab7c-4ec7-af55-03427271ab32 + name: Coverage.py + tags: + - testing + - coverage + url: https://github.com/coveragepy/coveragepy + description: | + Code coverage measurement for Python + references: + samm2: + - V-ST-A-2 + iso27001-2017: + - not explicitly covered by ISO 27001 - too specific + - part of periodic review, PDCA + iso27001-2022: + - ISO 27001:2022 mapping is missing + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Dynamic%20depth%20for%20applications/subsection/Coverage%20analysis isImplemented: false evidence: "" comments: "" tags: - none - Dynamic depth for infrastructure: - Load tests: - uuid: ab5725aa-4d53-47b9-96df-c14b3fa93bcd - risk: As it is unknown how many requests the systems and applications can serve, - due to an unexpected load the availability is disturbed. - measure: Load test against the production system or a production near system - is performed. + Coverage of service to service communication: + uuid: 22aab0ef-76ce-4b8c-979c-3699784330db + risk: Service to service communication is not covered. + measure: Service to service communication is dumped and checked. difficultyOfImplementation: - knowledge: 3 - time: 2 - resources: 5 + knowledge: 4 + time: 5 + resources: 2 usefulness: 3 - level: 4 - implementation: [] + level: 5 + dependsOn: + - 07796811-37f9-467c-9ff2-48f346e77ff3 # Simple Scan references: samm2: - - V-ST-1-A + - V-ST-A-2 iso27001-2017: - - 12.1.3 - 14.2.3 - 14.2.8 iso27001-2022: - - 8.6 - 8.32 - 8.29 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Dynamic%20depth%20for%20applications/subsection/Coverage%20of%20service%20to%20service%20communication + implementation: + - uuid: 000b55f9-e6fd-4649-8290-27876a0409e2 + name: Citrus Fresh Integration Testing + tags: + - framework + - testing + url: https://citrusframework.org/ + description: Integration Test framework with focus on messaging applications + and Microservices. isImplemented: false evidence: "" comments: "" tags: - none + Dynamic depth for infrastructure: Test for exposed services: uuid: a6c4cefb-a0b7-4787-8cc7-a0f96b4b00d8 risk: Standard network segmentation and firewalling has not been performed, @@ -8404,7 +6764,7 @@ Test and Verification: time: 1 resources: 2 dependsOn: - - Isolated networks for virtual environments + - 4ce24abd-8ba6-494c-828d-4d193e28e4a1 # Isolated networks for virtual environments usefulness: 2 level: 2 implementation: @@ -8415,10 +6775,47 @@ Test and Verification: - uuid: f085295e-46a3-4c8d-bbc3-1ac6b9dfcf2a name: OWASP Amass tags: [] - url: https://github.com/OWASP/Amass + url: https://github.com/owasp-amass/amass + references: + samm2: + - V-ST-A-1 + iso27001-2017: + - 13.1.3 + - 14.2.3 + - 14.2.8 + iso27001-2022: + - 8.22 + - 8.32 + - 8.29 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Dynamic%20depth%20for%20infrastructure/subsection/Test%20for%20exposed%20services + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Test network segmentation: + uuid: 6d2c3ac6-8afc-4af6-a5e9-6188341aca01 + risk: Wrong or no network segmentation of pods makes it easier for an attacker + to access a database and extract or modify data. + measure: Cluster internal test needs to be performed. Integration of fine granulated + network segmentation (also between pods in the same namespace). + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 1 + usefulness: 3 + level: 2 + implementation: + - uuid: fffa6fb9-1fae-4852-88dc-c7086961330c + name: netassert + tags: [] + url: https://github.com/controlplaneio/netassert + dependsOn: + - 4ce24abd-8ba6-494c-828d-4d193e28e4a1 # Isolated networks for virtual environments references: samm2: - - V-ST-1-A + - V-ST-A-2 iso27001-2017: - 13.1.3 - 14.2.3 @@ -8427,6 +6824,55 @@ Test and Verification: - 8.22 - 8.32 - 8.29 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Dynamic%20depth%20for%20infrastructure/subsection/Test%20network%20segmentation + comments: "" + tags: + - none + Test of the configuration of cloud environments: + uuid: 7bb70764-9392-4462-935d-e55b2e148199 + risk: Standard hardening practices for cloud environments are not performed + leading to vulnerabilities. + measure: With the help of tools the configuration of virtual environments are + tested. + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 1 + usefulness: 4 + level: 2 + implementation: + - uuid: 893d9f37-2142-4490-996c-e43b55064d3d + name: kubescape + url: https://github.com/kubescape/kubescape + tags: + - kubernetes + - vulnerability + - misconfiguration + description: _Testing if Kubernetes is deployed securely as defined in Kubernetes + Hardening Guidance by to NSA and CISA_ + - uuid: 2af7204c-a25c-4625-9775-889978386407 + name: kube-hunter + tags: [] + url: https://github.com/aquasecurity/kube-hunter + - uuid: d45fba7d-f176-4f06-a33c-434b17ec8a8f + name: openVAS + tags: [] + url: https://www.openvas.org/ + references: + samm2: [] + iso27001-2017: + - System hardening is not explicitly covered by ISO 27001 - too specific + - 12.6.1 + - 14.2.3 + - 14.2.8 + iso27001-2022: + - System hardening is not explicitly covered by ISO 27001 - too specific + - 8.8 + - 8.32 + - 8.29 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Dynamic%20depth%20for%20infrastructure/subsection/Test%20of%20the%20configuration%20of%20cloud%20environments isImplemented: false evidence: "" comments: "" @@ -8459,10 +6905,75 @@ Test and Verification: iso27001-2022: - 8.19 - 8.8 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Dynamic%20depth%20for%20infrastructure/subsection/Test%20for%20unauthorized%20installation isImplemented: false evidence: "" dependsOn: - - Evaluation of the trust of used components + - 0de465a6-55a7-4343-af79-948bb5ff10ba # Evaluation of the trust of used components + tags: + - none + Weak password test: + uuid: 61e10f9c-e126-4ffa-af12-fdbe0d0a831f + risk: Weak passwords in components like applications or systems, specially for + privileged accounts, lead to take over of that account. + measure: Automatic brute force attacks are performed. Specially the usage of + standard accounts like 'admin' and employee user-ids is recommended. + difficultyOfImplementation: + knowledge: 2 + time: 1 + resources: 1 + usefulness: 1 + level: 3 + implementation: + - uuid: b99c9d52-dd1a-4aef-8699-65173cf978ce + name: HTC Hydra + tags: + - password + url: https://github.com/vanhauser-thc/thc-hydra + references: + samm2: + - V-ST-A-2 + iso27001-2017: + - 9.4.3 + iso27001-2022: + - 5.17 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Dynamic%20depth%20for%20infrastructure/subsection/Weak%20password%20test + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Load tests: + uuid: ab5725aa-4d53-47b9-96df-c14b3fa93bcd + risk: As it is unknown how many requests the systems and applications can serve, + due to an unexpected load the availability is disturbed. + measure: Load test against the production system or a production near system + is performed. + difficultyOfImplementation: + knowledge: 3 + time: 2 + resources: 5 + usefulness: 3 + level: 4 + implementation: [] + references: + samm2: + - V-RT-AB-1 + iso27001-2017: + - 12.1.3 + - 14.2.3 + - 14.2.8 + iso27001-2022: + - 8.6 + - 8.32 + - 8.29 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Dynamic%20depth%20for%20infrastructure/subsection/Load%20tests + isImplemented: false + evidence: "" + comments: "" tags: - none Test for unused Resources: @@ -8490,7 +7001,7 @@ Test and Verification: Hunt Unused Resources In Kubernetes. references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - 13.1.3 - 14.2.3 @@ -8499,124 +7010,225 @@ Test and Verification: - 8.22 - 8.32 - 8.29 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Dynamic%20depth%20for%20infrastructure/subsection/Test%20for%20unused%20Resources isImplemented: false evidence: "" comments: "" tags: - none - Test network segmentation: - uuid: 6d2c3ac6-8afc-4af6-a5e9-6188341aca01 - risk: Wrong or no network segmentation of pods makes it easier for an attacker - to access a database and extract or modify data. - measure: Cluster internal test needs to be performed. Integration of fine granulated - network segmentation (also between pods in the same namespace). + Static depth for applications: + Exploit likelihood estimation: + uuid: f2f0f274-c1a0-4501-92fe-7fc4452bc8ad + description: "Severity-based vulnerability triage alone generates a lot false + positives, requiring a more refined approach.\n\nUse the likelihood of exploitation + by using *known exploited vulnerabilities* (CISA KEV), or prediction models + such as \n*Exploit Prediction Scoring System* (EPSS).\n" + risk: | + Without proper prioritization, organizations may waste time and effort on low-risk vulnerabilities while neglecting critical ones. + measure: | + Use CISA KEV and EPSS to prioritize vulnerabilities that are more likely to be exploited. difficultyOfImplementation: knowledge: 2 time: 2 - resources: 1 - usefulness: 3 + resources: 2 + usefulness: 4 level: 2 - implementation: - - uuid: fffa6fb9-1fae-4852-88dc-c7086961330c - name: netassert - tags: [] - url: https://github.com/controlplaneio/netassert dependsOn: - - Segmented networks for virtual environments + - d918cd44-a972-43e9-a974-eff3f4a5dcfe # Software Composition Analysis (server side) + implementation: + - uuid: aa507341-9531-42cd-95cf-d7b51af47086 + name: Known Exploited Vulnerabilities + tags: + - vulnerability + url: https://www.cisa.gov/known-exploited-vulnerabilities-catalog + description: A catalog of vulnerabilities that have been exploited. + - uuid: e39afc58-8195-4600-92c6-11922e3a141b + name: Exploit Prediction Scoring System + tags: + - vulnerability + url: https://www.first.org/epss/ + description: Estimates the likelihood that a software vulnerability will be + exploited. references: samm2: - - V-ST-2-A + - V-ST-A-2 + - I-SB-B-3 iso27001-2017: - - 13.1.3 - - 14.2.3 - - 14.2.8 + - 12.6.1 iso27001-2022: - - 8.22 - - 8.32 - - 8.29 - isImplemented: false - evidence: "" - comments: "" + - 8.8 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20applications/subsection/Exploit%20likelihood%20estimation tags: - none - Test of the configuration of cloud environments: - uuid: 7bb70764-9392-4462-935d-e55b2e148199 - risk: Standard hardening practices for cloud environments are not performed - leading to vulnerabilities. - measure: With the help of tools the configuration of virtual environments are - tested. + Software Composition Analysis (server side): + uuid: d918cd44-a972-43e9-a974-eff3f4a5dcfe + description: Use a tool like trivy and concentrate on application related vulnerabilities. + At this stage, ignore vulnerabilities in container base images used in the + service. + risk: Server side components might have vulnerabilities. + measure: Tests for known vulnerabilities in server side components (e.g. backend/middleware) + are performed. + difficultyOfImplementation: + knowledge: 1 + time: 3 + resources: 1 + usefulness: 5 + level: 2 + dependsOn: + - f6f7737f-25a9-4317-8de2-09bf59f29b5b # Defined build process + - 2a44b708-734f-4463-b0cb-86dc46344b2f # Inventory of production components + implementation: + - uuid: 06334caf-8be6-487a-96b1-d41c7ed5f207 + name: OWASP Dependency Check + tags: + - OpenSource + - Supply Chain + - vulnerability + url: https://owasp.org/www-project-dependency-check/ + - uuid: 500399bd-7dfc-47fd-99d8-b55cefb760a9 + name: Dependency-Track + description: | + Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track takes a unique and highly beneficial approach by leveraging the capabilities of Software Bill of Materials (SBOM). + url: https://github.com/DependencyTrack/dependency-track + tags: + - sca + - inventory + - OpenSource + - Supply Chain + - vulnerability + - inventory + - uuid: aa54a82c-d628-4d42-9bc8-1aa269cd91c7 + name: retire.js + tags: [] + url: https://github.com/RetireJS/retire.js/ + - uuid: 7c26484a-763c-437d-b953-d482a4fd7cf3 + name: npm audit + tags: [] + url: https://docs.npmjs.com/cli/audit + test-url-expects: + - 301 + - uuid: 5c0e817b-204e-4301-a315-2f7cc180c240 + name: Dependabot + tags: + - dependency + - dependency-management + - scm + url: https://github.com/dependabot/dependabot-core + description: | + Dependabot creates pull requests to keep your dependencies secure and up-to-date. + - uuid: 7f500e95-2110-44c4-a1f8-cd7ef5d9eb6b + name: Trivy + tags: [] + url: https://github.com/aquasecurity/trivy + references: + samm2: + - V-ST-A-2 + - I-SB-B-2 + iso27001-2017: + - 12.6.1 + iso27001-2022: + - 8.8 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20applications/subsection/Software%20Composition%20Analysis%20%28server%20side%29 + tags: + - false-positive + - defect-management + - scanning + - sca + - sats + - dast + Test for Time to Patch: + uuid: 13af1227-3dd1-4d4f-a9e9-53deb793c18f + risk: Automatic PRs for dependencies are overlooked resulting in known vulnerabilities + in production artifacts. + measure: |- + Test of the Time to Patch (e.g. based on Mean Time to Close automatic PRs) + This activity is not repeated in the Sub-Dimension "Static depth for infrastructure", but it applies to infrastructure as well. difficultyOfImplementation: - knowledge: 2 - time: 2 + knowledge: 1 + time: 1 resources: 1 - usefulness: 4 + usefulness: 3 level: 2 implementation: - - uuid: 893d9f37-2142-4490-996c-e43b55064d3d - name: kubescape - url: https://github.com/armosec/kubescape + - uuid: d6292c7d-aab7-43d3-a7c6-1e443b5c1aa4 + name: dependabot tags: - - kubernetes - - vulnerability - - misconfiguration - description: _Testing if Kubernetes is deployed securely as defined in Kubernetes - Hardening Guidance by to NSA and CISA_ - - uuid: 2af7204c-a25c-4625-9775-889978386407 - name: kube-hunter - tags: [] - url: https://github.com/aquasecurity/kube-hunter - - uuid: d45fba7d-f176-4f06-a33c-434b17ec8a8f - name: openVAS - tags: [] - url: https://www.openvas.org/ + - auto-pr + - patching + url: https://docs.github.com/en/code-security/getting-started/dependabot-quickstart-guide + - uuid: 8228266e-e04f-40ba-94c8-bfadc5310920 + name: renovate + tags: + - auto-pr + - patching + url: https://github.com/renovatebot/renovate + dependsOn: + - 8ae0b92c-10e0-4602-ba22-7524d6aed488 # Automated PRs for patches references: - samm2: [] + samm2: + - V-ST-A-2 iso27001-2017: - - System hardening is not explicitly covered by ISO 27001 - too specific - - 12.6.1 - - 14.2.3 - - 14.2.8 + - Not explicitly covered by ISO 27001 - too specific + - 14.2.1 + - 14.2.5 iso27001-2022: - - System hardening is not explicitly covered by ISO 27001 - too specific - - 8.8 - - 8.32 - - 8.29 - isImplemented: false - evidence: "" + - Not explicitly covered by ISO 27001 - too specific + - 8.25 + - 8.27 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20applications/subsection/Test%20for%20Time%20to%20Patch comments: "" + meta: + implementationGuide: Usage of a version control platform API (e.g. github + API) can be used to fetch the information. Consider that `Measure libyears` + might be an alternative to this activity. tags: - - none - Weak password test: - uuid: 61e10f9c-e126-4ffa-af12-fdbe0d0a831f - risk: Weak passwords in components like applications or systems, specially for - privileged accounts, lead to take over of that account. - measure: Automatic brute force attacks are performed. Specially the usage of - standard accounts like 'admin' and employee user-ids is recommended. + - patching + Test libyear: + uuid: 87b54313-fafd-4860-930f-5ef132b3e4ad + risk: Vulnerabilities in running artifacts stay for long and might get exploited. + measure: Test `libyear`, which provides a good insight how good patch management + is. difficultyOfImplementation: - knowledge: 2 + knowledge: 1 time: 1 resources: 1 - usefulness: 1 - level: 3 + usefulness: 3 + level: 2 implementation: - - uuid: b99c9d52-dd1a-4aef-8699-65173cf978ce - name: HTC Hydra + - uuid: 2fff917f-205e-4eab-2e0e-1fab8c04bf33 + name: libyear tags: - - password - url: https://www.htc-cs.com/en/products/htc-hydra/ + - patching + - build + url: https://libyear.com/ + description: A simple measure of software dependency freshness. It is a single + number telling you how up-to-date your dependencies are. + dependsOn: + - f6f7737f-25a9-4317-8de2-09bf59f29b5b # Defined build process references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - - 9.4.3 + - Not explicitly covered by ISO 27001 - too specific + - 14.2.1 + - 14.2.5 iso27001-2022: - - 5.17 - isImplemented: false - evidence: "" + - Not explicitly covered by ISO 27001 - too specific + - 8.25 + - 8.27 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20applications/subsection/Test%20libyear comments: "" + meta: + implementationGuide: | + `libyear` can be integrated into the build process and flag or even better break the build in case the defined threshold (e.g. 30 years) is reached. + An alternative approach is to determine `libyear` based on deployed artifacts (which requires more effort in implementation). tags: - - none - Static depth for applications: + - patching API design validation: uuid: 017d9e26-42b5-49a4-b945-9f59b308fb99 risk: Creation of insecure or non-compliant API. @@ -8628,8 +7240,8 @@ Test and Verification: knowledge: 2 time: 2 resources: 2 - usefulness: 4 - level: 2 + usefulness: 3 + level: 3 implementation: - uuid: 261f243e-f89c-4169-b076-b22a03ec00be name: Spectral @@ -8653,7 +7265,7 @@ Test and Verification: on API best practices. references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - 14.2.1 - 14.2.5 @@ -8661,70 +7273,11 @@ Test and Verification: - 8.25 - 8.27 - 8.28 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20applications/subsection/API%20design%20validation isImplemented: false - evidence: "" - comments: "" - tags: - - none - Dead code elimination: - uuid: d17dbff0-1f10-492a-b4c7-17bb59a0a711 - risk: Dead code increases the attack surface (use of hard coded credentials - and variables, sensitive information) - measure: Collection of unused code and then manual removal of unused code. - difficultyOfImplementation: - knowledge: 1 - time: 1 - resources: 1 - usefulness: 1 - level: 5 - implementation: - - uuid: 00702aca-04d9-49ca-90d0-c32c199b26cb - name: PMD - tags: [] - dependsOn: - - Defined build process - references: - samm2: - - V-ST-2-A - iso27001-2017: - - Not explicitly covered by ISO 27001 - too specific - - 14.2.1 - - 14.2.5 - iso27001-2022: - - Not explicitly covered by ISO 27001 - too specific - - 8.25 - - 8.27 - comments: "" - tags: - - none - Exclusion of source code duplicates: - uuid: d17dbff0-1f10-492a-b4c7-17bb59a0a711 - risk: Duplicates in source code might influence the stability of the application. - measure: Automatic Detection and manual removal of duplicates in source code. - difficultyOfImplementation: - knowledge: 1 - time: 1 - resources: 1 - usefulness: 1 - level: 5 - implementation: - - uuid: 00702aca-04d9-49ca-90d0-c32c199b26cb - name: PMD - tags: [] dependsOn: - - Defined build process - references: - samm2: - - V-ST-2-A - iso27001-2017: - - Not explicitly covered by ISO 27001 - too specific - - 14.2.1 - - 14.2.5 - iso27001-2022: - - Not explicitly covered by ISO 27001 - too specific - - 8.25 - - 8.27 - comments: "" + - 2a44b708-734f-4463-b0cb-86dc46344b2f # Inventory of production components tags: - none Local development security checks performed: @@ -8743,1118 +7296,48 @@ Test and Verification: - uuid: 5b52a841-c281-45fd-b68f-0a93aa6fa398 name: Fortify Extension for Visual Studio Code url: https://marketplace.visualstudio.com/items?itemName=fortifyvsts.fortify-extension-for-vs-code + test-url-expects: + - 404 tags: - ide - sast - uuid: cf1213fd-8bfa-4a97-bf8b-937c93f31005 name: Setting Up the Visual Studio Code Extension Plugin url: https://checkmarx.atlassian.net/wiki/spaces/SD/pages/1759216424/Setting+Up+the+Visual+Studio+Code+Extension+Plugin + test-url-expects: + - 302 tags: - ide - sast - uuid: 3f5a493d-12d0-4468-b9fa-c3e4eae89ffb name: HCL AppScan CodeSweep url: https://marketplace.visualstudio.com/items?itemName=HCLTechnologies.hclappscancodesweep + test-url-expects: + - 404 tags: - ide - sast - - argocd: - uuid: fdb0e7cc-d3dd-4a2b-9f45-7d403001294f - name: argoCD - tags: - - deployment - url: https://argo-cd.readthedocs.io/en/stable/ - signing-of-commits-protection: - uuid: 86c6bdba-73c0-4c99-bbda-81b85c9fe2a4 - name: Enforcement of commit signing - tags: - - signing - url: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/defining-the-mergeability-of-pull-requests/managing-a-branch-protection-rule - description: Usage of branch protection rules - signing-of-commits: - uuid: d6d755d3-b9f1-4942-a084-e62b266541df - name: Signing of commits - tags: - - signing - url: https://git-scm.com/book/en/v2/Git-Tools-Signing-Your-Work - description: Signing of commits in git - ci-cd-tools: - uuid: b4bfead3-5fb6-4dd0-ba44-5da713bd22e4 - name: CI/CD tools - tags: - - ci-cd - url: https://martinfowler.com/articles/continuousIntegration.html - description: CI/CD tools such as jenkins, gitlab-ci or github-actions - apimaturity: - uuid: 596cb528-8981-4723-bcc3-22c261f26114 - name: API Security Maturity Model for Authorization - tags: - - api - url: https://curity.io/resources/learn/the-api-security-maturity-model/ - container-technologi: - uuid: ed6b6340-6c7f-4e13-8937-f560d3f5db11 - name: Container technologies and orchestration like Docker, Kubernetes - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:ContainerOrchestrationSoftware/ - cwe25: - uuid: c77f7ecd-76de-4611-bd6d-5b249f910c39 - name: CWE Top 25 Most Dangerous Software Weaknesses - tags: - - documentation - - threat - url: https://cwe.mitre.org/top25/archive/2020/2020_cwe_top25.html - docker-content-trust: - uuid: ee81f93f-8230-4cfb-a132-ae4ec61cb8e6 - name: Docker Content Trust - tags: [] - url: https://docs.docker.com/engine/security/trust/ - in-toto: - uuid: 6e9d8c14-ba3b-4698-afc3-365b4ab6fb1f - name: in-toto - tags: [] - url: https://in-toto.github.io/ - a-complete-backup-of: - uuid: ba7348e5-1abf-4c7d-8fbc-49f99460930b - name: A complete backup of persisted data might be performed*. - tags: [] - a-point-in-time-reco: - uuid: 9af7624e-0729-4eeb-b257-ebaf65f70355 - name: A Point in Time Recovery for databases should be implemented. - tags: [] - blue-green-deploymen: - uuid: 4fb3d95c-07c0-4cbb-b396-5054aba751c2 - name: Blue/Green Deployments - tags: [] - url: https://martinfowler.com/bliki/BlueGreenDeployment.html - docker: - uuid: cc47b2e3-6ee5-4926-af3a-d418ef91c8ba - name: Docker - url: https://github.com/moby/moby - tags: [] - webserver: - uuid: a71ce8f8-fd4a-4240-8b46-64a6cdb5dfdb - name: Webserver - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:WebServer/ - rolling-update: - uuid: ee2eb94b-7204-40d8-97da-43c7b1296e2e - name: rolling update - tags: [] - kubernetes-admission: - uuid: 2a76300f-6b1f-4a51-b925-134c36b723af - name: Kubernetes Admission Controller can whitelist registries and/or whitelist - a signing key. - tags: [] - url: https://medium.com/slalom-technology/build-a-kubernetes-dynamic-admission-controller-for-container-registry-whitelisting-b46fe020e22d - dependabot: - uuid: d6292c7d-aab7-43d3-a7c6-1e443b5c1aa4 - name: dependabot - tags: - - auto-pr - - patching - url: https://dependabot.com/ - renovate: - uuid: 8228266e-e04f-40ba-94c8-bfadc5310920 - name: renovate - tags: - - auto-pr - - patching - url: https://github.com/renovatebot/renovate - jenkins: - uuid: 42ddb49f-48f2-4a3a-b76a-e73104ac6971 - name: Jenkins - tags: [] - url: https://www.jenkins.io/ - sample-concept-1: - uuid: 1a463242-b480-46f6-a912-b51ec1c1558d - name: "Sample concept: \n(1" - tags: [] - description: "Sample concept: \n(1) each container has a set lifetime and - is killed / replaced with a new container multiple times a day where you - have some form of a graceful replacement to ensure no (short) service - outage will occur to the end users. \n(2) twice a day a rebuild of images - is done. The rebuilds are put into a automated testing pipeline. If the - testing has no blocking issues the new images will be released for deployment - during the next \"restart\" of a container. What has to be done, is to - ensure the new containers are deployed in some canary deployment manner, - this will ensure that if (and only if) something buggy has been introduced - which breaks functionality the canary deployment will make sure the \"older - version\" is being used and not the buggy newer one." - distroless: - uuid: ef647044-b675-47d3-9720-3ebc144ef37b - name: Distroless - tags: [] - url: https://github.com/GoogleContainerTools/distroless - fedora-coreos: - uuid: be757cb3-63d6-4a63-9c4e-e10b746fd47a - name: Fedora CoreOS - tags: [] - url: https://getfedora.org/coreos - distroless-usage: - uuid: a92c4f8f-a918-406a-b1e5-70acfc0477bd - name: Distroless or Alpine - tags: [] - url: https://itnext.io/which-container-images-to-use-distroless-or-alpine-96e3dab43a22 - threat-modeling-play: - uuid: fd0f282b-a065-4464-beed-770c604a5f52 - name: Threat Modeling Playbook - tags: - - owasp - - defender - - threat-modeling - - whiteboard - url: https://github.com/Toreon/threat-model-playbook - owasp-samm: - uuid: b5eaf710-e05f-49e5-a649-13afde9aeb52 - name: OWASP SAMM - tags: - - threat-modeling - - owasp - - defender - url: https://owaspsamm.org/model/design/threat-assessment/stream-b/ - whiteboard: - uuid: c0533602-11b7-4838-93cc-a40556398163 - name: Whiteboard - tags: - - defender - - threat-modeling - - collaboration - - whiteboard - url: https://en.wikipedia.org/wiki/Whiteboard - miro-or-any-other-c: - uuid: 965c3814-b6df-4ead-a096-1ed78ce1c7c1 - name: Miro (or any other collaborative board) - tags: - - defender - - threat-modeling - - collaboration - - whiteboard - url: https://miro.com/ - draw-io: - uuid: 088794c4-3424-40d4-9084-4151587fc84d - name: Draw.io - tags: - - defender - - threat-modeling - - whiteboard - url: https://github.com/jgraph/drawio-desktop - threagile: - uuid: e8332407-5149-459e-a2fe-c5c78c7ec55c - name: Threagile - tags: - - threat-modeling - url: https://github.com/Threagile/threagile - don-t-forget-evil-u: - uuid: bb5b8988-021b-452a-a914-bd36887b6860 - name: '[Don''t Forget EVIL U' - tags: [] - url: https://www.owasp.org/index.php/Agile_Software_Development - description: '[Do not Forget EVIL User Stories](https://www.owasp.org/index.php/Agile_Software_Development:_Don%27t_Forget_EVIL_User_Stories) - and [Practical Security Stories and Security Tasks for Agile Development - Environments](http://safecode.org/publication/SAFECode_Agile_Dev_Security0712.pdf)' - libyear: - uuid: 2fff917f-205e-4eab-2e0e-1fab8c04bf33 - name: libyear - tags: - - patching - - build - url: https://libyear.com/ - description: A simple measure of software dependency freshness. It is a - single number telling you how up-to-date your dependencies are. - owasp-juice-shop: - uuid: 1fff917f-205e-4eab-ae0e-1fab8c04bf3a - name: OWASP Juice Shop - tags: - - training - url: https://github.com/bkimminich/juice-shop - description: In case you do not have the budget to hire an external security - expert, an option is to use the OWASP JuiceShop on a "hacking Friday" - owasp-cheatsheet-ser: - uuid: 1c3f2f7a-5031-4687-9d69-76c5178c74e1 - name: OWASP Cheatsheet Series - tags: - - secure coding - url: https://cheatsheetseries.owasp.org/ - owasp-juiceshop: - uuid: 81476121-67dd-4ba9-a67b-e78a23050c28 - name: OWASP JuiceShop - tags: [] - url: https://github.com/bkimminich/juice-shop - description: |- - In case you do not have the budget to hire an external security expert, an option - is to use the [OWASP JuiceShop](https://github.com/bkimminich/juice-shop) on a "hacking Friday" - https-cheatsheetse: - uuid: 99080ac7-60cd-46af-93a1-a53a33597cba - name: https://cheatsheetseries.owasp.org/ - tags: - - training - - secure coding - url: https://cheatsheetseries.owasp.org/ - owasp-security-champ: - uuid: c191a515-3c10-4903-a889-70c8021f2ea1 - name: OWASP Security Champions Playbook - tags: - - security champions - url: https://github.com/c0rdis/security-champions-playbook - build-it-break-it-fi: - uuid: 8d4c1849-f310-4c42-8148-2810b382bc6f - name: Build it Break it Fix it Contest - tags: [] - url: https://builditbreakit.org/ - motivate-people: - uuid: 8e1b4a8a-c53b-4b1e-90f6-c60b7e225098 - name: Motivate people - tags: - - security champions - - gamification - - nudging - url: https://github.com/wurstbrot/security-pins - description: |- - Enhance motivation can be performed with the distribution of pins - as a reward, see [OWASP Security Pins Project](https://github.com/wurstbrot/security-pins) - owasp-top-10-maturit: - uuid: 22b63bdb-2003-4ac0-969d-b1e5268c2510 - name: OWASP Top 10 Maturity Categories for Security Champions - tags: - - security champions - url: https://owaspsamm.org/presentations/OWASP_Top_10_Maturity_Categories_for_Security_Champions.pptx - involve-security-sme: - uuid: 8a044b74-17f2-4ffa-9dee-6b3bb6e4baf3 - name: Involve Security SME - tags: [] - description: Security SME are involved in discussion for requirements analysis, - software design and sprint planning to provide guidance and suggestions. - damn-vulnerable-web: - uuid: a8cd9acb-ad22-44d6-b177-1154c65a8529 - name: Damn Vulnerable Web Application - tags: - - training - description: Simple Application with intended vulnerabilities. HTML based. - example-all-docker: - uuid: 349cf64c-abea-40bb-bd07-9c98ce648fa4 - name: 'Example: All docker images used by teams need to be based on standard - images.' - tags: [] - owasp-asvs: - uuid: 88767cde-1610-402e-98ec-bc3575377183 - name: OWASP ASVS - tags: [] - url: https://owasp.org/www-project-application-security-verification-standard/ - owasp-masvs: - uuid: 7bf90650-a53a-4581-a214-1afd5de3a059 - name: OWASP MASVS - tags: [] - url: https://github.com/OWASP/owasp-masvs - cis-kubernetes-bench: - uuid: edaec98d-dac7-4dfd-8ab3-42c471d5b9ff - name: CIS Kubernetes Bench for Security - tags: [] - url: https://www.cisecurity.org/cis-benchmarks/ - cis-docker-bench-for: - uuid: 4dd23c4a-5a7e-4917-82cf-d00e0f04482f - name: CIS Docker Bench for Security - tags: [] - url: https://www.cisecurity.org/cis-benchmarks/ - for-example-for-cont: - uuid: f4d7c796-8574-4a88-ab00-98d245a115ef - name: For example for Cont - tags: [] - description: 'For example for Containers: Deny running containers as root, - deny using advanced privileges, deny mounting of the hole filesystem, - ...' - url: https://d3fend.mitre.org/technique/d3f:ExecutionIsolation/ - attack-matrix-cloud: - uuid: 3b7df373-2ad9-456e-9abe-439cdc9d4d8b - name: Attack Matrix Cloud - tags: - - mitre - url: https://attack.mitre.org/matrices/enterprise/cloud/ - description: Attack matrix for cloud - attack-matrix-contai: - uuid: 59881520-4c69-4922-a44e-99044a77de2b - name: Attack Matrix Containers - tags: - - mitre - url: https://attack.mitre.org/matrices/enterprise/cloud/ - description: Attack matrix for containers - attack-matrix-kubern: - uuid: 9fbc47ad-82bc-46d1-bba9-66815ab79935 - name: Attack Matrix Kubernetes - tags: - - mitre - url: https://www.microsoft.com/security/blog/2020/04/02/attack-matrix-kubernetes/ - description: Attack matrix for kubernetes - istio: - uuid: 9429d52c-203d-49ae-814f-1401210887cd - name: istio - tags: [] - url: https://istio.io/ - bridges: - uuid: fc0eda30-2bf7-466f-948e-e17584db9f30 - name: bridges - tags: [] - firewalls: - uuid: e3c6fb92-3f7d-471f-9308-c62359f4f1b7 - name: firewalls - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:Firewall/ - open-policy-agent: - uuid: 4a024319-4510-4a53-a8b6-8f35b6c01867 - name: Open Policy Agent - tags: [] - url: https://www.openpolicyagent.org/ - gitops: - uuid: b0931397-2402-44f1-814b-63292ab4a339 - name: GitOps - tags: [] - url: https://www.redhat.com/en/topics/devops/what-is-gitops - ansible: - uuid: 73747d35-2185-4f22-94a0-723288fa283c - name: Ansible - tags: [] - url: https://github.com/ansible/ansible - chef: - uuid: 691c443f-b6e2-498d-94dc-778d8d51cfce - name: Chef - tags: [] - url: https://github.com/chef/chef - puppet: - uuid: eb7f76a8-87e5-4394-af4c-c09487c85982 - name: Puppet - tags: [] - url: https://github.com/puppetlabs/puppet - jenkinsfile: - uuid: 321dcfe4-d2fc-4dd2-85bf-aac563958458 - name: Jenkinsfile - tags: [] - url: https://www.jenkins.io/doc/book/pipeline/jenkinsfile/ - seccomp: - uuid: 0cc7e68b-f7d9-4e66-8065-47d076129ffd - name: seccomp - tags: [] - url: https://man7.org/linux/man-pages/man2/seccomp.2.html - strace: - uuid: 73ab2e3d-11a7-459d-8b57-9337662bd1ff - name: strace - tags: [] - url: https://man7.org/linux/man-pages/man1/strace.1.html - remove-direct-access: - uuid: b206481f-9c66-45e2-843c-37c5730580cd - name: Remove direct access to infrastructure - tags: [] - directory-service: - uuid: 04edc63e-d389-48dd-b365-552aaf4ea004 - name: Directory Service - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:DirectoryService/ - plugins: - uuid: cc55cba1-ea0a-466e-99c5-337c9da2b00e - name: Plugins - tags: [] - smartcard: - uuid: e76a395a-8d6a-4e25-a175-6cf25409b755 - name: Smartcard - tags: [] - url: https://d3fend.mitre.org/technique/d3f:Multi-factorAuthentication/ - yubikey: - uuid: d5981117-9bc2-45ed-b4a4-383135dc13d8 - name: YubiKey - tags: [] - url: https://d3fend.mitre.org/technique/d3f:Multi-factorAuthentication/ - sms: - uuid: 6151cfb3-c894-421e-83da-cac0b2bfaec8 - name: SMS - tags: [] - totp: - uuid: f69f5d03-691f-4e14-8fbc-ad66e2e5a12d - name: TOTP - tags: [] - url: https://d3fend.mitre.org/technique/d3f:One-timePassword/ - http-basic-authentic: - uuid: 41fda224-2980-443c-bfd4-0a1d4b520cb9 - name: HTTP-Basic Authentication - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:WebAuthentication/ - vpn: - uuid: e506f60b-747b-44b1-8fe8-f67ccd8f290e - name: VPN - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:VPN/ - for-applications-ch: - uuid: d7fb1f5a-05e3-49f7-ae67-00bfb8f8410c - name: 'For applications: Check default encoding' - tags: [] - managing-secrets: - uuid: 7e744f11-976e-46b6-88d4-f39b2965dfaf - name: managing secrets - tags: [] - url: https://d3fend.mitre.org/technique/d3f:CredentialHardening/ - crypto: - uuid: 520517ef-2911-4efc-8e1b-dcc9389aca45 - name: crypto - tags: [] - authentication: - uuid: ba6bd46c-2069-4f4d-b26c-7334a7553339 - name: authentication - tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:Authentication/ - rsyslog: - uuid: 79f88310-d63e-471d-8e63-8c77f2281b66 - name: rsyslog - url: https://www.rsyslog.com/ - tags: - - tool - - logging - logstash: - uuid: 7a8fad2e-d642-4972-8501-74591b23feab - name: logstash - url: https://www.elastic.co/guide/en/logstash/current/getting-started-with-logstash.html - tags: - - tool - - logging - fluentd: - uuid: f5da3a20-ab64-4ecf-b4e1-660c80036e45 - name: fluentd - tags: - - tool - url: https://www.fluentd.org/ - bash: - uuid: 6226f8bc-2f6e-45c2-9232-98d2027e4531 - name: bash - tags: - - tool - url: https://www.gnu.org/software/bash/ - owasp-logging-cheats: - uuid: 5a5c7d99-41e8-454a-86ae-a638c9787d8c - name: OWASP Logging CheatSheet - url: https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html - tags: - - logging - - documentation - elk-stack: - uuid: 38fe9d00-df8b-44b6-910d-ca0f02b5c5d3 - name: ELK-Stack - tags: [] - url: https://www.elastic.co/elk-stack - https-ht-transpare: - uuid: 84ef86ea-ada4-4e10-ae4f-a5bb77dcae5d - name: https://ht.transpare - tags: [] - url: https://ht.transparencytoolkit.org/FileServer/FileServer/OLD - description: https://ht.transparencytoolkit.org/FileServer/FileServer/OLD%20Fileserver/books/SICUREZZA/Addison.Wesley.Security.Metrics.Mar.2007.pdf - prometheus: - uuid: ddf221df-3517-42e4-b23d-c1d9a162744c - name: Prometheus - tags: [] - url: https://prometheus.io/ - collected: - uuid: 73f6a52c-4fc2-45dc-991b-d5911b6c1ef8 - name: collected - tags: [] - httpunit: - uuid: 3bd40005-f180-4b95-907d-ec5b58ac1f20 - name: HttpUnit - tags: [] - url: http://httpunit.sourceforge.net/ - junit: - uuid: cc2eec82-f3a7-4ae5-9ccb-3d75352b2e4d - name: JUnit - tags: - - unittest - url: https://junit.org/junit5/ - karma: - uuid: fd56720a-ad4b-487c-b4c3-897a688672c4 - name: Karma - tags: [] - url: https://karma-runner.github.io - owasp-defectdojo: - uuid: 227d786c-dd76-4b81-b0b2-62389ab8f0fb - name: OWASP DefectDojo - tags: - - vulnerability management system - - owasp - url: https://github.com/DefectDojo/django-DefectDojo - description: | - DefectDojo is a security program and vulnerability management tool. DefectDojo allows you to manage your application security program, maintain product and application information, triage vulnerabilities and push findings into defect trackers. Consolidate your findings into one source of truth with DefectDojo. - purify: - uuid: d2eb592d-c9b5-4c39-bff7-bb313a58e3a9 - name: Purify - tags: - - vulnerability management system - url: https://github.com/faloker/purify/ - description: | - The goal of Purify to be an easy-in-use and efficient tool to simplify a workflow of managing vulnerabilities delivered from various (even custom) tools. - see-other-actions-e: - uuid: 44c08670-78dc-47ee-a4c1-2503ca6b6cf8 - name: See other actions, e.g. "Treatment of defects with severity high". - tags: [] - sast: - uuid: aaad322e-806e-4c51-b78d-6551f7dc376a - name: SAST - tags: [] - description: 'At SAST (Static Application Security Testing): Server-side - / client-side teams can easily be recorded. With microservice architecture - individual microservices can be used usually Teams.' - url: https://d3fend.mitre.org/dao/artifact/d3f:StaticAnalysisTool/ - dast: - uuid: 9d4bd377-11ec-4054-9c9e-9bfb99ac9609 - name: DAST - tags: [] - description: 'At DAST (Dynamic Application Security Testing): vulnerabilities - are classified and can be assigned to server-side and client-side teams.' - url: https://d3fend.mitre.org/dao/artifact/d3f:DynamicAnalysisTool/ - owasp-defect-dojo: - uuid: bb9d0f2d-f8bc-46b5-bbc7-7dbcf927191c - name: OWASP Defect Dojo - tags: [] - url: https://github.com/DefectDojo/django-DefectDojo - owasp-dependency-che: - uuid: 06334caf-8be6-487a-96b1-d41c7ed5f207 - name: OWASP Dependency Check - tags: - - OpenSource - - Supply Chain - - vulnerability - url: https://owasp.org/www-project-dependency-check/ - logparser-jenkins-pl: - uuid: ef80cd34-d3ba-4406-a4fa-4cf6f30c2e81 - name: LogParser Jenkins Plugins - tags: [] - owasp-code-pulse: - uuid: 7063cf8c-cd98-480f-8ef7-11cf241d2366 - name: OWASP Code Pulse - tags: [] - url: https://www.owasp.org/index.php/OWASP_Code_Pulse - ajax-spider: - uuid: 6583fd5f-4314-4b39-9265-de72f861c8cb - name: Ajax Spider - tags: [] - url: https://www.zaproxy.org/docs/desktop/addons/ajax-spider/ - curl: - uuid: f2a5f642-43b3-4b2c-97d5-b14d5964981b - name: cURL - tags: [] - url: https://curl.se/ - openapi: - uuid: 7ce77258-bf65-4e7a-9627-daf765ee1d77 - name: OpenAPI Specifications - tags: [] - url: https://spec.openapis.org/ - owasp-zap: - uuid: 42a87524-ec35-4de2-a30c-1a7c7d045801 - name: OWASP Zap - tags: - - vulnerability - - scanner - url: https://github.com/zaproxy/zaproxy - description: | - The OWASP Zed Attack Proxy (ZAP) is one of the world's most popular free security tools and is actively maintained by a dedicated international team of ... - arachni: - uuid: 83ae1e92-5eb9-4467-b3d3-fd2f96e6ab63 - name: Arachni - url: https://github.com/Arachni/arachni - zest: - uuid: 7eb37566-02d5-4fff-8dcf-8fcd1c8197f3 - name: Zest - url: https://www.zaproxy.org/docs/desktop/addons/zest/ - tags: - - zap - description: | - Zest is an experimental specialized scripting language (also known as a domain-specific language) originally developed by the Mozilla security team and is intended to be used in web oriented security tools. - owasp-securecodebox: - uuid: f220b299-0917-4750-96c5-d81cd402b4df - name: OWASP secureCodeBox - tags: - - vulnerability - - scanner-orchestration - url: https://github.com/secureCodeBox/secureCodeBox - description: | - secureCodeBox is a kubernetes based, modularized toolchain for continuous security scans of your software project. Its goal is to orchestrate and easily automate a bunch of security-testing tools out of the box. - kube-hunter: - uuid: 2af7204c-a25c-4625-9775-889978386407 - name: kube-hunter - tags: [] - url: https://github.com/aquasecurity/kube-hunter - openvas: - uuid: d45fba7d-f176-4f06-a33c-434b17ec8a8f - name: openVAS - tags: [] - url: https://www.openvas.org/ - htc-hydra: - uuid: b99c9d52-dd1a-4aef-8699-65173cf978ce - name: HTC Hydra - tags: - - password - url: https://www.htc-cs.com/en/products/htc-hydra/ - netassert: - uuid: fffa6fb9-1fae-4852-88dc-c7086961330c - name: netassert - tags: [] - url: https://github.com/controlplaneio/netassert - nmap: - uuid: 08111dc3-bdc4-47d8-8f2e-10bb50a86882 - name: nmap - tags: [] - url: https://nmap.org/ - owasp-amass: - uuid: f085295e-46a3-4c8d-bbc3-1ac6b9dfcf2a - name: OWASP Amass - tags: [] - url: https://github.com/OWASP/Amass - k8spurger: - uuid: 8fea20ad-e332-4aa8-b1f1-aa9deb635dc1 - name: K8sPurger - tags: - - vulnerability - - scanner - - dast - - infrastructure - url: https://github.com/yogeshkk/K8sPurger - description: | - Hunt Unused Resources In Kubernetes. - pmd: - uuid: 00702aca-04d9-49ca-90d0-c32c199b26cb - name: PMD - tags: [] - eslint: - uuid: 6a0948a7-4781-4858-9766-f4303971b28b - name: eslint - tags: [] - url: https://eslint.org/ - findsecuritybugs: - uuid: f911d2b4-3e0c-424c-acf9-3bd363ef5078 - name: FindSecurityBugs - tags: [] - jsprime: - uuid: cccc2882-62ab-4175-afa1-58471017e8ed - name: jsprime - tags: [] - url: https://github.com/dpnishant/jsprime - bdd-mobile-security: - uuid: 3a8ba0ea-37dc-4124-983b-bbf9b4443d75 - name: '[bdd-mobile-security' - tags: [] - url: https://github.com/ing-bank/bdd-mobile-security-automation-framework - description: '[bdd-mobile-security-automation-framework](https://github.com/ing-bank/bdd-mobile-security-automation-framework)' - retire-js: - uuid: aa54a82c-d628-4d42-9bc8-1aa269cd91c7 - name: retire.js - tags: [] - url: https://github.com/RetireJS/retire.js/ - npm-audit: - uuid: 7c26484a-763c-437d-b953-d482a4fd7cf3 - name: npm audit - tags: [] - url: https://docs.npmjs.com/cli/audit - sigmahq: - uuid: 1adf1ac0-8572-407b-a358-3976d9a225e2 - name: SigmaHQ - tags: [] - url: https://github.com/SigmaHQ/sigma - dive-to-inspect-a-co: - uuid: 73419fb5-b13d-4242-83ec-86f36c7d73d5 - name: Dive to inspect a container images - tags: [] - url: https://github.com/wagoodman/dive - clusterscanner: - url: https://github.com/SDA-SE/clusterscanner - uuid: 3c9ac78c-0fd4-43f4-8211-c915f9ef685f - name: ClusterScanner - tags: - - docker - - image - - container - - vulnerability - - misconfiguration - - security-tools - - scanning - description: Discover vulnerabilities and container image misconfiguration - in production environments. - dockerfile-with-hado: - uuid: 94d993ad-ef6e-4d9f-b7a8-27ea68dc3005 - name: Dockerfile with hadolint - tags: [] - url: https://github.com/hadolint/hadolint - deployment-with-kube: - uuid: 95b717cd-5ad3-40b5-993b-13a63c382b1b - name: Deployment with kube-score - tags: [] - url: https://github.com/zegl/kube-score - kubesec: - uuid: 1e58f8d2-61e2-45bb-a17c-51516d0cc9ba - name: kubesec - tags: [] - url: https://kubesec.io - anchore-io: - uuid: fab2765d-8d96-4fc6-af96-dc9304ca41dc - name: Anchore.io - tags: [] - url: https://anchore.com/ - clair: - uuid: f10f5423-4dff-4bb7-99c8-9ce214645071 - name: Clair - tags: [] - url: https://github.com/quay/clair - openscap: - uuid: d0c6b3a0-b073-44d7-a187-c4ad8eaa6531 - name: OpenSCAP - tags: [] - url: https://www.open-scap.org/ - vuls: - uuid: 04261564-2fcf-4b73-8847-83b0d855e1c5 - name: Vuls - tags: [] - url: https://github.com/future-architect/vuls - kube-bench: - uuid: 8aeefd29-6220-45bf-aead-83eba2e9d055 - name: kube-bench - tags: [] - url: https://github.com/aquasecurity/kube-bench - trufflehog: - uuid: d90fefc9-4e5d-420f-ac87-eeb165bf0ee6 - name: truffleHog - tags: [] - url: https://github.com/dxa4481/truffleHog - go-pillage-registrie: - uuid: 382873e2-8604-4410-ae5e-b0f5ccdee835 - name: go-pillage-registries - tags: [] - url: https://github.com/nccgroup/go-pillage-registries - https-github-com-a: - uuid: 7f500e95-2110-44c4-a1f8-cd7ef5d9eb6b - name: https://github.com/aquasecurity/trivy - tags: [] - url: https://github.com/aquasecurity/trivy - registries-like-quay: - uuid: 8737c6c0-4e90-400a-bf9a-f8e399913b57 - name: Registries like quay - tags: [] - description: Registries like quay, dockerhub provide (commercial) offerings, - often not suitable for distroless images - dockerfilelint: - uuid: eba2685d-2d25-4961-8e4e-2957e7c07c30 - name: dockerfilelint - tags: - - sast - - docker - - dockerfile - url: https://github.com/replicatedhq/dockerfilelint - description: dockerfilelint is an node module that analyzes a Dockerfile - and looks for common traps, mistakes and helps enforce best practices. - threat-matrix-for-storage: - uuid: 1c56dbea-e067-44e2-8d3b-0a1205a70617 - name: Threat Matrix for Storage - url: https://www.microsoft.com/security/blog/2021/04/08/threat-matrix-for-storage/ - tags: - - documentation - - storage - - cluster - - kubernetes - defend-the-core-kubernetes: - uuid: b7a92886-aec9-4bf4-94c4-07cc191a97af - name: Defend the core kubernetes security at every layer - url: https://thenewstack.io/defend-the-core-kubernetes-security-at-every-layer/ - tags: - - documentation - - cluster - - kubernetes - business-friendly-vulnerability-metrics: - uuid: 3b99799c-e875-4cc2-aad7-5ce4564a1cde - name: Business friendly vulnerability management metrics - url: https://medium.com/uber-security-privacy/business-friendly-vulnerability-management-metrics-cfd702fd7705 - tags: - - documentation - - vulnerability - - vulnerability management system - kubescape: - uuid: 893d9f37-2142-4490-996c-e43b55064d3d - name: kubescape - url: https://github.com/armosec/kubescape - tags: - - kubernetes - - vulnerability - - misconfiguration - description: _Testing if Kubernetes is deployed securely as defined in Kubernetes - Hardening Guidance by to NSA and CISA_ - azuredevops: - uuid: b1b88bc5-5a22-4888-a27b-acce3d9fe29a - name: Improve code quality with branch policies - url: https://docs.microsoft.com/en-us/azure/devops/repos/git/branch-policies?view=azure-devops - tags: - - source-code-protection - - scm - github-policies: - uuid: 99211481-de9c-4358-880e-628366416a27 - name: About protected branches - url: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/defining-the-mergeability-of-pull-requests/about-protected-branches - tags: - - source-code-protection - - scm - sonarqube: - uuid: aa5ded61-5380-4da6-9474-afc36a397682 - name: In-Depth Linting of Your TypeScript While Coding - url: https://blog.sonarsource.com/in-depth-linting-of-your-typescript-while-coding - tags: - - ide - - linting - stylecop: - uuid: 0b7ec352-0c36-4de1-8912-617fc6c608fe - name: How to enforce a consistent coding style in your projects - url: https://www.meziantou.net/how-to-enforce-a-consistent-coding-style-in-your-projects.htm - tags: - - ide - - linting - fortify-vscode-extension: - uuid: 5b52a841-c281-45fd-b68f-0a93aa6fa398 - name: Fortify Extension for Visual Studio Code - url: https://marketplace.visualstudio.com/items?itemName=fortifyvsts.fortify-extension-for-vs-code - tags: - - ide - - sast - appscan-vscode-extension: - uuid: 3f5a493d-12d0-4468-b9fa-c3e4eae89ffb - name: HCL AppScan CodeSweep - url: https://marketplace.visualstudio.com/items?itemName=HCLTechnologies.hclappscancodesweep - tags: - - ide - - sast - checkmarx-vscode-extension: - uuid: cf1213fd-8bfa-4a97-bf8b-937c93f31005 - name: Setting Up the Visual Studio Code Extension Plugin - url: https://checkmarx.atlassian.net/wiki/spaces/SD/pages/1759216424/Setting+Up+the+Visual+Studio+Code+Extension+Plugin - tags: - - ide - - sast - pre-commit-microsoft: - uuid: 58ac9dea-b6c7-4698-904e-df89a9451c82 - name: DevSecOps control Pre-commit - url: https://docs.microsoft.com/en-us/azure/cloud-adoption-framework/secure/devsecops-controls#plan-and-develop - tags: - - pre-commit - pre-commit-synopsis: - uuid: 8da8d115-0f4e-40f0-a3ce-484a49e845fb - name: Building your DevSecOps pipeline 5 essential activities - url: https://www.synopsys.com/blogs/software-security/devsecops-pipeline-checklist/ - tags: - - pre-commit - dependencyTrack: - uuid: 500399bd-7dfc-47fd-99d8-b55cefb760a9 - name: Dependency-Track is an intelligent Component Analysis platform that - allows organizations to identify and reduce risk in the software supply - chain. Dependency-Track takes a unique and highly beneficial approach - by leveraging the capabilities of Software Bill of Materials (SBOM). - url: https://github.com/DependencyTrack/dependency-track - tags: - - sca - - inventory - - OpenSource - - Supply Chain - - vulnerability - juice-shop: - uuid: c021aa72-c71c-43e4-9573-717b74d6c19d - name: OWASP Juice Shop - tags: - - training - url: https://github.com/bkimminich/juice-shop - description: In case you do not have the budget to hire an external security - expert, an option is to use the OWASP JuiceShop on a "hacking Friday" - dvwa: - uuid: e1282ab3-7ffd-4ee5-a564-8e9af070979d - name: Damn Vulnerable Web Application - tags: - - training - description: Simple Application with intended vulnerabilities. HTML based. - loggingCheatSheet: - uuid: 032ca7cc-67dc-46bc-9702-3580a3c9d1a9 - name: OWASP Logging CheatSheet - url: https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html - tags: - - logging - - documentation - zap: - uuid: 84a2a907-a6fb-4ceb-8e21-f65c0d633445 - name: OWASP Zap - tags: - - vulnerability - - scanner - url: https://github.com/zaproxy/zaproxy - description: | - The OWASP Zed Attack Proxy (ZAP) is one of the world's most popular free security tools and is actively maintained by a dedicated international team of ... - secureCodeBox: - uuid: dc0995a5-ff13-4cfc-b95f-07bf8a30b6ab - name: OWASP secureCodeBox - tags: - - vulnerability - - scanner-orchestration - url: https://github.com/secureCodeBox/secureCodeBox - description: | - secureCodeBox is a kubernetes based, modularized toolchain for continuous security scans of your software project. Its goal is to orchestrate and easily automate a bunch of security-testing tools out of the box. - K8sPurger: - uuid: 7a019f5e-a77d-4f4a-89a6-d5107054a2cb - name: K8sPurger - tags: - - vulnerability - - scanner - - dast - - infrastructure - url: https://github.com/yogeshkk/K8sPurger - description: | - Hunt Unused Resources In Kubernetes. - hashicorp-vault: - uuid: e3a2ffc8-313f-437e-9663-b24591568209 - name: Hashicorp Vault - tags: - - authentication - - authorization - - secrets - - infrastructure - url: https://github.com/hashicorp/vault - description: | - A tool for secrets management, encryption as a service, and privileged access management. - stoplight-spectral: - uuid: 261f243e-f89c-4169-b076-b22a03ec00be - name: Spectral - tags: - - linting - - api - - documentation - url: https://github.com/stoplightio/spectral - description: | - Spectral is a flexible JSON/YAML linter built with extensibility in mind. - It uses JSON/YAML path rules to describe the problems you want to find. - api-oas-checker: - uuid: d2c9403d-9da2-4518-b33f-8b74b9c5ca3f - name: API OAS Checker - tags: - - linting - - api - - documentation - url: https://github.com/italia/api-oas-checker - description: | - A tool to check OpenAPI specifications using a comprehensive ruleset based - on API best practices. - coveragepy: - uuid: f011de6e-ab7c-4ec7-af55-03427271ab32 - name: Coverage.py - tags: - - testing - - coverage - url: https://github.com/nedbat/coveragepy - description: | - Code coverage measurement for Python - github-dependabot: - uuid: 5c0e817b-204e-4301-a315-2f7cc180c240 - name: Dependabot - tags: - - dependency - - dependency-management - - scm - url: https://github.com/dependabot/dependabot-core - description: | - Dependabot creates pull requests to keep your dependencies secure and up-to-date. - github-super-linter: - uuid: 94a7a85e-8064-46b4-929a-9e03fa292a9f - name: Super-Linter - tags: - - linting - - scm - url: https://github.com/github/super-linter - description: | - Lint code bases to catch common errors and enforce code style - schemathesis: - uuid: c9bbecf2-567b-4422-b29a-67b16385f32b - name: Schemathesis - tags: - - testing - - api - - documentation - url: https://github.com/schemathesis/schemathesis - description: | - Schemathesis is a tool for testing web applications and services by sending requests based on the Open API / Swagger schema. - martin-feature-toggles: - uuid: 83be6c60-6633-4c32-98de-7ae065c143c9 - name: Feature Toggles - tags: - - development - - architecture - url: https://martinfowler.com/articles/feature-toggles.html - description: | - Feature Toggles are a powerful technique, allowing teams to modify system behavior without changing code. (Pete Hodgson) - defectdojo-client: - uuid: 7ec30b0e-9681-427a-80ee-ab811d9e476f - name: DefectDojo Client - tags: - - Defectdojo - - statistics - url: https://github.com/SDA-SE/defectdojo-client - description: | - This projects contains the DefectDojo upload client and statistics client. It is for example used within the ClusterImageScanner. - falco: - uuid: 32b64e6e-5187-45e3-b4f3-f5f9a9739012 - name: Falco - tags: - - falco - - systemcall - - monitoring - url: https://github.com/falcosecurity/falco - description: | - Falco makes it easy to consume kernel events, and enrich those events with information from Kubernetes and the rest of the cloud native stack. - sammancoaching: - uuid: 9223be73-00da-400e-a910-3871734cff2f - name: sammancoaching - tags: - - documentation - - coaching - - education - url: https://sammancoaching.org/ - description: | - Security coaches work with software development teams to help them adopt better security practices. - terraform: - uuid: 0d63f907-37fe-4375-88a5-a5e252732618 - name: terraform - tags: - - IaC - url: https://www.terraform.io/ - description: | - Terraform enables infrastructure automation for provisioning, compliance, and management of any cloud, datacenter, and service. - packj: - uuid: 5d8b27ac-286e-47a5-b23f-769eb6d74e4a - name: packj - tags: - - OpenSource - - Supply Chain - - vulnerability - url: https://github.com/ossillate-inc/packj - description: | - Packj is a tool to detect software supply chain attacks. It can detect malicious, vulnerable, abandoned, typo-squatting, and other "risky" packages from popular open-source package registries, such as NPM, RubyGems, and PyPI. - apiMyth: - uuid: 6150533e-58ca-4b52-a9b2-6226545d9ea0 - name: Top 5 API Security Myths That Are Crushing Your Business - tags: - - documentation - - waf - url: https://thehackernews.com/2022/11/top-5-api-security-myths-that-are.html - description: | - There are several myths and misconceptions about API security. These myths about securing APIs are crushing your business - uuid: 58ac9dea-b6c7-4698-904e-df89a9451c82 name: DevSecOps control Pre-commit - url: https://docs.microsoft.com/en-us/azure/cloud-adoption-framework/secure/devsecops-controls#plan-and-develop + url: https://learn.microsoft.com/en-us/security/zero-trust/develop/secure-devops-environments-zero-trust tags: - pre-commit - uuid: 8da8d115-0f4e-40f0-a3ce-484a49e845fb name: Building your DevSecOps pipeline 5 essential activities - url: https://www.synopsys.com/blogs/software-security/devsecops-pipeline-checklist/ + url: https://www.blackduck.com/blog/devsecops-pipeline-checklist/ tags: - pre-commit references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - Hardening is not explicitly covered by ISO 27001 - too specific - 13.1.3 iso27001-2022: - Hardening is not explicitly covered by ISO 27001 - too specific - 8.22 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20applications/subsection/Local%20development%20security%20checks%20performed isImplemented: false evidence: "" comments: "" @@ -9872,7 +7355,9 @@ Test and Verification: usefulness: 2 level: 3 dependsOn: - - Defined build process + - f6f7737f-25a9-4317-8de2-09bf59f29b5b # Defined build process + - 2a44b708-734f-4463-b0cb-86dc46344b2f # Inventory of production components + - f2f0f274-c1a0-4501-92fe-7fc4452bc8ad # Exploit likelihood estimation implementation: - uuid: aa54a82c-d628-4d42-9bc8-1aa269cd91c7 name: retire.js @@ -9882,65 +7367,12 @@ Test and Verification: name: npm audit tags: [] url: https://docs.npmjs.com/cli/audit + test-url-expects: + - 301 - uuid: 500399bd-7dfc-47fd-99d8-b55cefb760a9 - name: Dependency-Track is an intelligent Component Analysis platform that - allows organizations to identify and reduce risk in the software supply - chain. Dependency-Track takes a unique and highly beneficial approach by - leveraging the capabilities of Software Bill of Materials (SBOM). - url: https://github.com/DependencyTrack/dependency-track - tags: - - sca - - inventory - - OpenSource - - Supply Chain - - vulnerability - - uuid: 5c0e817b-204e-4301-a315-2f7cc180c240 - name: Dependabot - tags: - - dependency - - dependency-management - - scm - url: https://github.com/dependabot/dependabot-core + name: Dependency-Track description: | - Dependabot creates pull requests to keep your dependencies secure and up-to-date. - references: - samm2: - - V-ST-2-A - iso27001-2017: - - 12.6.1 - iso27001-2022: - - 8.8 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Software Composition Analysis (server side): - uuid: d918cd44-a972-43e9-a974-eff3f4a5dcfe - risk: Server side components might have vulnerabilities. - measure: Tests for known vulnerabilities in server side components (e.g. backend/middleware) - are performed. - difficultyOfImplementation: - knowledge: 1 - time: 3 - resources: 1 - usefulness: 5 - level: 2 - dependsOn: - - Defined build process - implementation: - - uuid: 06334caf-8be6-487a-96b1-d41c7ed5f207 - name: OWASP Dependency Check - tags: - - OpenSource - - Supply Chain - - vulnerability - url: https://owasp.org/www-project-dependency-check/ - - uuid: 500399bd-7dfc-47fd-99d8-b55cefb760a9 - name: Dependency-Track is an intelligent Component Analysis platform that - allows organizations to identify and reduce risk in the software supply - chain. Dependency-Track takes a unique and highly beneficial approach by - leveraging the capabilities of Software Bill of Materials (SBOM). + Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track takes a unique and highly beneficial approach by leveraging the capabilities of Software Bill of Materials (SBOM). url: https://github.com/DependencyTrack/dependency-track tags: - sca @@ -9948,73 +7380,44 @@ Test and Verification: - OpenSource - Supply Chain - vulnerability - - uuid: aa54a82c-d628-4d42-9bc8-1aa269cd91c7 - name: retire.js - tags: [] - url: https://github.com/RetireJS/retire.js/ - - uuid: 7c26484a-763c-437d-b953-d482a4fd7cf3 - name: npm audit - tags: [] - url: https://docs.npmjs.com/cli/audit + - inventory - uuid: 5c0e817b-204e-4301-a315-2f7cc180c240 name: Dependabot tags: - dependency - dependency-management - - scm - url: https://github.com/dependabot/dependabot-core - description: | - Dependabot creates pull requests to keep your dependencies secure and up-to-date. - references: - samm2: - - V-ST-2-A - iso27001-2017: - - 12.6.1 - iso27001-2022: - - 8.8 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Static analysis for all components/libraries: - uuid: f4ff841d-3b2a-45d9-853e-5ec7ecbcb054 - risk: Used components like libraries and legacy applications might have vulnerabilities - measure: Usage of a static analysis for all used components. - difficultyOfImplementation: - knowledge: 2 - time: 4 - resources: 2 - usefulness: 3 - level: 5 - dependsOn: - - Static analysis for important client side components - - Static analysis for important server side components - implementation: [] + - scm + url: https://github.com/dependabot/dependabot-core + description: | + Dependabot creates pull requests to keep your dependencies secure and up-to-date. references: samm2: - - V-ST-2-A + - V-ST-A-2 + - I-SB-B-2 iso27001-2017: - 12.6.1 iso27001-2022: - 8.8 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20applications/subsection/Software%20Composition%20Analysis%20%28client%20side%29 isImplemented: false + tags: + - defect-management + - sca evidence: "" comments: "" - tags: - - none - Static analysis for all self written components: - uuid: ee68331f-9b1d-4f61-844b-b2ea04753a84 - risk: Parts in the source code of the frontend or middleware have vulnerabilities. - measure: Usage of static analysis tools for all parts of the middleware and - frontend. Static analysis uses for example string matching algorithms and/or + Static analysis for important client side components: + uuid: e237176b-bec5-447d-a926-e37d6dd60e4b + risk: Important parts in the source code of the frontend have vulnerabilities. + measure: Usage of static analysis tools for important parts of the frontend + are used. Static analysis uses for example string matching algorithms and/or dataflow analysis. difficultyOfImplementation: knowledge: 2 time: 2 resources: 1 - usefulness: 4 - level: 4 + usefulness: 3 + level: 3 implementation: - uuid: 6a0948a7-4781-4858-9766-f4303971b28b name: eslint @@ -10027,50 +7430,63 @@ Test and Verification: name: jsprime tags: [] url: https://github.com/dpnishant/jsprime + - uuid: 3a8ba0ea-37dc-4124-983b-bbf9b4443d75 + name: '[bdd-mobile-security' + tags: [] + url: https://github.com/ing-bank/bdd-mobile-security-automation-framework + description: '[bdd-mobile-security-automation-framework](https://github.com/ing-bank/bdd-mobile-security-automation-framework)' - uuid: 5b52a841-c281-45fd-b68f-0a93aa6fa398 name: Fortify Extension for Visual Studio Code url: https://marketplace.visualstudio.com/items?itemName=fortifyvsts.fortify-extension-for-vs-code + test-url-expects: + - 404 tags: - ide - sast - uuid: cf1213fd-8bfa-4a97-bf8b-937c93f31005 name: Setting Up the Visual Studio Code Extension Plugin url: https://checkmarx.atlassian.net/wiki/spaces/SD/pages/1759216424/Setting+Up+the+Visual+Studio+Code+Extension+Plugin + test-url-expects: + - 302 tags: - ide - sast - uuid: 3f5a493d-12d0-4468-b9fa-c3e4eae89ffb name: HCL AppScan CodeSweep url: https://marketplace.visualstudio.com/items?itemName=HCLTechnologies.hclappscancodesweep + test-url-expects: + - 404 tags: - ide - sast dependsOn: - - Static analysis for important client side components - - Static analysis for important server side components + - f6f7737f-25a9-4317-8de2-09bf59f29b5b # Defined build process + - 2a44b708-734f-4463-b0cb-86dc46344b2f # Inventory of production components references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - 12.6.1 iso27001-2022: - 8.8 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20applications/subsection/Static%20analysis%20for%20important%20client%20side%20components isImplemented: false evidence: "" comments: "" tags: - none - Static analysis for important client side components: - uuid: e237176b-bec5-447d-a926-e37d6dd60e4b - risk: Important parts in the source code of the frontend have vulnerabilities. - measure: Usage of static analysis tools for important parts of the frontend + Static analysis for important server side components: + uuid: 6c05c837-8c99-46e2-828b-7c903e27dba4 + risk: Important parts in the source code of the middleware have vulnerabilities. + measure: Usage of static analysis tools for important parts of the middleware are used. Static analysis uses for example string matching algorithms and/or dataflow analysis. difficultyOfImplementation: knowledge: 2 time: 2 resources: 1 - usefulness: 3 + usefulness: 4 level: 3 implementation: - uuid: 6a0948a7-4781-4858-9766-f4303971b28b @@ -10084,55 +7500,100 @@ Test and Verification: name: jsprime tags: [] url: https://github.com/dpnishant/jsprime - - uuid: 3a8ba0ea-37dc-4124-983b-bbf9b4443d75 - name: '[bdd-mobile-security' - tags: [] - url: https://github.com/ing-bank/bdd-mobile-security-automation-framework - description: '[bdd-mobile-security-automation-framework](https://github.com/ing-bank/bdd-mobile-security-automation-framework)' - uuid: 5b52a841-c281-45fd-b68f-0a93aa6fa398 name: Fortify Extension for Visual Studio Code url: https://marketplace.visualstudio.com/items?itemName=fortifyvsts.fortify-extension-for-vs-code + test-url-expects: + - 404 tags: - ide - sast - uuid: cf1213fd-8bfa-4a97-bf8b-937c93f31005 name: Setting Up the Visual Studio Code Extension Plugin url: https://checkmarx.atlassian.net/wiki/spaces/SD/pages/1759216424/Setting+Up+the+Visual+Studio+Code+Extension+Plugin + test-url-expects: + - 302 tags: - ide - sast - uuid: 3f5a493d-12d0-4468-b9fa-c3e4eae89ffb name: HCL AppScan CodeSweep url: https://marketplace.visualstudio.com/items?itemName=HCLTechnologies.hclappscancodesweep + test-url-expects: + - 404 tags: - ide - sast dependsOn: - - Defined build process + - f6f7737f-25a9-4317-8de2-09bf59f29b5b # Defined build process + - 2a44b708-734f-4463-b0cb-86dc46344b2f # Inventory of production components references: samm2: - - V-ST-2-A + - V-ST-A-2 + - I-SB-B-3 iso27001-2017: - 12.6.1 iso27001-2022: - 8.8 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20applications/subsection/Static%20analysis%20for%20important%20server%20side%20components isImplemented: false evidence: "" comments: "" tags: - none - Static analysis for important server side components: - uuid: 6c05c837-8c99-46e2-828b-7c903e27dba4 - risk: Important parts in the source code of the middleware have vulnerabilities. - measure: Usage of static analysis tools for important parts of the middleware - are used. Static analysis uses for example string matching algorithms and/or + Test for Patch Deployment Time: + uuid: 0cb2c39a-3cec-4353-b3ab-8d70daf4c9d2 + risk: Automatic PRs for dependencies are overlooked resulting in known vulnerabilities + in production artifacts. + measure: | + Test of the Patch Deployment Time. + This activity is not repeated in the Sub-Dimension "Static depth for infrastructure", but it applies to infrastructure as well. + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 1 + usefulness: 3 + level: 3 + implementation: + - uuid: 00702aca-04d9-49ca-90d0-c32c199b26cb + name: PMD + tags: [] + dependsOn: + - 8ae0b92c-10e0-4602-ba22-7524d6aed488 # Automated PRs for patches + - f6f7737f-25a9-4317-8de2-09bf59f29b5b # Defined build process + references: + samm2: + - V-ST-A-2 + iso27001-2017: + - Not explicitly covered by ISO 27001 - too specific + - 14.2.1 + - 14.2.5 + iso27001-2022: + - Not explicitly covered by ISO 27001 - too specific + - 8.25 + - 8.27 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20applications/subsection/Test%20for%20Patch%20Deployment%20Time + comments: "" + meta: + implementationGuide: Self implementation. This activity is not repeated in + the Sub-Dimension "Static depth for infrastructure", but it applies to infrastructure + as well. + tags: + - patching + Static analysis for all self written components: + uuid: ee68331f-9b1d-4f61-844b-b2ea04753a84 + risk: Parts in the source code of the frontend or middleware have vulnerabilities. + measure: Usage of static analysis tools for all parts of the middleware and + frontend. Static analysis uses for example string matching algorithms and/or dataflow analysis. difficultyOfImplementation: knowledge: 2 time: 2 resources: 1 usefulness: 4 - level: 3 + level: 4 implementation: - uuid: 6a0948a7-4781-4858-9766-f4303971b28b name: eslint @@ -10148,73 +7609,65 @@ Test and Verification: - uuid: 5b52a841-c281-45fd-b68f-0a93aa6fa398 name: Fortify Extension for Visual Studio Code url: https://marketplace.visualstudio.com/items?itemName=fortifyvsts.fortify-extension-for-vs-code + test-url-expects: + - 404 tags: - ide - sast - uuid: cf1213fd-8bfa-4a97-bf8b-937c93f31005 name: Setting Up the Visual Studio Code Extension Plugin url: https://checkmarx.atlassian.net/wiki/spaces/SD/pages/1759216424/Setting+Up+the+Visual+Studio+Code+Extension+Plugin + test-url-expects: + - 302 tags: - ide - sast - uuid: 3f5a493d-12d0-4468-b9fa-c3e4eae89ffb name: HCL AppScan CodeSweep url: https://marketplace.visualstudio.com/items?itemName=HCLTechnologies.hclappscancodesweep + test-url-expects: + - 404 tags: - ide - sast dependsOn: - - Defined build process + - e237176b-bec5-447d-a926-e37d6dd60e4b # Static analysis for important client side components + - 6c05c837-8c99-46e2-828b-7c903e27dba4 # Static analysis for important server side components + - 2a44b708-734f-4463-b0cb-86dc46344b2f # Inventory of production components references: samm2: - - V-ST-2-A + - V-ST-A-2 + - I-SB-B-3 iso27001-2017: - 12.6.1 iso27001-2022: - 8.8 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20applications/subsection/Static%20analysis%20for%20all%20self%20written%20components isImplemented: false evidence: "" comments: "" tags: - none - Stylistic analysis: - uuid: efa52cc8-6c5c-4ba2-a3d2-7164b0402f34 - risk: Unclear or obfuscated code might have unexpected behavior. - measure: Analysis of compliance to style guides of the source code ensures that - source code formatting rules are met (e.g. indentation, loops, ...). + Usage of multiple analyzers: + uuid: 297be001-8d94-41ee-ab29-207020d423c0 + risk: Each vulnerability analyzer has different opportunities. By using just + one analyzer, some vulnerabilities might not be found. + measure: Usage of multiple static tools to find more vulnerabilities. difficultyOfImplementation: - knowledge: 1 - time: 1 - resources: 1 + knowledge: 3 + time: 3 + resources: 5 usefulness: 1 - level: 5 - implementation: - - uuid: 00702aca-04d9-49ca-90d0-c32c199b26cb - name: PMD - tags: [] - - uuid: 0b7ec352-0c36-4de1-8912-617fc6c608fe - name: How to enforce a consistent coding style in your projects - url: https://www.meziantou.net/how-to-enforce-a-consistent-coding-style-in-your-projects.htm - tags: - - ide - - linting - - uuid: aa5ded61-5380-4da6-9474-afc36a397682 - name: In-Depth Linting of Your TypeScript While Coding - url: https://blog.sonarsource.com/in-depth-linting-of-your-typescript-while-coding - tags: - - ide - - linting - - uuid: 94a7a85e-8064-46b4-929a-9e03fa292a9f - name: Super-Linter - tags: - - linting - - scm - url: https://github.com/github/super-linter - description: | - Lint code bases to catch common errors and enforce code style + level: 4 + dependsOn: + - d918cd44-a972-43e9-a974-eff3f4a5dcfe # Software Composition Analysis (server side) + - 07fe8c4f-ae33-4409-b1b2-cf64cfccea86 # Software Composition Analysis (client side) + - ee68331f-9b1d-4f61-844b-b2ea04753a84 # Static analysis for all self written components + implementation: [] references: samm2: - - V-ST-2-A + - V-ST-A-3 iso27001-2017: - 12.6.1 - 14.2.1 @@ -10223,34 +7676,33 @@ Test and Verification: - 8.8 - 8.25 - 8.27 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20applications/subsection/Usage%20of%20multiple%20analyzers isImplemented: false evidence: "" comments: "" tags: - none - Test for Patch Deployment Time: - uuid: d17dbff0-1f10-492a-b4c7-17bb59a0a711 - risk: Automatic PRs for dependencies are overlooked resulting in known vulnerabilities - in production artifacts. - measure: | - Test of the Patch Deployment Time. - This activity is not repeated in the Sub-Dimension "Static depth for infrastructure", but it applies to infrastructure as well. + Dead code elimination: + uuid: a8d7d1f1-fc24-49ab-8fb6-f3a03da9c61d + risk: Dead code increases the attack surface (use of hard coded credentials + and variables, sensitive information) + measure: Collection of unused code and then manual removal of unused code. difficultyOfImplementation: - knowledge: 2 - time: 2 + knowledge: 1 + time: 1 resources: 1 - usefulness: 3 - level: 3 + usefulness: 1 + level: 5 implementation: - uuid: 00702aca-04d9-49ca-90d0-c32c199b26cb name: PMD tags: [] dependsOn: - - Automated PRs for patches - - Defined build process + - f6f7737f-25a9-4317-8de2-09bf59f29b5b # Defined build process references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 14.2.1 @@ -10259,44 +7711,30 @@ Test and Verification: - Not explicitly covered by ISO 27001 - too specific - 8.25 - 8.27 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20applications/subsection/Dead%20code%20elimination comments: "" - meta: - implementationGuide: Self implementation. This activity is not repeated in - the Sub-Dimension "Static depth for infrastructure", but it applies to infrastructure - as well. tags: - - patching - Test for Time to Patch: + - none + Exclusion of source code duplicates: uuid: d17dbff0-1f10-492a-b4c7-17bb59a0a711 - risk: Automatic PRs for dependencies are overlooked resulting in known vulnerabilities - in production artifacts. - measure: |- - Test of the Time to Patch (e.g. based on Mean Time to Close automatic PRs) - This activity is not repeated in the Sub-Dimension "Static depth for infrastructure", but it applies to infrastructure as well. + risk: Duplicates in source code might influence the stability of the application. + measure: Automatic Detection and manual removal of duplicates in source code. difficultyOfImplementation: knowledge: 1 time: 1 resources: 1 - usefulness: 3 - level: 2 + usefulness: 1 + level: 5 implementation: - - uuid: d6292c7d-aab7-43d3-a7c6-1e443b5c1aa4 - name: dependabot - tags: - - auto-pr - - patching - url: https://dependabot.com/ - - uuid: 8228266e-e04f-40ba-94c8-bfadc5310920 - name: renovate - tags: - - auto-pr - - patching - url: https://github.com/renovatebot/renovate + - uuid: 00702aca-04d9-49ca-90d0-c32c199b26cb + name: PMD + tags: [] dependsOn: - - Automated PRs for patches + - f6f7737f-25a9-4317-8de2-09bf59f29b5b # Defined build process references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 14.2.1 @@ -10305,72 +7743,85 @@ Test and Verification: - Not explicitly covered by ISO 27001 - too specific - 8.25 - 8.27 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20applications/subsection/Exclusion%20of%20source%20code%20duplicates comments: "" - meta: - implementationGuide: Usage of a version control platform API (e.g. github - API) can be used to fetch the information. Consider that `Measure libyears` - might be an alternative to this activity. tags: - - patching - Test libyear: - uuid: d17dbff0-1f10-492a-b4c7-17bb59a0a711 - risk: Vulnerabilities in running artifacts stay for long and might get exploited. - measure: Test `libyear`, which provides a good insight how good patch management - is. + - none + Static analysis for all components/libraries: + uuid: f4ff841d-3b2a-45d9-853e-5ec7ecbcb054 + risk: Used components like libraries and legacy applications might have vulnerabilities + measure: Usage of a static analysis for all used components. difficultyOfImplementation: - knowledge: 1 - time: 1 - resources: 1 + knowledge: 2 + time: 4 + resources: 2 usefulness: 3 - level: 2 - implementation: - - uuid: 2fff917f-205e-4eab-2e0e-1fab8c04bf33 - name: libyear - tags: - - patching - - build - url: https://libyear.com/ - description: A simple measure of software dependency freshness. It is a single - number telling you how up-to-date your dependencies are. + level: 5 dependsOn: - - Defined build process + - e237176b-bec5-447d-a926-e37d6dd60e4b # Static analysis for important client side components + - 6c05c837-8c99-46e2-828b-7c903e27dba4 # Static analysis for important server side components + - 2a44b708-734f-4463-b0cb-86dc46344b2f # Inventory of production components + implementation: [] references: samm2: - - V-ST-2-A + - V-ST-A-2 + - I-SB-B-3 iso27001-2017: - - Not explicitly covered by ISO 27001 - too specific - - 14.2.1 - - 14.2.5 + - 12.6.1 iso27001-2022: - - Not explicitly covered by ISO 27001 - too specific - - 8.25 - - 8.27 + - 8.8 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20applications/subsection/Static%20analysis%20for%20all%20components%2Flibraries + isImplemented: false + evidence: "" comments: "" - meta: - implementationGuide: | - `libyear` can be integrated into the build process and flag or even better break the build in case the defined threshold (e.g. 30 years) is reached. - An alternative approach is to determine `libyear` based on deployed artifacts (which requires more effort in implementation). tags: - - patching - Usage of multiple analyzers: - uuid: 297be001-8d94-41ee-ab29-207020d423c0 - risk: Each vulnerability analyzer has different opportunities. By using just - one analyzer, some vulnerabilities might not be found. - measure: Usage of multiple static tools to find more vulnerabilities. + - none + Stylistic analysis: + uuid: efa52cc8-6c5c-4ba2-a3d2-7164b0402f34 + risk: Unclear or obfuscated code might have unexpected behavior. + measure: Analysis of compliance to style guides of the source code ensures that + source code formatting rules are met (e.g. indentation, loops, ...). difficultyOfImplementation: - knowledge: 3 - time: 3 - resources: 5 + knowledge: 1 + time: 1 + resources: 1 usefulness: 1 - level: 4 - dependsOn: - - Software Composition Analysis (server side) - - Software Composition Analysis (client side) - - Static analysis for all self written components - implementation: [] + level: 5 + implementation: + - uuid: 00702aca-04d9-49ca-90d0-c32c199b26cb + name: PMD + tags: [] + - uuid: 0b7ec352-0c36-4de1-8912-617fc6c608fe + name: How to enforce a consistent coding style in your projects + url: https://www.meziantou.net/how-to-enforce-a-consistent-coding-style-in-your-projects.htm + tags: + - ide + - linting + - uuid: 6a0948a7-4781-4858-9766-f4303971b28b + name: eslint + tags: [] + url: https://eslint.org/ + - uuid: aa5ded61-5380-4da6-9474-afc36a397682 + name: In-Depth Linting of Your TypeScript While Coding + url: https://medium.com/@elenavilchik/in-depth-linting-of-your-typescript-while-coding-1d084affbf0 + test-url-expects: + - 403 + tags: + - ide + - linting + - uuid: 94a7a85e-8064-46b4-929a-9e03fa292a9f + name: Super-Linter + tags: + - linting + - scm + url: https://github.com/github/super-linter + description: | + Lint code bases to catch common errors and enforce code style references: samm2: - - V-ST-3-A + - V-ST-A-2 iso27001-2017: - 12.6.1 - 14.2.1 @@ -10379,76 +7830,85 @@ Test and Verification: - 8.8 - 8.25 - 8.27 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20applications/subsection/Stylistic%20analysis isImplemented: false evidence: "" comments: "" tags: - none Static depth for infrastructure: - Analyze logs: - uuid: b217c8bb-5d61-4b41-a675-1083993f83b1 - risk: Not aware of attacks happening. - measure: Check logs for keywords. + Test for stored secrets in build artifacts: + uuid: d5e6303c-d5c6-4d59-b258-a3b9de38a07f + risk: Stored secrets in container images or other build artifacts shouldn't + exists because they might be exposed to unauthorized parties. + measure: Test for secrets in container images and other artifacts difficultyOfImplementation: knowledge: 2 - time: 2 + time: 1 resources: 2 - usefulness: 3 - level: 3 + usefulness: 2 + level: 1 implementation: - - uuid: 1adf1ac0-8572-407b-a358-3976d9a225e2 - name: SigmaHQ + - uuid: d90fefc9-4e5d-420f-ac87-eeb165bf0ee6 + name: truffleHog tags: [] - url: https://github.com/SigmaHQ/sigma + url: https://github.com/trufflesecurity/trufflehog + - uuid: 382873e2-8604-4410-ae5e-b0f5ccdee835 + name: go-pillage-registries + tags: [] + url: https://github.com/nccgroup/go-pillage-registries references: - samm2: [] + samm2: + - V-ST-A-1 iso27001-2017: - - ISO 27001:2017 mapping is missing + - vcs usage is not explicitly covered by ISO 27001 - too specific + - 9.4.3 + - 10.1.2 iso27001-2022: - - ISO 27001:2022 mapping is missing + - vcs usage is not explicitly covered by ISO 27001 - too specific + - 5.17 + - 8.24 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20infrastructure/subsection/Test%20for%20stored%20secrets%20in%20build%20artifacts isImplemented: false evidence: "" comments: "" tags: - none - Correlate known vulnerabilities in infrastructure with new image versions: - uuid: 7de0ae33-6538-45cd-8222-a1475647ba58 - risk: TODO. - measure: TODO + Test for stored secrets in code: + uuid: c6e3c812-56e2-41b0-ae01-b7afc41a004c + risk: Stored secrets in git history or directly in code shouldn't exists because + they might be exposed to unauthorized parties. + measure: Test for secrets in code and git history difficultyOfImplementation: knowledge: 2 - time: 5 - resources: 4 - usefulness: 1 - level: 4 - dependsOn: - - Usage of a maximum lifetime for images + time: 1 + resources: 2 + usefulness: 2 + level: 1 implementation: - - uuid: fab2765d-8d96-4fc6-af96-dc9304ca41dc - name: Anchore.io - tags: [] - url: https://anchore.com/ - - uuid: f10f5423-4dff-4bb7-99c8-9ce214645071 - name: Clair - tags: [] - url: https://github.com/quay/clair - - uuid: d0c6b3a0-b073-44d7-a187-c4ad8eaa6531 - name: OpenSCAP + - uuid: d90fefc9-4e5d-420f-ac87-eeb165bf0ee6 + name: truffleHog tags: [] - url: https://www.open-scap.org/ - - uuid: 04261564-2fcf-4b73-8847-83b0d855e1c5 - name: Vuls + url: https://github.com/trufflesecurity/trufflehog + - uuid: 382873e2-8604-4410-ae5e-b0f5ccdee835 + name: go-pillage-registries tags: [] - url: https://github.com/future-architect/vuls + url: https://github.com/nccgroup/go-pillage-registries references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - - 12.6.1 - - 14.2.1 + - vcs usage is not explicitly covered by ISO 27001 - too specific + - 9.4.3 + - 10.1.2 iso27001-2022: - - 8.8 - - 8.25 + - vcs usage is not explicitly covered by ISO 27001 - too specific + - 5.17 + - 8.24 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20infrastructure/subsection/Test%20for%20stored%20secrets%20in%20code isImplemented: false evidence: "" comments: "" @@ -10473,7 +7933,7 @@ Test and Verification: url: https://kubesec.io references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - System hardening is not explicitly covered by ISO 27001 - too specific - 12.6.1 @@ -10484,6 +7944,8 @@ Test and Verification: - 8.8 - 8.32 - 8.29 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20infrastructure/subsection/Test%20cluster%20deployment%20resources isImplemented: false evidence: "" comments: "" @@ -10501,7 +7963,7 @@ Test and Verification: usefulness: 2 level: 2 implementation: - - url: https://github.com/SDA-SE/clusterscanner + - url: https://github.com/SDA-SE/cluster-image-scanner uuid: 3c9ac78c-0fd4-43f4-8211-c915f9ef685f name: ClusterScanner tags: @@ -10516,66 +7978,154 @@ Test and Verification: in production environments. references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - 12.6.1 - 14.2.5 iso27001-2022: - 8.8 - 8.27 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20infrastructure/subsection/Test%20for%20image%20lifetime isImplemented: false evidence: "" comments: "" tags: - none - Test for known vulnerabilities: - uuid: 26e1c6d5-5632-4ec7-80d2-e564b98732ad - risk: Known vulnerabilities in infrastructure components like container images - might get exploited. - measure: Check for known vulnerabilities + Test of virtualized environments: + uuid: 58825d22-1ce6-4748-af81-0ec9956e4129 + risk: Virtualized environments (e.g. via Container Images) might contains + unsecure configurations. + measure: Test virtualized environments for unsecured configurations. difficultyOfImplementation: knowledge: 2 time: 1 - resources: 1 - usefulness: 4 - level: 4 - description: Subscribing to Github projects and reading release notes might - help. Software Composition Analysis for infrastructure might help, but is - often too fine-granular. + resources: 2 + usefulness: 3 + level: 2 implementation: - - uuid: 7f500e95-2110-44c4-a1f8-cd7ef5d9eb6b - name: https://github.com/aquasecurity/trivy - tags: [] - url: https://github.com/aquasecurity/trivy - - uuid: 8737c6c0-4e90-400a-bf9a-f8e399913b57 - name: Registries like quay + - uuid: 73419fb5-b13d-4242-83ec-86f36c7d73d5 + name: Dive to inspect a container images tags: [] - description: Registries like quay, dockerhub provide (commercial) offerings, - often not suitable for distroless images - - uuid: 500399bd-7dfc-47fd-99d8-b55cefb760a9 - name: Dependency-Track is an intelligent Component Analysis platform that - allows organizations to identify and reduce risk in the software supply - chain. Dependency-Track takes a unique and highly beneficial approach by - leveraging the capabilities of Software Bill of Materials (SBOM). - url: https://github.com/DependencyTrack/dependency-track + url: https://github.com/wagoodman/dive + - url: https://github.com/SDA-SE/cluster-image-scanner + uuid: 3c9ac78c-0fd4-43f4-8211-c915f9ef685f + name: ClusterScanner tags: - - sca - - inventory - - OpenSource - - Supply Chain + - docker + - image + - container - vulnerability + - misconfiguration + - security-tools + - scanning + description: Discover vulnerabilities and container image misconfiguration + in production environments. + references: + samm2: + - V-ST-A-1 + iso27001-2017: + - ISO 27001:2017 mapping is missing + iso27001-2022: + - ISO 27001:2022 mapping is missing + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20infrastructure/subsection/Test%20of%20virtualized%20environments + isImplemented: false + evidence: "" + comments: "" + tags: + - none + Test the cloud configuration: + uuid: 46d6a2a8-f9dc-4c15-9fc8-1723cfecbddc + risk: Standard hardening practices for cloud environments are not performed + leading to vulnerabilities. + measure: With the help of tools, the configuration of virtual environments are + tested. + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 1 + usefulness: 4 + level: 2 + implementation: + - uuid: 8aeefd29-6220-45bf-aead-83eba2e9d055 + name: kube-bench + tags: [] + url: https://github.com/aquasecurity/kube-bench references: samm2: - - V-ST-2-A + - V-ST-A-1 iso27001-2017: + - System hardening is not explicitly covered by ISO 27001 - too specific - 12.6.1 + - 14.2.3 + - 14.2.8 iso27001-2022: + - System hardening is not explicitly covered by ISO 27001 - too specific - 8.8 + - 8.32 + - 8.29 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20infrastructure/subsection/Test%20the%20cloud%20configuration isImplemented: false evidence: "" comments: "" tags: - none + Test the definition of virtualized environments: + uuid: 8fc3de67-7b8d-420b-8d24-f35928cfed6e + risk: The definition of virtualized environments (e.g. via Dockerfile) + might contain unsecure configurations. + measure: Test the definition of virtualized environments for unsecured configurations. + difficultyOfImplementation: + knowledge: 2 + time: 1 + resources: 2 + usefulness: 3 + level: 2 + meta: + implementationGuide: For containier (images), test that the images are following + best practices like distroless or non-root. + implementation: + - uuid: 94d993ad-ef6e-4d9f-b7a8-27ea68dc3005 + name: Dockerfile with hadolint + tags: [] + url: https://github.com/hadolint/hadolint + - uuid: 95b717cd-5ad3-40b5-993b-13a63c382b1b + name: Deployment with kube-score + tags: [] + url: https://github.com/zegl/kube-score + - uuid: eba2685d-2d25-4961-8e4e-2957e7c07c30 + name: dockerfilelint + tags: + - sast + - docker + - dockerfile + url: https://github.com/replicatedhq/dockerfilelint + description: dockerfilelint is an node module that analyzes a Dockerfile and + looks for common traps, mistakes and helps enforce best practices. + references: + samm2: + - V-ST-A-1 + iso27001-2017: + - System hardening, virtual environments are not explicitly covered by ISO + 27001 - too specific + - 12.6.1 + - 14.2.3 + - 14.2.8 + - 14.2.1 + iso27001-2022: + - System hardening, virtual environments are not explicitly covered by ISO + 27001 - too specific + - 8.8 + - 8.32 + - 8.29 + - 8.25 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20infrastructure/subsection/Test%20the%20definition%20of%20virtualized%20environments + isImplemented: false + tags: + - none Test for malware: uuid: 837f8f90-adc2-4e6b-9ebb-60c2ee29494d risk: Third party might include malware. Ether due to the maintainer (e.g. @@ -10590,7 +8140,7 @@ Test and Verification: usefulness: 3 level: 3 implementation: - - url: https://github.com/SDA-SE/clusterscanner + - url: https://github.com/SDA-SE/cluster-image-scanner uuid: 3c9ac78c-0fd4-43f4-8211-c915f9ef685f name: ClusterScanner tags: @@ -10605,11 +8155,13 @@ Test and Verification: in production environments. references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - 12.2.1 iso27001-2022: - 8.7 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20infrastructure/subsection/Test%20for%20malware isImplemented: false evidence: "" comments: "" @@ -10628,72 +8180,34 @@ Test and Verification: implementation: [] references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - 12.6.1 - 14.2.5 - 12.2.1 iso27001-2022: - - 8.8 - - 8.7 - - 8.27 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Test for stored secrets: - uuid: c6e3c812-56e2-41b0-ae01-b7afc41a004c - risk: Stored secrets in git history, in container images or directly in code - shouldn't exists because they might be exposed to unauthorized parties. - measure: Test for secrets in code, container images and history - difficultyOfImplementation: - knowledge: 2 - time: 1 - resources: 2 - usefulness: 2 - level: 1 - implementation: - - uuid: d90fefc9-4e5d-420f-ac87-eeb165bf0ee6 - name: truffleHog - tags: [] - url: https://github.com/dxa4481/truffleHog - - uuid: 382873e2-8604-4410-ae5e-b0f5ccdee835 - name: go-pillage-registries - tags: [] - url: https://github.com/nccgroup/go-pillage-registries - references: - samm2: - - V-ST-1-A - iso27001-2017: - - vcs usage is not explicitly covered by ISO 27001 - too specific - - 9.4.3 - - 10.1.2 - iso27001-2022: - - vcs usage is not explicitly covered by ISO 27001 - too specific - - 5.17 - - 8.24 + - 8.8 + - 8.7 + - 8.27 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20infrastructure/subsection/Test%20for%20new%20image%20version isImplemented: false evidence: "" comments: "" tags: - none - Test of infrastructure components for known vulnerabilities: - uuid: 13367d8f-e37f-4197-a610-9ffca4fde261 - risk: Infrastructure components might have vulnerabilities. - measure: Test for known vulnerabilities in infrastructure components. Often, - the only way to respond to known vulnerabilities in operating system packages - is to accept the risk and wait for a patch. As the patch needs to be applied - fast when it is available, this activity depends on 'Usage of a maximum life - for images'. + Correlate known vulnerabilities in infrastructure with new image versions: + uuid: 7de0ae33-6538-45cd-8222-a1475647ba58 + risk: TODO. + measure: TODO difficultyOfImplementation: knowledge: 2 time: 5 - resources: 2 + resources: 4 usefulness: 1 level: 4 dependsOn: - - Usage of a maximum lifetime for images + - 485a3383-7f2e-4dba-bb84-479377070904 # Usage of a maximum lifetime for images implementation: - uuid: fab2765d-8d96-4fc6-af96-dc9304ca41dc name: Anchore.io @@ -10713,177 +8227,177 @@ Test and Verification: url: https://github.com/future-architect/vuls references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - 12.6.1 - 14.2.1 iso27001-2022: - 8.8 - 8.25 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20infrastructure/subsection/Correlate%20known%20vulnerabilities%20in%20infrastructure%20with%20new%20image%20versions isImplemented: false evidence: "" comments: "" tags: - none - Test of virtualized environments: - uuid: 58825d22-1ce6-4748-af81-0ec9956e4129 - risk: Virtualized environments (e.g. via Container Images) might contains - unsecure configurations. - measure: Test virtualized environments for unsecured configurations. + Software Composition Analysis: + uuid: 26e1c6d5-5632-4ec7-80d2-e564b98732ad + risk: Known vulnerabilities in infrastructure components like container images + might get exploited. + measure: Check for known vulnerabilities difficultyOfImplementation: knowledge: 2 time: 1 - resources: 2 - usefulness: 3 - level: 2 + resources: 1 + usefulness: 4 + level: 4 + description: Subscribing to Github projects and reading release notes might + help. Software Composition Analysis for infrastructure might help, but is + often too fine-granular. implementation: - - uuid: 73419fb5-b13d-4242-83ec-86f36c7d73d5 - name: Dive to inspect a container images + - uuid: 7f500e95-2110-44c4-a1f8-cd7ef5d9eb6b + name: Trivy tags: [] - url: https://github.com/wagoodman/dive - - url: https://github.com/SDA-SE/clusterscanner - uuid: 3c9ac78c-0fd4-43f4-8211-c915f9ef685f - name: ClusterScanner + url: https://github.com/aquasecurity/trivy + - uuid: 8737c6c0-4e90-400a-bf9a-f8e399913b57 + name: Registries like quay + tags: [] + description: Registries like quay, dockerhub provide (commercial) offerings, + often not suitable for distroless images + - uuid: 500399bd-7dfc-47fd-99d8-b55cefb760a9 + name: Dependency-Track + description: | + Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track takes a unique and highly beneficial approach by leveraging the capabilities of Software Bill of Materials (SBOM). + url: https://github.com/DependencyTrack/dependency-track tags: - - docker - - image - - container + - sca + - inventory + - OpenSource + - Supply Chain - vulnerability - - misconfiguration - - security-tools - - scanning - description: Discover vulnerabilities and container image misconfiguration - in production environments. + - inventory references: samm2: - - V-ST-1-A + - V-ST-A-2 iso27001-2017: - - ISO 27001:2017 mapping is missing + - 12.6.1 iso27001-2022: - - ISO 27001:2022 mapping is missing + - 8.8 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20infrastructure/subsection/Software%20Composition%20Analysis isImplemented: false + tags: + - scanning + - sca evidence: "" comments: "" - tags: - - none - Test the cloud configuration: - uuid: 46d6a2a8-f9dc-4c15-9fc8-1723cfecbddc - risk: Standard hardening practices for cloud environments are not performed - leading to vulnerabilities. - measure: With the help of tools, the configuration of virtual environments are - tested. + Test of infrastructure components for known vulnerabilities: + uuid: 13367d8f-e37f-4197-a610-9ffca4fde261 + risk: Infrastructure components might have vulnerabilities. + measure: Test for known vulnerabilities in infrastructure components. Often, + the only way to respond to known vulnerabilities in operating system packages + is to accept the risk and wait for a patch. As the patch needs to be applied + fast when it is available, this activity depends on 'Usage of a maximum life + for images'. difficultyOfImplementation: knowledge: 2 - time: 2 - resources: 1 - usefulness: 4 - level: 2 + time: 5 + resources: 2 + usefulness: 1 + level: 4 + dependsOn: + - 485a3383-7f2e-4dba-bb84-479377070904 # Usage of a maximum lifetime for images implementation: - - uuid: 8aeefd29-6220-45bf-aead-83eba2e9d055 - name: kube-bench + - uuid: fab2765d-8d96-4fc6-af96-dc9304ca41dc + name: Anchore.io tags: [] - url: https://github.com/aquasecurity/kube-bench + url: https://anchore.com/ + - uuid: f10f5423-4dff-4bb7-99c8-9ce214645071 + name: Clair + tags: [] + url: https://github.com/quay/clair + - uuid: d0c6b3a0-b073-44d7-a187-c4ad8eaa6531 + name: OpenSCAP + tags: [] + url: https://www.open-scap.org/ + - uuid: 04261564-2fcf-4b73-8847-83b0d855e1c5 + name: Vuls + tags: [] + url: https://github.com/future-architect/vuls references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - - System hardening is not explicitly covered by ISO 27001 - too specific - 12.6.1 - - 14.2.3 - - 14.2.8 + - 14.2.1 iso27001-2022: - - System hardening is not explicitly covered by ISO 27001 - too specific - 8.8 - - 8.32 - - 8.29 + - 8.25 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Static%20depth%20for%20infrastructure/subsection/Test%20of%20infrastructure%20components%20for%20known%20vulnerabilities isImplemented: false evidence: "" comments: "" tags: - none - Test the definition of virtualized environments: - uuid: 8fc3de67-7b8d-420b-8d24-f35928cfed6e - risk: The definition of virtualized environments (e.g. via Dockerfile) - might contain unsecure configurations. - measure: Test the definition of virtualized environments for unsecured configurations. + Test Intensity: + Default settings for intensity: + uuid: ab0a4b51-3b18-43f1-a6fc-a98e4b28453d + risk: Time pressure and ignorance might lead to false predictions for the test + intensity. + measure: The intensity of the used tools are not modified to save time. difficultyOfImplementation: - knowledge: 2 + knowledge: 1 time: 1 - resources: 2 - usefulness: 3 - level: 2 - meta: - implementationGuide: For containier (images), test that the images are following - best practices like distroless or non-root. - implementation: - - uuid: 94d993ad-ef6e-4d9f-b7a8-27ea68dc3005 - name: Dockerfile with hadolint - tags: [] - url: https://github.com/hadolint/hadolint - - uuid: 95b717cd-5ad3-40b5-993b-13a63c382b1b - name: Deployment with kube-score - tags: [] - url: https://github.com/zegl/kube-score - - uuid: eba2685d-2d25-4961-8e4e-2957e7c07c30 - name: dockerfilelint - tags: - - sast - - docker - - dockerfile - url: https://github.com/replicatedhq/dockerfilelint - description: dockerfilelint is an node module that analyzes a Dockerfile and - looks for common traps, mistakes and helps enforce best practices. + resources: 1 + usefulness: 1 + level: 1 + implementation: [] references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - - System hardening, virtual environments are not explicitly covered by ISO - 27001 - too specific - 12.6.1 - - 14.2.3 - - 14.2.8 - 14.2.1 + - 14.2.5 iso27001-2022: - - System hardening, virtual environments are not explicitly covered by ISO - 27001 - too specific - 8.8 - - 8.32 - - 8.29 - 8.25 + - 8.27 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Test%20Intensity/subsection/Default%20settings%20for%20intensity isImplemented: false evidence: "" comments: "" tags: - none - Test-Intensity: - Creation and application of a testing concept: - uuid: 79ef8103-e1ed-4055-8df8-fd2b2015bebe - risk: Scans might use a too small or too high test intensity. - measure: A testing concept considering the amount of time per scan/intensity - is created and applied. A dynamic analysis needs more time than a static analysis. - The dynamic scan, depending on the test intensity might be performed on every - commit, every night, every week or once in a month. + Regular automated tests: + uuid: 598897a2-358e-441f-984c-e12ec4f6110a + risk: After pushing source code to the version control system, any delay in + receiving feedback on defects makes them harder for the developer to remediate. + measure: On each push and/or at given intervals automatic security tests are + performed. difficultyOfImplementation: - knowledge: 3 - time: 3 - resources: 3 + knowledge: 1 + time: 1 + resources: 1 usefulness: 2 - level: 4 + level: 2 implementation: [] references: samm2: - - V-ST-2-A + - I-SB-A-3 + - V-ST-A-3 iso27001-2017: - - 14.2.2 - 14.2.3 - - 14.2.1 - - 14.2.5 - - 12.6.1 + - 14.2.8 + - 14.2.9 iso27001-2022: - - 8.25 - 8.32 - - 8.27 - - 8.8 + - 8.29 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Test%20Intensity/subsection/Regular%20automated%20tests isImplemented: false evidence: "" comments: "" @@ -10906,35 +8420,7 @@ Test and Verification: implementation: [] references: samm2: - - V-ST-2-A - iso27001-2017: - - 12.6.1 - - 14.2.1 - - 14.2.5 - iso27001-2022: - - 8.8 - - 8.25 - - 8.27 - isImplemented: false - evidence: "" - comments: "" - tags: - - none - Default settings for intensity: - uuid: ab0a4b51-3b18-43f1-a6fc-a98e4b28453d - risk: Time pressure and ignorance might lead to false predictions for the test - intensity. - measure: The intensity of the used tools are not modified to safe time. - difficultyOfImplementation: - knowledge: 1 - time: 1 - resources: 1 - usefulness: 1 - level: 1 - implementation: [] - references: - samm2: - - V-ST-1-A + - V-ST-A-2 iso27001-2017: - 12.6.1 - 14.2.1 @@ -10943,6 +8429,8 @@ Test and Verification: - 8.8 - 8.25 - 8.27 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Test%20Intensity/subsection/Deactivating%20of%20unneeded%20tests isImplemented: false evidence: "" comments: "" @@ -10959,11 +8447,11 @@ Test and Verification: time: 3 resources: 5 usefulness: 3 - level: 1 + level: 3 implementation: [] references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - 12.6.1 - 14.2.1 @@ -10972,34 +8460,43 @@ Test and Verification: - 8.8 - 8.25 - 8.27 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Test%20Intensity/subsection/High%20test%20intensity isImplemented: false evidence: "" comments: "" tags: - none - Regular tests: - uuid: 598897a2-358e-441f-984c-e12ec4f6110a - risk: After pushing source code to the version control system, any delay in - receiving feedback on defects makes them harder for the developer to remediate. - measure: On each push and/or at given intervals automatic security tests are - performed. + Creation and application of a testing concept: + uuid: 79ef8103-e1ed-4055-8df8-fd2b2015bebe + risk: Scans might use a too small or too high test intensity. + measure: A testing concept considering the amount of time per scan/intensity + is created and applied. A dynamic analysis needs more time than a static analysis. + The dynamic scan, depending on the test intensity might be performed on every + commit, every night, every week or once in a month. difficultyOfImplementation: - knowledge: 1 - time: 1 - resources: 1 + knowledge: 3 + time: 3 + resources: 3 usefulness: 2 - level: 2 + level: 4 implementation: [] references: samm2: - - I-SB-3-A + - V-ST-A-2 iso27001-2017: + - 14.2.2 - 14.2.3 - - 14.2.8 - - 14.2.9 + - 14.2.1 + - 14.2.5 + - 12.6.1 iso27001-2022: + - 8.25 - 8.32 - - 8.29 + - 8.27 + - 8.8 + openCRE: + - https://www.opencre.org/node/standard/DevSecOps%20Maturity%20Model%20%28DSOMM%29/section/Test%20Intensity/subsection/Creation%20and%20application%20of%20a%20testing%20concept isImplemented: false evidence: "" comments: "" diff --git a/src/assets/YAML/default/BuildAndDeployment/Build.yaml b/src/assets/YAML/default/BuildAndDeployment/Build.yaml index 4a75e22..6f61666 100755 --- a/src/assets/YAML/default/BuildAndDeployment/Build.yaml +++ b/src/assets/YAML/default/BuildAndDeployment/Build.yaml @@ -28,10 +28,10 @@ Build and Deployment: level: 2 implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/ci-cd-tools - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/container-technologi + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/container-technology references: samm2: - - I-SB-2-A + - I-SB-A-2 iso27001-2017: - 14.2.6 iso27001-2022: @@ -41,34 +41,40 @@ Build and Deployment: comments: "" Defined build process: uuid: f6f7737f-25a9-4317-8de2-09bf59f29b5b + description: | + A *build process* includes more than just compiling your source code. It also covers: + - Managing (third party) dependencies + - Environment configuration + - Running unit and integration tests + - Security scanning and compliance checks + - Artifact creation and storage + - Deployment preparation + + Basing the build process on human memory may lead to inconsistencies and security misconfigurations. + + A *defined build process* can automate these steps to ensure consistency, avoiding accidental omissions or misconfigurations. Use tools such as Jenkins, GitHub Actions, GitLab CI, or Maven to codify the process. + + A simplified, but still a *defined build process*, may be a checklist of the steps to be performed. risk: - Performing builds without a defined process is error prone; for example, - as a result of incorrect security related configuration. + Without a defined and automated build process the risk increase for accidental mistakes, forgetting test activities, and insecure misconfigurations. measure: - A well defined build process lowers the possibility of errors during - the build process. - description: | - Sample evidence as an attribute in the yaml: The build process is defined in [REPLACE-ME Pipeline](https://replace-me/jenkins/job) - in the folder _vars_. Projects are using a _Jenkinsfile_ to use the - defined process. + Find a tool that suits your environment. Add your manual build steps, include steps for running tests, scanning and preparation for deployment. + assessment: | + - Show your build pipeline configuration (e.g., Jenkinsfile, GitHub Actions workflow) and an exemplary job (build + test + security scan). + level: 1 difficultyOfImplementation: knowledge: 2 time: 3 resources: 2 usefulness: 4 - level: 1 - assessment: | - - Show your build pipeline and an exemplary job (build + test). - - Show that every team member has access. - - Show that failed jobs are fixed. - - Credits: AppSecure-nrw [Security Belts](https://github.com/AppSecure-nrw/security-belts/) implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/jenkins + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/maven - $ref: src/assets/YAML/default/implementations.yaml#/implementations/ci-cd-tools - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/container-technologi + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/container-technology references: samm2: - - I-SB-1-A + - I-SB-A-1 iso27001-2017: - 12.1.1 - 14.2.2 @@ -101,16 +107,16 @@ Build and Deployment: resources: 2 usefulness: 3 level: 2 + tags: + - inventory implementation: - - Container technology automatically creates a hash for images, which can be - used. - - Immutable images are an other way, e.g. by using a registry, which doesn't - allow overriding of images. + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/signing-of-containers + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/immutable-images dependsOn: - Defined build process references: samm2: - - I-SB-1-A + - I-SB-B-1 iso27001-2017: - 14.2.6 iso27001-2022: @@ -140,9 +146,13 @@ Build and Deployment: resources: 3 usefulness: 3 level: 2 - implementation: [] + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/trivy + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/syft references: - samm2: [] + samm2: + - I-SB-B-1 + - D-TA-A-1 iso27001-2017: - 8.1 - 8.2 @@ -150,6 +160,7 @@ Build and Deployment: - 5.9 - 5.12 isImplemented: false + tags: ["inventory", "scanning", "sca"] evidence: "" comments: "" Signing of artifacts: @@ -180,7 +191,7 @@ Build and Deployment: - Pinning of artifacts references: samm2: - - I-SB-1-A + - I-SB-A-1 iso27001-2017: - 14.2.6 iso27001-2022: @@ -207,7 +218,7 @@ Build and Deployment: - Defined build process references: samm2: - - I-SB-2-A + - I-SB-A-2 iso27001-2017: - 14.2.6 iso27001-2022: diff --git a/src/assets/YAML/default/BuildAndDeployment/Deployment.yaml b/src/assets/YAML/default/BuildAndDeployment/Deployment.yaml index 56bbba6..4e5b445 100755 --- a/src/assets/YAML/default/BuildAndDeployment/Deployment.yaml +++ b/src/assets/YAML/default/BuildAndDeployment/Deployment.yaml @@ -15,12 +15,12 @@ Build and Deployment: usefulness: 2 level: 5 implementation: - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/blue-green-deploymen + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/blue-green-deployment dependsOn: - Smoke Test references: samm2: - - TODO + - I-SD-A-3 iso27001-2017: - 17.2.1 # Availability of information processing facilities - 12.1.1 # Documented operational procedures @@ -38,6 +38,70 @@ Build and Deployment: isImplemented: false evidence: "" comments: "" + Canary deployment: + uuid: c4204a32-2545-4424-b524-d1cc52b46abd + description: |- + A *canary deployment* gradually shifts a small fraction of production + traffic to a new artifact version while monitoring service-level + indicators and security signals. If error rates, latency, or security + scanners (such as DAST probes against the canary fleet) report + anomalies, traffic is rolled back automatically before the new + version reaches the broader production population. + + Compared to *Blue/Green Deployment*, canary requires only a small + delta in infrastructure cost (commonly 5-10% additional capacity + rather than a doubled environment) but demands more sophisticated + traffic-control infrastructure such as a service mesh, an + application load balancer with weighted routing, or a feature-flag + platform. + risk: |- + A new artifact version can introduce regressions or security + issues. Promoting it to 100% of production traffic in one step + exposes the entire user population to those issues before they + can be detected. + measure: |- + Adopt a canary deployment strategy in which a small percentage of + production traffic (commonly 1-10%) is routed to the new artifact + version for a defined observation window. Promotion to higher + traffic percentages is gated on automated SLI checks (error rate, + latency, saturation) and security checks (DAST, runtime anomaly + detection). Rollback must be automated and triggered by gate + failure without human intervention. + assessment: | + - Canary stage exists in the deployment pipeline with a configured + initial traffic percentage and observation window. + - Automated promotion and rollback gates are defined based on SLIs + and security signals. + - Audit logs of canary deployments and their promotion or rollback + decisions are retained. + difficultyOfImplementation: + knowledge: 3 + time: 2 + resources: 2 + usefulness: 3 + level: 4 + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/canary-deployment + dependsOn: + - 67e1a9aa-9fbf-4ec5-a2de-400f01960c51 # Automated deployment process + references: + samm2: + - I-SD-A-3 + iso27001-2017: + - 12.1.2 # Change management + - 12.5.1 # Installation of software on operational systems + - 14.2.2 # System change control procedures + - 14.2.9 # System acceptance testing + - 17.2.1 # Availability of information processing facilities + iso27001-2022: + - 8.14 + - 8.19 + - 8.29 + - 8.31 + - 8.32 + isImplemented: false + evidence: "" + comments: "" Defined decommissioning process: uuid: da4ff665-dcb9-4e93-9d20-48cdedc50fc2 description: |- @@ -49,7 +113,8 @@ Build and Deployment: Unused applications are not maintained and may contain vulnerabilities. Once exploited they can be used to attack other applications or to perform lateral movements within the organization. - measure: A clear decommissioning process ensures the removal of unused applications. + measure: |- + A clear decommissioning process ensures the removal of unused applications from the `Inventory of production components` and if implemented from `Inventory of production artifacts`. difficultyOfImplementation: knowledge: 1 time: 2 @@ -58,7 +123,7 @@ Build and Deployment: level: 2 references: samm2: - - O-OM-2-B + - O-OM-B-2 iso27001-2017: - 11.2.7 iso27001-2022: @@ -68,36 +133,68 @@ Build and Deployment: comments: "" Defined deployment process: uuid: 74938a3f-1269-49b9-9d0f-c43a79a1985a + description: | + A *defined deployment process* is a documented and standardized procedure for releasing software into production, ensuring consistency and reducing the risk of errors. risk: >- - Deployment of insecure or malfunctioning artifacts. + Deployments relying on human memory are prone to errors, making experienced long-ter staff critical. measure: >- - Defining a deployment process ensures that there are - established criteria in terms of functionalities, - security, compliance, and performance, - and that the artifacts meet them. + Establish a written deployment process documented in README files, wikis, or implemented as executable scripts and automated steps. + assessment: | + - Deployment process is documented and available to relevant staff + - Logs of deployments are documented and availabe to relevant staff + level: 1 + difficultyOfImplementation: + knowledge: 1 + time: 1 + resources: 1 + usefulness: 1 + dependsOn: + - f6f7737f-25a9-4317-8de2-09bf59f29b5b # Def. Build Process + - 066084c6-1135-4635-9cc5-9e75c7c5459f # Version control + implementation: + references: + samm2: + - I-SD-A-1 + iso27001-2017: + - 12.1.1 + - 14.2.2 + iso27001-2022: + - 5.37 + - 8.32 + Automated deployment process: + uuid: 67e1a9aa-9fbf-4ec5-a2de-400f01960c51 + description: | + An *automated deployment process* implements the defined deployment steps using automation tools, ensuring consistency, auditability, and minimizing the risk of human errors or unauthorized changes. + risk: >- + Deployments relying on manual routines increase the risk of errors, insecure configurations, or deploying malfunctioning artifacts. + measure: >- + Automating the deployment process enforces predefined criteria for security, compliance, and performance, ensuring reliable artifact delivery. + assessment: | + - Deployment process is documented and available to relevant staff + - All deployment steps are automated + - Provide audit logs or evidence of deployments + level: 1 difficultyOfImplementation: knowledge: 2 time: 2 - resources: 1 + resources: 2 usefulness: 4 - level: 1 dependsOn: - - Continuous Integration + - f6f7737f-25a9-4317-8de2-09bf59f29b5b # Def. Build Process + - 74938a3f-1269-49b9-9d0f-c43a79a1985a # Def. Deployment Process implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/ci-cd-tools + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/jenkins - $ref: src/assets/YAML/default/implementations.yaml#/implementations/docker references: samm2: - - I-SD-1-A + - I-SD-A-1 iso27001-2017: - 12.1.1 - 14.2.2 iso27001-2022: - 5.37 - 8.32 - isImplemented: false - evidence: "" - comments: "" Environment depending configuration parameters (secrets): uuid: df428c9d-efa0-4226-9f47-a15bb53f822b risk: >- @@ -116,10 +213,10 @@ Build and Deployment: usefulness: 4 level: 2 implementation: - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/hasicorp-vault + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/hashicorp-vault references: samm2: - - I-SD-1-B + - I-SD-B-1 iso27001-2017: - 9.4.5 - 14.2.6 @@ -129,8 +226,8 @@ Build and Deployment: d3f: - ApplicationConfigurationHardening isImplemented: false - evidence: "" - comments: "" + tags: + - secret Handover of confidential parameters: uuid: 94a96f79-8bd6-4904-97c0-994ff88f176a risk: @@ -153,7 +250,7 @@ Build and Deployment: - Environment depending configuration parameters (secrets) references: samm2: - - I-SD-2-B + - I-SD-B-2 iso27001-2017: - 14.1.3 - 13.1.3 @@ -169,19 +266,19 @@ Build and Deployment: d3f: - ApplicationConfigurationHardening isImplemented: false - evidence: "" - comments: "" - Inventory of dependencies: + tags: + - secret + Inventory of production dependencies: uuid: 13e9757e-58e2-4277-bc0f-eadc674891e6 risk: - In case a vulnerability of severity high or critical is known by the organization, - it needs to be known where an artifacts with that vulnerability is deployed + Delayed identification of components and their vulnerabilities in production. + In case a vulnerability is known by the organization, it needs to be known where an artifacts with that vulnerability is deployed with which dependencies. measure: - A documented inventory of dependencies used in images and containers + A documented inventory of dependencies used in artifacts like container images and containers exists. dependsOn: - - Defined deployment process + - 83057028-0b77-4d2e-8135-40969768ae88 # Inventory of production artifacts - SBOM of components difficultyOfImplementation: knowledge: 2 @@ -190,47 +287,94 @@ Build and Deployment: usefulness: 3 level: 3 implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/backstage - $ref: src/assets/YAML/default/implementations.yaml#/implementations/dependencyTrack + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/image-metadata-collector references: samm2: - - I-SD-2-A + - I-SB-B-3 + - I-SB-B-2 + - I-SB-B-1 iso27001-2017: - 8.1 - 8.2 iso27001-2022: - 5.9 - 5.12 - isImplemented: false - evidence: "" comments: "" - Inventory of running artifacts: + tags: + - inventory + - sbom + - scanning + - sca + Inventory of production components: + uuid: 2a44b708-734f-4463-b0cb-86dc46344b2f + description: | + An inventory of production components is a complete, up-to-date list of all applications running in production. This enables effective vulnerability management, incident response, and compliance. Without it, organizations risk running unmaintained or unauthorized software. + risk: |- + An organization is unaware of components like applications in production. Not knowing existing applications in production leads to not assessing it. + measure: |- + A documented inventory of components in production exists (gathered manually or automatically). For example a manually created document with applications in production. + In a kubernetes cluster, namespaces can be automatically gathered and documented, e.g. in a JSON in a S3 bucket/git repository, dependency track. + assessment: | + - Inventory of all production applications with application name, owner, and date of last review + - Inventory is accessible to development, security and operations teams + dependsOn: + - 67e1a9aa-9fbf-4ec5-a2de-400f01960c51 # Automated deployment process + level: 1 + difficultyOfImplementation: + knowledge: 1 + time: 1 + resources: 1 + usefulness: 4 + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/backstage + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/dependencyTrack + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/image-metadata-collector + references: + samm2: + - I-SB-B-1 + - D-TA-B-1 + iso27001-2017: + - 8.1 + - 8.2 + iso27001-2022: + - 5.9 + - 5.12 + tags: + - inventory + Inventory of production artifacts: uuid: 83057028-0b77-4d2e-8135-40969768ae88 risk: In case a vulnerability of severity high or critical exists, it needs to be known where an artifacts (e.g. container image) with that vulnerability is deployed. - measure: A documented inventory or a possibility to gather the needed information. + measure: A documented inventory of artifacts in production like container images exists (gathered manually or automatically). dependsOn: - - Defined deployment process + - 67e1a9aa-9fbf-4ec5-a2de-400f01960c51 # Automated deployment process + - 2a44b708-734f-4463-b0cb-86dc46344b2f # Inventory of production components difficultyOfImplementation: knowledge: 2 time: 2 resources: 3 usefulness: 3 - level: 3 - implementation: [] + level: 2 + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/backstage + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/dependencyTrack + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/image-metadata-collector references: samm2: - - I-SD-2-A + - I-SB-B-1 + - D-TA-B-1 iso27001-2017: - 8.1 - 8.2 iso27001-2022: - 5.9 - 5.12 - isImplemented: false - evidence: "" - comments: "" + tags: + - inventory Rolling update on deployment: uuid: 85d52588-f542-4225-a338-20dc22a5508d risk: While a deployment is performed, the application can not be reached. @@ -246,10 +390,11 @@ Build and Deployment: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/webserver - $ref: src/assets/YAML/default/implementations.yaml#/implementations/rolling-update dependsOn: - - Defined deployment process + - 67e1a9aa-9fbf-4ec5-a2de-400f01960c51 # Automated deployment process references: samm2: - - I-SD-1-A + - I-SD-A-2 + - I-SD-A-3 iso27001-2017: - 12.5.1 - 14.2.2 @@ -281,7 +426,8 @@ Build and Deployment: - Defined build process references: samm2: - - I-SD-2-A + - I-SD-A-2 + - I-SD-A-3 iso27001-2017: - 14.3.1 - 14.2.8 @@ -313,7 +459,8 @@ Build and Deployment: dependsOn: - Same artifact for environments references: - samm2: [] + samm2: + - I-SD-A-2 iso27001-2017: - 14.3.1 - 14.2.8 @@ -347,7 +494,7 @@ Build and Deployment: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/packj references: samm2: - - O-EM-1-A + - O-EM-A-1 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 14.2.1 diff --git a/src/assets/YAML/default/BuildAndDeployment/PatchManagement.yaml b/src/assets/YAML/default/BuildAndDeployment/PatchManagement.yaml index 22aac63..3360754 100755 --- a/src/assets/YAML/default/BuildAndDeployment/PatchManagement.yaml +++ b/src/assets/YAML/default/BuildAndDeployment/PatchManagement.yaml @@ -4,20 +4,27 @@ Build and Deployment: Patch Management: A patch policy is defined: uuid: 99415139-6b50-441b-89e1-0aa59accd43d - risk: Vulnerabilities in running artifacts stay for long and might get exploited. + description: | + A patch policy defines how and when software components, images, and dependencies are updated. A patch policy ensures that all these artifacts are regularly reviewed and updated, reducing the window of exposure to known threats. The policy should specify the frequency, responsibilities, and documentation requirements for patching. + risk: Vulnerabilities in running artifacts may persist for a long time and might be exploited. measure: - A patch policy for all artifacts (e.g. in images) is defined. How often + Define a patch policy for all artifacts (e.g. in images) is defined. How often is an image rebuilt? + assessment: | + - Patch policy is documented and accessible to relevant staff. + - The policy defines patch frequency and responsible roles. + - Patch actions and exceptions are logged and reviewed. + - Evidence of regular patching and policy review is available. + level: 1 difficultyOfImplementation: knowledge: 3 time: 1 resources: 2 usefulness: 4 - level: 1 implementation: [] references: samm2: - - O-EM-1-B + - O-EM-B-1 iso27001-2017: - 12.6.1 - 12.5.1 @@ -33,22 +40,27 @@ Build and Deployment: - patching Automated PRs for patches: uuid: 8ae0b92c-10e0-4602-ba22-7524d6aed488 - risk: - Components with known (or unknown) vulnerabilities might stay for long and get exploited, - even when a patch is available. - measure: - Fast patching of third party component is needed. The DevOps way is - to have an automated pull request for new components. This includes + description: | + Automated PRs for patches ensure that updates for outdated or vulnerable dependencies are created and proposed without manual intervention. Tools continuously monitor for new versions or security advisories and immediately generate pull requests to update affected components in code, container images, or infrastructure. This process ensures that available patches are quickly visible to developers and can be reviewed and merged with minimal delay, reducing the risk window for known vulnerabilities. + risk: | + Components with known vulnerabilities might persist for a long time and be exploited, even when a patch is available. + measure: | + Fast patching of third-party components is needed. The DevOps way is to have an automated pull request for new components. This includes: * Applications - * Virtualized operating system components (e.g. container images) - * Operating Systems - * Infrastructure as Code/GitOps (e.g. argocd based on a git repository or terraform) + * Virtualized operating system components (e.g., container images) + * Operating systems + * Infrastructure as Code/GitOps (e.g., ArgoCD based on a git repository or Terraform) + assessment: | + - Automated PR tooling is enabled for all relevant repositories. + - PRs are created automatically for outdated or vulnerable dependencies. + - PRs are reviewed and merged according to the defined patch policy. + - Evidence of automated PRs and patching activity is available. + level: 1 difficultyOfImplementation: knowledge: 2 time: 2 resources: 2 - usefulness: 5 - level: 1 + usefulness: 4 implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/dependabot - $ref: src/assets/YAML/default/implementations.yaml#/implementations/jenkins @@ -57,13 +69,13 @@ Build and Deployment: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/renovate references: samm2: - - O-EM-1-B + - O-EM-B-1 iso27001-2017: - 12.6.1 - 14.2.5 iso27001-2022: - - 8.8 - - 8.27 + - "8.8" + - "8.27" comments: "" tags: - patching @@ -92,7 +104,7 @@ Build and Deployment: implementation: [] references: samm2: - - O-EM-1-B + - O-EM-B-2 iso27001-2017: - 12.6.1 iso27001-2022: @@ -128,7 +140,7 @@ Build and Deployment: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/distroless-usage references: samm2: - - I-SB-2 + - I-SB-B-2 iso27001-2017: - hardening is missing in ISO 27001 - 14.2.1 @@ -168,7 +180,7 @@ Build and Deployment: implementation: [] references: samm2: - - O-EM-1-B + - O-EM-B-1 iso27001-2017: - 12.6.1 iso27001-2022: @@ -203,7 +215,7 @@ Build and Deployment: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/sample-concept-1 references: samm2: - - O-EM-2-B + - O-EM-B-2 iso27001-2017: - 12.6.1 iso27001-2022: @@ -236,7 +248,7 @@ Build and Deployment: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/renovate references: samm2: - - O-EM-2-B + - O-EM-B-2 iso27001-2017: - 12.6.1 iso27001-2022: @@ -244,7 +256,7 @@ Build and Deployment: comments: "" tags: - patching - Automated deployment of automated PRs: + Automated deployment of automated PRs: &automerge-PR uuid: 08f27c26-2c6a-47fe-9458-5e88f188085d <<: *automerge-PR risk: @@ -262,4 +274,3 @@ Build and Deployment: implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/terraform - $ref: src/assets/YAML/default/implementations.yaml#/implementations/argocd - references: diff --git a/src/assets/YAML/default/CultureAndOrganization/Design.yaml b/src/assets/YAML/default/CultureAndOrganization/Design.yaml index 22ec238..62fc8b8 100755 --- a/src/assets/YAML/default/CultureAndOrganization/Design.yaml +++ b/src/assets/YAML/default/CultureAndOrganization/Design.yaml @@ -40,7 +40,7 @@ Culture and Organization: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/threat-matrix-for-storage references: samm2: - - D-TA-2-B + - D-TA-B-2 iso27001-2017: - Not explicitly covered by ISO 27001 - May be part of risk assessment @@ -71,7 +71,8 @@ Culture and Organization: implementation: [] references: samm2: - - D-TA-2-B + - D-TA-B-1 + - D-TA-A-2 iso27001-2017: - Not explicitly covered by ISO 27001 - May be part of risk assessment @@ -87,25 +88,6 @@ Culture and Organization: comments: "" Conduction of simple threat modeling on technical level: uuid: 47419324-e263-415b-815d-e7161b6b905e - risk: - Technical related threats are discovered too late in the development and - deployment process. - measure: - Threat modeling of technical features is performed during the product - sprint planning. - difficultyOfImplementation: - knowledge: 2 - time: 3 - resources: 1 - usefulness: 3 - level: 1 - implementation: - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/whiteboard - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/miro-or-any-other-c - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/draw-io - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/threat-modeling-play - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-samm - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/threat-matrix-for-storage description: | # OWASP SAMM Description Threat modeling is a structured activity for identifying, evaluating, and managing system threats, architectural design flaws, and recommended security mitigations. It is typically done as part of the design phase or as part of a security assessment. @@ -149,9 +131,29 @@ Culture and Organization: GraphQL queries are dynamically translated to SQL, Elasticsearch and NoSQL queries. Access to data is protected with basic auth set to _1234:1234_ for development purposes. Source: OWASP Project Integration Project + risk: + Technical related threats are discovered too late in the development and deployment process. + measure: | + Perform threat modeling of technical features during product sprint planning using simple checklists and diagrams. Document identified threats and mitigations for new or changed functionality. + assessment: | + - Evidence of threat modeling activities exists for high-risk applications, including annotated diagrams and documented threats/mitigations. + - Activities are performed during sprint planning and involve relevant stakeholders. Outcomes are recorded and accessible for review. + level: 1 + difficultyOfImplementation: + knowledge: 2 + time: 3 + resources: 1 + usefulness: 3 + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/whiteboard + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/miro-or-any-other-c + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/draw-io + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/threat-modeling-play + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-samm + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/threat-matrix-for-storage references: samm2: - - D-TA-2-B + - D-TA-B-2 iso27001-2017: - Not explicitly covered by ISO 27001 - May be part of risk assessment @@ -181,10 +183,11 @@ Culture and Organization: dependsOn: - Creation of simple abuse stories implementation: - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/don-t-forget-evil-u + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/don-t-forget-evil-user-stories references: samm2: - - D-TA-2-B + - D-TA-B-2 + - V-RT-B-2 iso27001-2017: - Not explicitly covered by ISO 27001 - May be part of project management @@ -213,13 +216,13 @@ Culture and Organization: usefulness: 4 level: 3 implementation: - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/don-t-forget-evil-u + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/don-t-forget-evil-user-stories dependsOn: - Conduction of simple threat modeling on technical level - Creation of threat modeling processes and standards references: samm2: - - D-TA-2-B + - D-TA-B-2 iso27001-2017: - Not explicitly covered by ISO 27001 - May be part of project management @@ -256,7 +259,8 @@ Culture and Organization: - Conduction of simple threat modeling on technical level references: samm2: - - D-TA-3-B + - D-TA-B-3 + - D-TA-B-2 iso27001-2017: - Not explicitly covered by ISO 27001 - May be part of risk assessment @@ -273,7 +277,7 @@ Culture and Organization: Information security targets are communicated: uuid: 1b9281b9-48e2-4c01-9ac6-9db9931c4885 risk: - Employees don't known their organizations security targets. Therefore + Employees don't know their organizations security targets. Therefore security is not considered during development and administration as much as it should be. measure: @@ -287,7 +291,8 @@ Culture and Organization: level: 2 implementation: [] references: - samm2: [] + samm2: + - G-SM-A-2 iso27001-2017: - 5.1.1 - 7.2.1 diff --git a/src/assets/YAML/default/CultureAndOrganization/EducationAndGuidance.yaml b/src/assets/YAML/default/CultureAndOrganization/EducationAndGuidance.yaml index 3229463..4395b7b 100755 --- a/src/assets/YAML/default/CultureAndOrganization/EducationAndGuidance.yaml +++ b/src/assets/YAML/default/CultureAndOrganization/EducationAndGuidance.yaml @@ -4,32 +4,52 @@ Culture and Organization: Education and Guidance: Ad-Hoc Security trainings for software developers: uuid: 12c90cc6-3d58-4d9b-82ff-d469d2a0c298 - risk: - Understanding security is hard and personnel needs to be trained on it. - Otherwise, flaws like an SQL Injection might be introduced into the software - which might get exploited. - measure: - Provide security awareness training for all personnel involved in software - development Ad-Hoc. + description: | + Ad-hoc security training provides basic awareness of software security risks and best practices to developers and other personnel involved in software development. These trainings are delivered as needed, without a fixed schedule, to address immediate knowledge gaps or respond to emerging threats. + risk: | + Without any security training, personnel may lack awareness of common software vulnerabilities (such as SQL Injection and vulnerable dependencies), increasing the risk of introducing exploitable flaws into applications. + measure: | + Provide security awareness training for all personnel involved in software development on an ad-hoc basis, ensuring that relevant topics are covered when new risks or needs are identified. + assessment: | + - Conduct security training for developers and relevant personnel + - Training materials are available + - Attendance records are available + level: 1 difficultyOfImplementation: knowledge: 2 time: 1 resources: 1 usefulness: 3 - level: 1 implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-juice-shop - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-cheatsheet-ser + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-cheatsheet-series references: samm2: - - G-EG-1-A + - G-EG-A-1 + iso27001-2017: + - 7.2.2 + iso27001-2022: + - 6.3 + Office Hours: + uuid: 185d5a74-19dc-4422-be07-44ea35226783 + risk: + Developers and Operations are not in contact with the security team and therefore do not ask prior implementation of (known or unknown) threats- + measure: + As a security team, be open for questions and hints during defined office hours. x x d + difficultyOfImplementation: + knowledge: 1 + time: 1 + resources: 1 + usefulness: 3 + level: 3 + implementation: + references: + samm2: + - G-EG-A-1 iso27001-2017: - 7.2.2 iso27001-2022: - 6.3 - isImplemented: false - evidence: "" - comments: "" Security Coaching: uuid: f7b215dc-73a4-4c61-9e49-b3a3af1c9ac3 risk: Training does not change behaviour. Therefore, even if security practices are understood, it's likely that they are not performed. @@ -44,7 +64,7 @@ Culture and Organization: level: 3 references: samm2: - - G-EG-3-B + - G-EG-B-3 iso27001-2017: - 7.1.1 iso27001-2022: @@ -71,7 +91,7 @@ Culture and Organization: level: 4 references: samm2: - - G-EG-3-B + - G-EG-B-3 iso27001-2017: - 7.1.1 iso27001-2022: @@ -99,7 +119,7 @@ Culture and Organization: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/build-it-break-it-fi references: samm2: - - G-EG-2-A + - G-EG-A-2 iso27001-2017: - 7.2.2 iso27001-2022: @@ -125,7 +145,8 @@ Culture and Organization: implementation: [] references: samm2: - - G-EG-2-A + - G-EG-A-2 + - G-EG-B-2 iso27001-2017: - Mutual review of source code is not explicitly required in ISO 27001 may be @@ -156,8 +177,8 @@ Culture and Organization: implementation: [] references: samm2: - - G-EG-1-A - - G-EG-2-A + - G-EG-A-1 + - G-EG-A-2 iso27001-2017: - Mutual security testing is not explicitly required in ISO 27001 may be - 7.2.2 @@ -183,7 +204,8 @@ Culture and Organization: implementation: [] references: samm2: - - G-EG-2-A + - G-EG-A-2 + - O-IM-B-2 iso27001-2017: - War games are not explicitly required in ISO 27001 may be - 7.2.2 @@ -211,32 +233,18 @@ Culture and Organization: resources: 1 usefulness: 4 level: 2 - description: - "Implement a program where each software development team has a - member considered a \u201CSecurity Champion\u201D who is the liaison between - Information Security and developers. Depending on the size and structure of - the team the \u201CSecurity Champion\u201D may be a software developer, tester, - or a product manager. The \u201CSecurity Champion\u201D has a set number of - hours per week for Information Security related activities. They participate - in periodic briefings to increase awareness and expertise in different security - disciplines. \u201CSecurity Champions\u201D have additional training to help - develop these roles as Software Security subject-matter experts. You may need - to customize the way you create and support \u201CSecurity Champions\u201D - for cultural reasons.\n\nThe goals of the position are to increase effectiveness - and efficiency of application security and compliance and to strengthen the - relationship between various teams and Information Security. To achieve these - objectives, \u201CSecurity Champions\u201D assist with researching, verifying, - and prioritizing security and compliance related software defects. They are - involved in all Risk Assessments, Threat Assessments, and Architectural Reviews - to help identify opportunities to remediate security defects by making the - architecture of the application more resilient and reducing the attack threat - surface.\nSource: [OWASP SAMM](https://owaspsamm.org/model/governance/education-and-guidance/stream-b/)\n" + description: | + Implement a program where each software development team has a member considered a "Security Champion" who is the liaison between Information Security and developers. Depending on the size and structure of the team the "Security Champion" may be a software developer, tester, or a product manager. The "Security Champion" has a set number of hours per week for Information Security related activities. They participate in periodic briefings to increase awareness and expertise in different security disciplines. "Security Champions" have additional training to help develop these roles as Software Security subject-matter experts. You may need to customize the way you create and support "Security Champions" for cultural reasons. + + The goals of the position are to increase effectiveness and efficiency of application security and compliance and to strengthen the relationship between various teams and Information Security. To achieve these objectives, "Security Champions" assist with researching, verifying, and prioritizing security and compliance related software defects. They are involved in all Risk Assessments, Threat Assessments, and Architectural Reviews to help identify opportunities to remediate security defects by making the architecture of the application more resilient and reducing the attack threat surface. + + [Source: OWASP SAMM](https://owaspsamm.org/model/governance/education-and-guidance/stream-b/) implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-security-champ references: samm2: - - G-EG-1-B - - G-EG-2-B + - G-EG-B-1 + - G-EG-B-2 iso27001-2017: - Security champions are missing in ISO 27001 most likely - 7.2.1 @@ -269,11 +277,11 @@ Culture and Organization: [Source: OWASP SAMM 2](https://owaspsamm.org/model/governance/education-and-guidance/stream-a/) implementation: - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-juiceshop - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-cheatsheet-ser + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-juice-shop + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-cheatsheet-series references: samm2: - - G-EG-1-A + - G-EG-A-1 iso27001-2017: - 7.2.2 iso27001-2022: @@ -294,11 +302,11 @@ Culture and Organization: usefulness: 4 level: 4 implementation: - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-juiceshop - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/https-cheatsheetse + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-juice-shop + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-cheatsheet-series references: samm2: - - G-EG-3-A + - G-EG-A-2 iso27001-2017: - 7.2.2 iso27001-2022: @@ -320,13 +328,13 @@ Culture and Organization: usefulness: 5 level: 2 implementation: - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-cheatsheet-ser + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-cheatsheet-series dependsOn: - Each team has a security champion references: samm2: - - D-TA-2-B - - G-EG-1-A + - D-TA-B-2 + - G-EG-A-1 iso27001-2017: - Security champions are missing in ISO 27001 - 7.2.2 @@ -354,7 +362,7 @@ Culture and Organization: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-top-10-maturit references: samm2: - - G-EG-1-B + - G-EG-B-1 iso27001-2017: - not required by ISO 27001 - interestingly enough A7.2.3 is requiring a process to handle misconduct @@ -394,7 +402,7 @@ Culture and Organization: AppSecure-nrw [Security Belts](https://github.com/AppSecure-nrw/security-belts/) references: samm2: - - V-ST-1-B + - V-ST-B-1 iso27001-2017: - ISO 27001:2017 mapping is missing iso27001-2022: @@ -404,23 +412,27 @@ Culture and Organization: comments: "" Security consulting on request: uuid: 0b28367b-75a0-4bae-a926-3725c1bf9bb0 - risk: - Not asking a security expert when questions regarding security appear - might lead to flaws. - measure: - Security consulting to teams is given on request. The security consultants - can be internal or external. + level: 1 + description: | + Security consulting on request allows teams to seek expert advice on security-related questions or challenges as they arise. This support can be provided by internal or external security consultants and helps address specific concerns during software development. + risk: | + If teams do not consult security experts when questions arise, security flaws may be introduced or remain undetected, increasing the risk of vulnerabilities in the software. + measure: | + Make security consulting available to teams on request, ensuring that expert advice is accessible when needed to address security concerns during development. + assessment: | + - Show evidence that an it security expert is available for questions at least quarterly. + - Documentation of consultations and resulting actions is available for review. difficultyOfImplementation: knowledge: 3 time: 1 resources: 1 usefulness: 3 - level: 1 implementation: - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-cheatsheet-ser + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-cheatsheet-series references: samm2: - - G-EG-1-A + - G-EG-A-1 + - G-EG-B-1 iso27001-2017: - security consulting is missing in ISO 27001 may be - 6.1.1 @@ -450,7 +462,8 @@ Culture and Organization: implementation: [] references: samm2: - - O-IM-3-B + - G-EG-B-3 + - O-IM-B-3 iso27001-2017: - 16.1.6 iso27001-2022: @@ -490,7 +503,7 @@ Culture and Organization: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/damn-vulnerable-web references: samm2: - - G-EG-1-A + - G-EG-A-2 iso27001-2017: - 7.2.2 iso27001-2022: diff --git a/src/assets/YAML/default/CultureAndOrganization/Process.yaml b/src/assets/YAML/default/CultureAndOrganization/Process.yaml index 5bc822e..b769977 100755 --- a/src/assets/YAML/default/CultureAndOrganization/Process.yaml +++ b/src/assets/YAML/default/CultureAndOrganization/Process.yaml @@ -58,28 +58,66 @@ Culture and Organization: comments: "" Definition of simple BCDR practices for critical components: uuid: c72da779-86cc-45b1-a339-190ce5093171 - risk: - In case of an emergency, like a power outage, DR actions to perform are - not clear. This leads to reaction and remediation delays. - measure: - By understanding and documenting a business continuity and disaster - recovery (BCDR) plan, the overall availability of systems and applications - is increased. Success factors like responsibilities, Service Level Agreements, - Recovery Point Objectives, Recovery Time Objectives or Failover must be fully - documented and understood. + description: | + Business Continuity and Disaster Recovery (BCDR) is a plan and a process that enable an organization to quickly restore normal operations after a disruptive event, such as a cyberattack or natural disaster. + risk: | + If the disaster recovery actions are not clear, you risk slow reaction and remediation delays. + This applies to cyber attacks as well as natural emergencies, such as a power outage. + measure: | + Develop, document, and communicate a BCDR plan for all critical components. The plan must define roles and responsibilities, Service Level Agreements (SLAs), Recovery Point Objectives (RPOs), Recovery Time Objectives (RTOs), and failover procedures. Ensure all relevant personnel are trained and the plan is reviewed and updated regularly. + assessment: | + - There is a documented BCDR plan covering all critical components of the application(s). + - The plan clearly defines responsibilities, SLAs, RPOs, RTOs, and failover steps. + - Relevant staff are aware of the plan, and evidence of regular review and testing is available. + level: 1 difficultyOfImplementation: knowledge: 4 time: 3 resources: 2 usefulness: 4 - level: 1 implementation: [] references: - samm2: [] + samm2: + - O-IM-B-2 iso27001-2017: - 17.1.1 iso27001-2022: - 5.29 - isImplemented: false - evidence: "" - comments: "" + Determining the protection requirement: + uuid: 72737130-472c-4984-80f8-9ab2f1c2ed5d + risk: |- + Not defining the protection requirement of applications can lead to wrong prioritization, delayed remediation of + critical security issues, increasing the risk of exploitation and potential damage to the organization. + measure: |- + Defining the protection requirement. + The protection requirements for an application should consider: + - Processed data criticality + - Application accessibility (internal vs. external) + - Regulatory compliance + - Other relevant factors + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 1 + usefulness: 3 + level: 2 + dependsOn: + - 2a44b708-734f-4463-b0cb-86dc46344b2f # inventory of production components + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-defectdojo + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/purify + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/business-friendly-vulnerability-metrics + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/defectdojo-client + references: + samm2: + - O-OM-A-2 + - G-PC-B-2 + iso27001-2022: + - 5.25 + - 5.12 + - 5.13 + - 5.10 + tags: + - vulnerability-mgmt + - metrics + - vmm-measurements diff --git a/src/assets/YAML/default/Implementation/ApplicationHardening.yaml b/src/assets/YAML/default/Implementation/ApplicationHardening.yaml index bb71462..fde532a 100755 --- a/src/assets/YAML/default/Implementation/ApplicationHardening.yaml +++ b/src/assets/YAML/default/Implementation/ApplicationHardening.yaml @@ -40,41 +40,99 @@ Implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-asvs - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-masvs - $ref: src/assets/YAML/default/implementations.yaml#/implementations/apimaturity + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/api-myths references: samm2: - - D-SR-1-A + - D-SR-A-2 iso27001-2017: - Hardening is not explicitly covered by ISO 27001 - too specific - 13.1.3 iso27001-2022: - Hardening is not explicitly covered by ISO 27001 - too specific - 8.22 - isImplemented: false comments: "" - Contextualized Encoding: + Context-aware output encoding: uuid: e1f37abb-d848-4a3a-b3df-65e91a89dcb7 + description: | + **Input validation** stops malicious data from entering your system. \ + **Output encoding** neutralizes malicious data before rendering to user, or the next system. + + Input validation and output encoding work together. Apply both. + + **Context-aware output encoding** encodes data differently, depending on its context. In the sample below the `{{bad_data}}` must be encoded differently, depending on its context, to render safe HTML. + + ```html +
{{bad_data}}
+ Click me + + + ``` risk: - The generation of interpreter directives from user-provided data poses difficulties and can introduce vulnerabilities to injection attacks. + If an attacker manages to slip though your input validation, the attacker may gain control over the user session or execute arbitrary actions. measure: | - Implementing contextualized encoding, such as employing object-relational mapping tools or utilizing prepared statements, nearly removes the threat of injection vulnerabilities. + * Use modern secure frameworks such as React/Angular/Vue/Svelte. The default method here renders data in a safe way. + * Use established and well-maintained encoding libraries such as OWASP’s Java Encoder and Microsoft’s AntiXSS. + * Implement content security policies (CSP) to restrict the types of content that can be loaded and executed. difficultyOfImplementation: - knowledge: 2 + knowledge: 1 time: 2 resources: 1 usefulness: 3 level: 1 + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-dom-xss-cheats + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/cwe-838 + references: + samm2: + - D-SR-A-1 + iso27001-2017: + - Hardening is not explicitly covered by ISO 27001 - too specific + - 13.1.3 + iso27001-2022: + - Hardening is not explicitly covered by ISO 27001 - too specific + - 8.22 + comments: "" + Parametrization: + uuid: 00e91a8a-3972-4692-8679-674ab8547486 description: | - Bear in mind that utilizing frameworks is a recommended approach; however, they can develop known security weaknesses over time. Diligent and regular patching is crucial. - implementation: [] + By concatenating strings from user input to build SQL queries, an attacker can manipulate the query to do other unintentional SQL commands as well. + + This is called *SQL injection* but the principle applies to NoSql, and anywhere that your code is building commands that will be executed. + + Pay attention to these two lines of code. They seem similar, but behave very differently. + + * `sql.execute("SELECT * FROM table WHERE ID = " + id);` + * `sql.execute("SELECT * FROM table WHERE ID = ?", id);` + The second line is parameterized. The same principle applies to other types, such as command line execution, etc. + risk: | + Systems vulnerable to injections may lead to data breaches, loss of data, + unauthorized alteration of data, or complete database compromise or downtime. + + This applies to SQL, NoSql, LDAP, XPath, email headers OS commands, etc. + measure: | + * Identify which of the types your application is using. Check that you use: + * Use _parametrized queries_ (or _prepared statements_) + * For database queries, you may also use: + * Use _stored procedures_ () + * Use ORM (Object-Relational Mapping) tools that automatically handle input sanitization + difficultyOfImplementation: + knowledge: 1 + time: 2 + resources: 1 + usefulness: 3 + level: 1 + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-parameterization-cheats references: samm2: - - D-SR-1-A + - D-SR-A-1 iso27001-2017: - Hardening is not explicitly covered by ISO 27001 - too specific - 13.1.3 iso27001-2022: - Hardening is not explicitly covered by ISO 27001 - too specific - 8.22 + comments: "" App. Hardening Level 1: uuid: cf819225-30cb-4702-8e32-60225eedc33d risk: @@ -115,9 +173,10 @@ Implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-asvs - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-masvs - $ref: src/assets/YAML/default/implementations.yaml#/implementations/apimaturity + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/api-myths references: samm2: - - D-SR-1-A + - D-SR-A-3 iso27001-2017: - Hardening is not explicitly covered by ISO 27001 - too specific - 13.1.3 @@ -145,9 +204,10 @@ Implementation: implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-asvs - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-masvs + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/api-myths references: samm2: - - D-SR-2-A + - D-SR-A-3 iso27001-2017: - Hardening is not explicitly covered by ISO 27001 - too specific - 13.1.3 @@ -155,7 +215,6 @@ Implementation: - Hardening is not explicitly covered by ISO 27001 - too specific - 8.22 isImplemented: false - evidence: "" comments: "" dependsOn: - App. Hardening Level 1 @@ -181,7 +240,7 @@ Implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-masvs references: samm2: - - D-SR-2-A + - D-SR-A-2 iso27001-2017: - Hardening is not explicitly covered by ISO 27001 - too specific - 13.1.3 @@ -189,7 +248,6 @@ Implementation: - Hardening is not explicitly covered by ISO 27001 - too specific - 8.22 isImplemented: false - evidence: "" comments: "" dependsOn: - App. Hardening Level 2 (75%) @@ -215,15 +273,117 @@ Implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-masvs references: samm2: - - D-SR-3-A + - D-SR-A-3 iso27001-2017: - Hardening is not explicitly covered by ISO 27001 - too specific - 13.1.3 iso27001-2022: - Hardening is not explicitly covered by ISO 27001 - too specific - 8.22 - isImplemented: false - evidence: "" - comments: "" dependsOn: - App. Hardening Level 2 + Secure headers: + uuid: 29318d60-18ce-4526-80ea-f5928e49f639 + risk: | + Missing or misconfigured security headers can lead to various security vulnerabilities, e.g.: + - Cross-Site Scripting (XSS) due to missing Content Security Policy + - Clickjacking attacks due to missing X-Frame-Options + - Information disclosure through Server header exposure + - SSL/TLS downgrade attacks due to missing HSTS + - Cross-site scripting and injection due to missing security headers + measure: | + Implement and enforce security headers across all applications and services + + Implementation Methods: + 1. Reverse Proxy/Load Balancer: Configure at nginx/Apache level + 2. Web Application: Implement in the application middleware + 3. Service Mesh: Configure at the ingress controller level + 4. Standard Docker Image: Use secure base images with preset headers + + Remove or Secure: + - Server header: Hide server version information + - X-Powered-By: Remove technology stack information + difficultyOfImplementation: + knowledge: 2 + time: 1 + resources: 2 + usefulness: 4 + level: 3 + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-secure-headers + meta: + implementationGuide: | + Essential headers: + - Content-Security-Policy: Define trusted sources for content + - Strict-Transport-Security: Enforce HTTPS connections + - X-Frame-Options: Prevent clickjacking attacks + - X-Content-Type-Options: Prevent MIME-type sniffing + - X-XSS-Protection: Enable browser's XSS filtering + - Referrer-Policy: Control information in the Referrer header + references: + samm2: + - O-EM-A-2 + iso27001-2017: + - Hardening is not explicitly covered by ISO 27001 - too specific + - 13.1.3 + iso27001-2022: + - Hardening is not explicitly covered by ISO 27001 - too specific + - 8.22 + openCRE: + - https://www.opencre.org/cre/620-421 + Containers are running as non-root: + uuid: a86c1fbc-28fd-4610-89a3-a7f73acfe45f + risk: |- + There are various reasons to run a container as non-root. Samples are listed: + ## Container Escape Vectors + + - Root privileges significantly increase the chance of breaking container isolation + - Root access can be leveraged to exploit kernel vulnerabilities + - Compromised root containers provide attackers with maximum privileges inside the container + - Greater potential for escaping container boundaries to the host system + + ## Host System Vulnerabilities + + Root containers can potentially: + + - Mount sensitive host filesystems + - Access critical device files + - Modify host network settings + - Interact with host system processes + - Override security controls + + ## Resource Management Issues + + Root privileges may allow containers to: + + - Bypass resource quotas and limits + - Modify control group (cgroup) settings + - Interfere with other containers' resources + - Circumvent memory and CPU restrictions + + Security Boundary Weakening + + - Violates the principle of least privilege + - Provides unnecessary elevated permissions + - Expands the potential attack surface + - Increases the impact of a successful compromise + + measure: |- + Containers are running as non-root. This can be enforced in the image itself or during runtime parameters + (e.g. `podman run --user [...]`). + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 1 + usefulness: 3 + level: 2 + implementation: [] + references: + samm2: + - O-EM-A-1 + iso27001-2017: + - Virtual environments are not explicitly covered by ISO 27001 - too specific + - 13.1.3 + iso27001-2022: + - Virtual environments are not explicitly covered by ISO 27001 - too specific + - 8.22 diff --git a/src/assets/YAML/default/Implementation/DevelopmentAndSourceControl.yaml b/src/assets/YAML/default/Implementation/DevelopmentAndSourceControl.yaml index b540e6e..9a49570 100755 --- a/src/assets/YAML/default/Implementation/DevelopmentAndSourceControl.yaml +++ b/src/assets/YAML/default/Implementation/DevelopmentAndSourceControl.yaml @@ -16,10 +16,11 @@ Implementation: description: "" implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/stylecop - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/sonarqube + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/sonarqube-lint + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/eslint references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - ISO 27001:2017 mapping is missing iso27001-2022: @@ -27,57 +28,55 @@ Implementation: isImplemented: false evidence: "" comments: "" - API design validation: - uuid: 948a4d51-ceb5-4ebd-bdc7-d74ea25e171c - risk: Creation of insecure or non-compliant API. - measure: | - Design contract-first APIs using an interface description language such as OpenAPI, AsyncAPI or SOAP - and validate the specification using specific tools. - Checks should be integrated in IDEs and CI/CD pipelines. + Require a PR before merging: + uuid: e7598ac4-b082-4e56-b7df-e2c6b426a5e2 + risk: Intentional or accidental alterations in critical branches like main (or master). + measure: >- + Define source code management system policies (e.g. branch protection rules, + mandatory code reviews from at least one person, ...) + to ensure that changes to critical branches are only possible under defined conditions. + These policies can be implemented at repository level or organization level, + depending on the source code management system. difficultyOfImplementation: knowledge: 2 - time: 2 + time: 1 resources: 2 usefulness: 4 - level: 3 + level: 2 implementation: - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/stoplight-spectral - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/api-oas-checker + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/azuredevops + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/github-policies references: samm2: - - V-ST-1-A + - O-EM-A-1 iso27001-2017: + - Peer review - four eyes principle is not explicitly required by ISO 27001 + - 6.1.2 - 14.2.1 - - 14.2.5 iso27001-2022: - - 8.25 # Secure development lifecycle - - 8.27 # Secure system architecture and engineering principles - - 8.28 # Secure coding - isImplemented: false - evidence: "" - comments: "" - Source Control Protection: - uuid: e7598ac4-b082-4e56-b7df-e2c6b426a5e2 - risk: Intentional or accidental alterations in critical branches like master. + - Peer review - four eyes principle is not explicitly required by ISO 27001 + - 5.3 + - 8.25 + Dismiss stale PR approvals: + uuid: ea6f69f7-54a5-4922-ac15-a77ff0c16162 + risk: Intentional or accidental alterations in critical branches like main (or master) through post-approval code additions. measure: >- - Define source code management system policies (e.g. branch protection rules, - mandatory code reviews, ...) - to ensure that changes to critical branches are only possible under defined conditions. - These policies can be implemented at repository level or organization level, - depending on the source code management system. + Implement a policy where any commits made after a pull request has been approved automatically revoke that approval, necessitating a fresh review and re-approval process. difficultyOfImplementation: knowledge: 2 time: 1 resources: 2 usefulness: 4 - level: 2 + level: 3 + dependsOn: + - e7598ac4-b082-4e56-b7df-e2c6b426a5e2 # Require a PR before merging implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/azuredevops - $ref: src/assets/YAML/default/implementations.yaml#/implementations/github-policies - $ref: src/assets/YAML/default/implementations.yaml#/implementations/signing-of-commits-protection references: samm2: - - O-EM-1-A + - O-EM-A-1 iso27001-2017: - Peer review - four eyes principle is not explicitly required by ISO 27001 - 6.1.2 @@ -86,27 +85,29 @@ Implementation: - Peer review - four eyes principle is not explicitly required by ISO 27001 - 5.3 - 8.25 - isImplemented: false - evidence: "" - comments: "" - Versioning: + Version control: uuid: 066084c6-1135-4635-9cc5-9e75c7c5459f - risk: Deployment of untracked artifacts. + description: + Use a _version control system_ like Github, Gitlab, Bitbucket, etc to version your source code. + + Also known as _source control_, _revision control_, or _source code management_. + risk: + Without version control, it is challenging to track changes, collaborate effectively, and maintain a history of code modifications. + Rollback to earlier versions is hard. measure: >- - Version artifacts in order to identify deployed features and issues. - This includes application and infrastructure code, jenkins configuration, container and virtual machine images. + Version your source code in order to identify deployed features and issues. + This includes application and infrastructure code, jenkins configuration, container and virtual machine images definitions. difficultyOfImplementation: knowledge: 3 time: 3 resources: 3 usefulness: 5 level: 1 - dependsOn: - - Defined deployment process implementation: [] references: samm2: - - O-EM-1-A + - O-EM-A-1 + - I-SB-A-2 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 12.1.1 @@ -116,9 +117,6 @@ Implementation: - Not explicitly covered by ISO 27001 - too specific - 5.37 - 8.32 - isImplemented: false - evidence: "" - comments: "" .gitignore: uuid: 363a3eea-baf9-4010-88ca-bb8186a2989d risk: Unintended leakage of secrets, debug, or workstation specific data @@ -134,7 +132,7 @@ Implementation: implementation: [] references: samm2: - - O-EM-1-A + - O-EM-A-1 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 12.1.1 @@ -144,5 +142,60 @@ Implementation: - Not explicitly covered by ISO 27001 - too specific - 5.37 - 8.32 - evidence: "" - comments: "" + Require status checks to pass: + uuid: ac8730a2-ccc0-465c-9550-d91edae9d5ee + risk: Organizations risk introducing broken builds, quality issues, and security vulnerabilities into their codebase. + measure: >- + Mandate passing of security related specified status checks, like successful builds or static application security tests, before proceeding. + difficultyOfImplementation: + knowledge: 2 + time: 1 + resources: 2 + usefulness: 4 + level: 3 + dependsOn: + - e7598ac4-b082-4e56-b7df-e2c6b426a5e2 + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/azuredevops + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/github-policies + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/signing-of-commits-protection + references: + samm2: + - O-EM-A-1 + iso27001-2017: + - 6.1.2 + - 14.2.1 + iso27001-2022: + - 5.3 + - 8.25 + Block force pushes: + uuid: c7d99b18-c3e1-4d22-b2e3-9aa9146c0b17 + risk: |- + Misuse of force push can lead to loss of work. It may overwrite remote + branches without warning, potentially erasing valuable contributions from team members. This can disrupt collaboration, + cause data loss, and create confusion in the development process. + + Bypassing the pull request process might remove an important code review step. + This increases the risk of merging low-quality or buggy code into the main branch, potentially introducing bugs in the codebase. + measure: >- + Mandate blocking of force pushes in the version control platform. + difficultyOfImplementation: + knowledge: 2 + time: 1 + resources: 2 + usefulness: 3 + level: 3 + dependsOn: + - e7598ac4-b082-4e56-b7df-e2c6b426a5e2 + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/azuredevops + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/github-policies + references: + samm2: + - O-EM-A-1 + iso27001-2017: + - 6.1.2 + - 14.2.1 + iso27001-2022: + - 5.3 + - 8.25 diff --git a/src/assets/YAML/default/Implementation/InfrastructureHardening.yaml b/src/assets/YAML/default/Implementation/InfrastructureHardening.yaml index 75e9a3f..6d789b5 100755 --- a/src/assets/YAML/default/Implementation/InfrastructureHardening.yaml +++ b/src/assets/YAML/default/Implementation/InfrastructureHardening.yaml @@ -17,13 +17,12 @@ Implementation: usefulness: 4 level: 1 implementation: - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/smartcard - $ref: src/assets/YAML/default/implementations.yaml#/implementations/yubikey - $ref: src/assets/YAML/default/implementations.yaml#/implementations/sms - $ref: src/assets/YAML/default/implementations.yaml#/implementations/totp references: samm2: - - O-EM-1-A + - O-EM-A-1 iso27001-2017: - 9.2.4 - 6.1.2 # Segregation of duties. @@ -54,13 +53,12 @@ Implementation: dependsOn: - MFA for admins implementation: - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/smartcard - $ref: src/assets/YAML/default/implementations.yaml#/implementations/yubikey - $ref: src/assets/YAML/default/implementations.yaml#/implementations/sms - $ref: src/assets/YAML/default/implementations.yaml#/implementations/totp references: samm2: - - O-EM-1-A + - O-EM-A-1 iso27001-2017: - 9.2.4 - 6.1.2 # Segregation of duties. @@ -89,15 +87,13 @@ Implementation: implementation: [] references: samm2: - - O-EM-1-A + - O-EM-A-1 iso27001-2017: - Virtual environments are not explicitly covered by ISO 27001 - too specific - 13.1.3 iso27001-2022: - Virtual environments are not explicitly covered by ISO 27001 - too specific - 8.22 - isImplemented: false - evidence: "" comments: "" Backup: uuid: 5c61fd6b-8106-4c68-ac28-a8a42f1c67dc @@ -117,7 +113,7 @@ Implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/a-complete-backup-of - $ref: src/assets/YAML/default/implementations.yaml#/implementations/a-point-in-time-reco dependsOn: - - Defined deployment process + - 74938a3f-1269-49b9-9d0f-c43a79a1985a # Defined deployment process references: samm2: - TODO @@ -148,7 +144,7 @@ Implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/firewalls references: samm2: - - O-EM-1-A + - O-EM-A-2 iso27001-2017: - Virtual environments are not explicitly covered by ISO 27001 - too specific - 13.1.3 @@ -174,7 +170,7 @@ Implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/remove-direct-access references: samm2: - - O-EM-1-A + - O-EM-A-2 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 17.2.1 @@ -207,7 +203,7 @@ Implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/jenkinsfile references: samm2: - - O-EM-1-A + - O-EM-A-2 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 12.1.1 @@ -241,7 +237,7 @@ Implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/firewalls references: samm2: - - O-EM-1-A + - O-EM-A-1 iso27001-2017: - Virtual environments are not explicitly covered by ISO 27001 - too specific - 13.1.3 @@ -270,7 +266,7 @@ Implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/falco references: samm2: - - O-EM-1-A + - O-EM-A-2 iso27001-2017: - System hardening is not explicitly covered by ISO 27001 - too specific iso27001-2022: @@ -278,29 +274,6 @@ Implementation: isImplemented: false evidence: "" comments: "" - Microservice-architecture: - uuid: 118b869b-3850-456e-98d9-1abdb85cbc5a - risk: Monolithic applications are hard to test. - measure: - A microservice-architecture helps to have small components, which are - more easy to test. - difficultyOfImplementation: - knowledge: 4 - time: 5 - resources: 5 - usefulness: 1 - level: 5 - implementation: [] - references: - samm2: - - O-EM-1-A - iso27001-2017: - - Not explicitly covered by ISO 27001 - iso27001-2022: - - ISO 27001:2022 mapping is missing - isImplemented: false - evidence: "" - comments: "" Production near environments are used by developers: uuid: e14de741-94b3-447c-8b07-eea947d82e61 risk: @@ -319,12 +292,12 @@ Implementation: usefulness: 4 level: 4 dependsOn: - - Defined deployment process + - 67e1a9aa-9fbf-4ec5-a2de-400f01960c51 # Automated deployment process - Infrastructure as Code implementation: [] references: samm2: - - O-EM-1-A + - O-EM-A-2 iso27001-2017: - 12.1.4 - 17.2.1 @@ -341,7 +314,7 @@ Implementation: or to modify information unauthorized on systems. measure: The usage of a (role based) access control helps to restrict system - access to authorized users. + access to authorized users. And enhancement is to use *attribute based access control*. difficultyOfImplementation: knowledge: 2 time: 3 @@ -351,12 +324,9 @@ Implementation: implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/directory-service - $ref: src/assets/YAML/default/implementations.yaml#/implementations/plugins - dependsOn: - - Defined deployment process - - Defined build process references: samm2: - - O-EM-1-A + - O-EM-A-2 iso27001-2017: - 9.4.1 iso27001-2022: @@ -366,22 +336,24 @@ Implementation: comments: "" Simple access control for systems: uuid: 82e499d1-f463-4a4b-be90-68812a874af6 - risk: Attackers a gaining access to internal systems and application interfaces + description: Basic access control for internal systems is implemented. + risk: Attackers a gaining access to other internal systems and application interfaces is one breach occurs. measure: All internal systems are using simple authentication + assessment: | + - Presenting the documentation of the review of all user privileges yearly. + - Presenting the admin count and validating that there are less than 5 admins per system. difficultyOfImplementation: knowledge: 3 time: 3 resources: 3 usefulness: 5 level: 1 - dependsOn: - - Defined deployment process implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/http-basic-authentic - $ref: src/assets/YAML/default/implementations.yaml#/implementations/vpn references: samm2: - - O-EM-1-A + - O-EM-A-1 iso27001-2017: - 9.4.1 iso27001-2022: @@ -404,16 +376,16 @@ Implementation: usefulness: 4 level: 2 implementation: - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/cis-kubernetes-bench - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/cis-docker-bench-for + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/cis-kubernetes-benchmark + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/cis-docker-benchmark - $ref: src/assets/YAML/default/implementations.yaml#/implementations/for-example-for-cont - $ref: src/assets/YAML/default/implementations.yaml#/implementations/attack-matrix-cloud - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/attack-matrix-contai + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/attack-matrix-containers - $ref: src/assets/YAML/default/implementations.yaml#/implementations/attack-matrix-kubern - $ref: src/assets/YAML/default/implementations.yaml#/implementations/defend-the-core-kubernetes references: samm2: - - O-EM-1-A + - O-EM-A-1 iso27001-2017: - system hardening is not explicitly covered by ISO 27001 - too specific - 13.1.3 @@ -437,16 +409,16 @@ Implementation: usefulness: 3 level: 4 implementation: - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/cis-kubernetes-bench - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/cis-docker-bench-for + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/cis-kubernetes-benchmark + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/cis-docker-benchmark - $ref: src/assets/YAML/default/implementations.yaml#/implementations/for-example-for-cont - $ref: src/assets/YAML/default/implementations.yaml#/implementations/attack-matrix-cloud - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/attack-matrix-contai + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/attack-matrix-containers - $ref: src/assets/YAML/default/implementations.yaml#/implementations/attack-matrix-kubern - $ref: src/assets/YAML/default/implementations.yaml#/implementations/defend-the-core-kubernetes references: samm2: - - O-EM-1-A + - O-EM-A-2 iso27001-2017: - Hardening is not explicitly covered by ISO 27001 - too specific - 13.1.3 @@ -456,7 +428,7 @@ Implementation: isImplemented: false evidence: "" comments: "" - Usage of a chaos monkey: + Usage of a chaos technology: uuid: f8e80f18-2503-4e3e-b3bc-7f67bb28defe risk: Due to manual changes on a system, they are not replaceable anymore. In @@ -471,10 +443,11 @@ Implementation: resources: 5 usefulness: 3 level: 4 - implementation: [] + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/chaosmonkey references: samm2: - - O-EM-1-A + - O-EM-A-3 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 17.1.3 @@ -500,7 +473,7 @@ Implementation: implementation: "" references: samm2: - - I-SD-2-B + - I-SD-B-2 iso27001-2017: - 10.1 iso27001-2022: @@ -512,10 +485,12 @@ Implementation: uuid: ad23be9c-5661-4f1f-81a3-5a5dc7061629 risk: Evil actors might be able to perform a man in the middle attack and sniff - confidential information (e.g. authentication factors like passwords) - measure: + confidential information (e.g. authentication factors like passwords). + measure: |- By using encryption at the edge of traffic in transit, it is impossible - or at least harder to sniff credentials being outside of the organization. + or at least harder to sniff credentials or information being outside of the organization. + + Using standard secure protocols like HTTPS is recommended. difficultyOfImplementation: knowledge: 2 time: 2 @@ -525,7 +500,7 @@ Implementation: implementation: "" references: samm2: - - I-SD-2-B + - I-SD-B-2 iso27001-2017: - 10.1 iso27001-2022: @@ -550,7 +525,7 @@ Implementation: implementation: "" references: samm2: - - I-SD-2-B + - I-SD-B-2 iso27001-2017: - 10.1 iso27001-2022: @@ -576,7 +551,7 @@ Implementation: implementation: "" references: samm2: - - I-SD-2-B + - I-SD-B-2 iso27001-2017: - 10.1 iso27001-2022: @@ -606,7 +581,7 @@ Implementation: - Defined build process references: samm2: - - O-EM-1-A + - O-EM-A-2 iso27001-2017: - not explicitly covered by ISO 27001 - too specific iso27001-2022: @@ -627,11 +602,11 @@ Implementation: usefulness: 4 level: 2 dependsOn: - - Defined deployment process + - 74938a3f-1269-49b9-9d0f-c43a79a1985a # Defined deployment process implementation: [] references: samm2: - - O-EM-1-A + - O-EM-A-1 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 12.1.4 @@ -662,7 +637,7 @@ Implementation: implementation: [] references: samm2: - - O-EM-1-A + - O-EM-A-1 iso27001-2017: - Virtual environments are not explicitly covered by ISO 27001 - too specific - 12.1.3 @@ -675,13 +650,15 @@ Implementation: - 8.14 isImplemented: false evidence: "" - comments: "" + comments: "" WAF baseline: uuid: f0e01814-3b88-4bd0-a3a9-f91db001d20b risk: Vulnerable input, such as exploits, can infiltrate the application via numerous entry points, posing a significant security threat. measure: Implementing a web application firewall (WAF) is a critical security control. At a baseline level, the objective is to finely balance the reduction of false positives, maintaining user experience, against a potential increase in the less noticeable false negatives. + + Begin with the WAF in a monitoring state to understand the traffic and threats. Progressively enforce blocking actions based on intelligence gathered, ensuring minimal disruption to legitimate traffic. description: | A baseline WAF configuration provides essential defense against common vulnerabilities, acting as a first line of automated threat detection and response. Steps: @@ -698,27 +675,28 @@ Implementation: resources: 3 usefulness: 3 level: 3 - description: | - Begin with the WAF in a monitoring state to understand the traffic and threats. Progressively enforce blocking actions based on intelligence gathered, ensuring minimal disruption to legitimate traffic. dependsOn: - - Contextualized encoding - implementation: [] + - Context-aware output encoding + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/api-myths references: samm2: - - D-SR-3-A + - O-EM-A-1 iso27001-2017: - Hardening is not explicitly covered by ISO 27001 - too specific - 13.1.3 iso27001-2022: - Hardening is not explicitly covered by ISO 27001 - too specific - 8.22 - comments: + comments: WAF medium: - uuid: f0e01814-3b88-4bd0-a3a9-f91db001d20b + uuid: f0e01814-3b88-4bd0-a3a9-f91db001d20b-medium risk: The threat from malicious inputs remains high, with exploits seeking to exploit any vulnerabilities present at the various points of entry to the application. measure: A WAF deployed with a medium level of protection strengthens the security posture by striking a more advanced balance between the detection of genuine threats and the minimization of false alarms. + + Maintain the WAF in alert mode initially to ensure a comprehensive understanding of potential threats. With a medium-level configuration, the WAF settings are refined for greater precision in threat detection, with a stronger emphasis on security without significantly impacting legitimate traffic. description: | A medium-level WAF configuration builds upon the baseline to offer a more nuanced and responsive defense mechanism against a wider array of threats. @@ -736,28 +714,29 @@ Implementation: resources: 4 usefulness: 3 level: 4 - description: | - Maintain the WAF in alert mode initially to ensure a comprehensive understanding of potential threats. With a medium-level configuration, the WAF settings are refined for greater precision in threat detection, with a stronger emphasis on security without significantly impacting legitimate traffic. dependsOn: - WAF baseline - implementation: [] + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/api-myths references: samm2: - - D-SR-3-A + - O-EM-A-2 iso27001-2017: - Hardening is not explicitly covered by ISO 27001 - too specific - 13.1.3 iso27001-2022: - Hardening is not explicitly covered by ISO 27001 - too specific - 8.22 - comments: - + comments: + WAF Advanced: uuid: f0e01814-3b88-4bd0-a3a9-f91db001d20b-advanced risk: The presence of sophisticated threats necessitates a robust defense strategy where application inputs are meticulously scrutinized for security breaches, including advanced persistent threats and zero-day vulnerabilities. measure: An advanced WAF protection level includes rigorous input validation, rejecting any parameters not explicitly required, and custom rule sets that are dynamically updated in response to emerging threats. + + The advanced WAF setup is designed to ensure all data is in the correct format and any superfluous input parameters are automatically rejected. It includes machine learning algorithms to detect anomalies, custom-developed rules for real-time traffic analysis, and seamless integration with existing security infrastructures to adapt to the ever-changing threat landscape. description: | This advanced configuration goes beyond typical WAF implementations by enforcing strict input format checks and parameter validation to prevent any unauthorized or malformed data from compromising the application. @@ -779,22 +758,21 @@ Implementation: resources: 5 usefulness: 4 level: 5 - description: | - The advanced WAF setup is designed to ensure all data is in the correct format and any superfluous input parameters are automatically rejected. It includes machine learning algorithms to detect anomalies, custom-developed rules for real-time traffic analysis, and seamless integration with existing security infrastructures to adapt to the ever-changing threat landscape. dependsOn: - WAF medium - implementation: [] + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/api-myths references: samm2: - - D-SR-3-A + - O-EM-A-2 iso27001-2017: - Hardening is not explicitly covered by ISO 27001 - too specific - 13.1.3 iso27001-2022: - Hardening is not explicitly covered by ISO 27001 - too specific - 8.22 - comments: - + comments: + diff --git a/src/assets/YAML/default/InformationGathering/Logging.yaml b/src/assets/YAML/default/InformationGathering/Logging.yaml index 63c73db..a718b45 100755 --- a/src/assets/YAML/default/InformationGathering/Logging.yaml +++ b/src/assets/YAML/default/InformationGathering/Logging.yaml @@ -16,44 +16,41 @@ Information Gathering: time: 1 resources: 1 usefulness: 5 - level: 3 + level: 2 dependsOn: - - Visualized logging - Alerting implementation: [] references: samm2: - - O-IM-1-A + - O-IM-A-1 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 12.4.1 iso27001-2022: - Not explicitly covered by ISO 27001 - too specific - 8.15 - isImplemented: false - evidence: "" - comments: "" Centralized system logging: uuid: 4eced38a-7904-4c45-adb0-50b663065540 - risk: - Local stored system logs can be unauthorized manipulated by attackers - or might be corrupt after an incident. In addition, it is hard to perform - a aggregation of logs. - measure: - By using centralized logging logs are protected against unauthorized - modification. + description: | + Centralized system logging involves collecting and storing system logs from multiple sources in a secure, central location. This approach improves log integrity, simplifies monitoring, and enables efficient incident response. + risk: | + Locally stored system logs can be manipulated by attackers unauthorized or might be corrupt or lost after an incident. In addition, it is hard to perform aggregation of logs. + measure: | + - Implement a centralized logging solution for all critical systems. + - System logs must be stored in a central repository, protected from unauthorized access and modification. + - Ensure that log collection is automated and covers all relevant system events. + level: 1 difficultyOfImplementation: knowledge: 1 time: 1 resources: 1 usefulness: 2 - level: 1 implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/rsyslog - $ref: src/assets/YAML/default/implementations.yaml#/implementations/logstash references: samm2: - - O-IM-1-A + - O-IM-A-1 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 12.4.1 @@ -83,7 +80,7 @@ Information Gathering: implementation: [] references: samm2: - - O-IM-2-A + - O-IM-A-2 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 12.4.1 @@ -124,7 +121,7 @@ Information Gathering: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-logging-cheats references: samm2: - - O-IM-1-A + - O-IM-A-1 iso27001-2017: - 12.4.1 iso27001-2022: @@ -154,7 +151,7 @@ Information Gathering: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/bash references: samm2: - - O-IM-1-A + - O-OM-A-1 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 12.4.1 @@ -181,7 +178,7 @@ Information Gathering: time: 3 resources: 3 usefulness: 4 - level: 2 + level: 3 dependsOn: - Centralized system logging - Centralized application logging @@ -189,7 +186,7 @@ Information Gathering: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/elk-stack references: samm2: - - O-IM-1-A + - O-IM-A-1 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 12.4.1 @@ -199,3 +196,22 @@ Information Gathering: isImplemented: false evidence: "" comments: "" + Analyze logs: + uuid: b217c8bb-5d61-4b41-a675-1083993f83b1 + risk: Not aware of attacks happening. + measure: Check logs for keywords. + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 2 + usefulness: 3 + level: 3 + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/sigmahq + references: + samm2: + - O-IM-A-1 + iso27001-2017: + - ISO 27001:2017 mapping is missing + iso27001-2022: + - ISO 27001:2022 mapping is missing diff --git a/src/assets/YAML/default/InformationGathering/Monitoring.yaml b/src/assets/YAML/default/InformationGathering/Monitoring.yaml index 450dbc9..2d0b6f8 100755 --- a/src/assets/YAML/default/InformationGathering/Monitoring.yaml +++ b/src/assets/YAML/default/InformationGathering/Monitoring.yaml @@ -20,7 +20,7 @@ Information Gathering: implementation: [] references: samm2: - - O-IM-2-A + - O-IM-A-2 iso27001-2017: - 12.1.3 iso27001-2022: @@ -46,7 +46,7 @@ Information Gathering: implementation: [] references: samm2: - - O-IM-2-A + - O-IM-A-2 iso27001-2017: - 12.6.1 iso27001-2022: @@ -70,7 +70,7 @@ Information Gathering: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/falco references: samm2: - - O-IM-2-A + - O-IM-A-2 iso27001-2017: - 12.6.1 iso27001-2022: @@ -94,7 +94,8 @@ Information Gathering: implementation: [] references: samm2: - - I-DM-A 3 + - O-IM-A-2 + - I-DM-A-3 iso27001-2017: - 16.1.2 - 16.1.4 @@ -126,11 +127,10 @@ Information Gathering: level: 4 dependsOn: - Visualized metrics - implementation: - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/https-ht-transpare + implementation: [] references: samm2: - - O-IM-2-A + - O-IM-A-2 iso27001-2017: - not explicitly covered by ISO 27001 - too specific iso27001-2022: @@ -153,7 +153,7 @@ Information Gathering: implementation: [] references: samm2: - - O-IM-1-A + - O-IM-A-1 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 12.1.3 @@ -183,7 +183,7 @@ Information Gathering: implementation: [] references: samm2: - - O-IM-2-A + - O-IM-A-2 iso27001-2017: - 12.4.1 - 13.1.1 @@ -206,7 +206,7 @@ Information Gathering: implementation: [] references: samm2: - - O-IM-2-A + - O-IM-A-2 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 12.1.3 @@ -231,7 +231,7 @@ Information Gathering: implementation: [] references: samm2: - - O-IM-2-A + - O-IM-A-2 iso27001-2017: - not explicitly covered by ISO 27001 iso27001-2022: @@ -259,7 +259,7 @@ Information Gathering: implementation: [] references: samm2: - - O-IM-2-A + - O-IM-A-2 iso27001-2017: - 12.1.3 iso27001-2022: @@ -284,59 +284,73 @@ Information Gathering: implementation: [] references: samm2: - - O-IM-2-A + - O-IM-A-2 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 16.1.5 iso27001-2022: - Not explicitly covered by ISO 27001 - too specific - 5.26 - isImplemented: false - evidence: "" comments: "" Simple application metrics: uuid: e9a6d403-a467-445e-b98a-74f0c29da0b1 - risk: Attacks on an application are not recognized. - measure: - Gathering of application metrics helps to identify incidents like brute - force attacks, login/logout. + description: | + Collecting basic operational data from applications, such as authentication attempts, transaction volumes, and resource usage, will help detect abnormal patterns that may indicate security incidents or system issues. + risk: | + Without monitoring application metrics, attacks or abnormal behaviors may go undetected, increasing the risk of successful exploitation, data breaches, and delayed incident response. + measure: | + Gathering of application metrics helps to identify incidents like brute force attacks, login/logout patterns, and unusual spikes in activity. Key metrics to monitor include: + - Authentication attempts (successful/failed logins) + - Transaction volumes and patterns (e.g. orders, payments) + - API call rates and response times + - User session metrics + - Resource utilization + + Example: An e-commerce application normally processes 100 orders per hour. A sudden spike to 1000 orders per hour could indicate either: + - A legitimate event (unannounced marketing campaign, viral social media post) + - A security incident (automated bulk purchase bots, credential stuffing attack) + + By monitoring these basic metrics, teams can quickly investigate abnormal patterns and determine if they represent security incidents requiring response. + assessment: | + - Basic application metrics are collected and reviewed. + level: 1 difficultyOfImplementation: knowledge: 2 time: 2 resources: 2 usefulness: 5 - level: 1 implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/prometheus references: samm2: - - O-IM-1-A + - O-IM-A-1 iso27001-2017: - 12.4.1 iso27001-2022: - 8.15 - isImplemented: false - evidence: "" comments: "" Simple budget metrics: uuid: f08a3219-6941-43ec-8762-4aff739f4664 - risk: - Not getting notified about reaching the end of the budget (e.g. due to - a denial of service) creates unexpected costs. - measure: - Cloud providers often provide insight into budgets. A threshold and - alarming for the budget is set. + description: | + Monitoring resource usage and costs to prevent unexpected expenses. This is especially important in cloud environments where resource consumption can quickly exceed planned budgets. + risk: | + Failure to monitor budget metrics can result in unexpected costs, financial loss, and potential service disruption due to resource exhaustion or denial-of-service attacks. + measure: | + Set up budget monitoring and alerting for all critical resources. Use provider tools to track spending and configure alerts when thresholds are reached. Implement hard limits where possible to prevent budget overruns. + assessment: | + - The organization regularly monitors budget metrics + - Alerting outside given thresholds are implemented + level: 1 difficultyOfImplementation: knowledge: 1 time: 1 resources: 1 usefulness: 5 - level: 1 implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/collected references: samm2: - - O-IM-1-A + - O-IM-A-1 iso27001-2017: - 12.1.3 iso27001-2022: @@ -346,26 +360,25 @@ Information Gathering: comments: "" Simple system metrics: uuid: 3d1f4c3b-f713-46d9-933a-54a014a26c03 - risk: - Without simple metrics analysis of incidents are hard. In case an application - uses a lot of CPU from time to time, it is hard for a developer to find out - the source with Linux commands. - measure: - Gathering of system metrics helps to identify incidents and specially - bottlenecks like in CPU usage, memory usage and hard disk usage. + description: | + Monitoring basic system performance data, such as CPU, memory, and disk usage, will help identify performance bottlenecks and potential security incidents. + risk: | + Without monitoring system metrics, it is difficult to detect incidents or performance issues, leading to delayed response, reduced availability, and increased risk of undetected attacks. + measure: | + Collect and monitor key system metrics, including CPU, memory, and disk usage. + assessment: | + - Basic system metrics are monitored and reviewed regularly + level: 1 difficultyOfImplementation: knowledge: 2 time: 2 resources: 2 usefulness: 5 - assessment: | - Are system metrics gathered? - level: 1 implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/collected references: samm2: - - O-IM-1-A + - O-IM-A-1 iso27001-2017: - 12.1.3 iso27001-2022: @@ -392,7 +405,8 @@ Information Gathering: implementation: [] references: samm2: - - I-DM-A 3 + - O-IM-A-2 + - I-DM-A-3 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 16.1.5 @@ -418,7 +432,7 @@ Information Gathering: implementation: [] references: samm2: - - O-IM-2-A + - O-IM-A-2 iso27001-2017: - 12.1.3 iso27001-2022: diff --git a/src/assets/YAML/default/InformationGathering/TestKPI.yaml b/src/assets/YAML/default/InformationGathering/TestKPI.yaml new file mode 100644 index 0000000..3a18fa5 --- /dev/null +++ b/src/assets/YAML/default/InformationGathering/TestKPI.yaml @@ -0,0 +1,231 @@ +# yaml-language-server: $schema=../../schemas/dsomm-schema-information-gathering.json +--- +Information Gathering: + Test KPI: + #Number of vulnerabilities - appsec - vuln management ? + # Fix Rate? + Number of vulnerabilities/severity: + uuid: bc548cba-cb82-4f76-bd4b-325d9d256279 + risk: |- + Failing to convey the number of vulnerabilities by severity might undermine the effectiveness of product teams. This might lead to ignorance of findings. + measure: |- + Measurement and communication of vulnerabilities per severity for components like applications. At least quarterly. + description: |- + Communication can be performed in a simple way, e.g. text based during the build process. + This activity depends on at least one security testing implementation. + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 2 + usefulness: 3 + level: 2 + dependsOn: [] + implementation: [] + references: + samm2: + - I-DM-B-2 + iso27001-2022: + - 5.25 + - 5.12 + - 5.13 + - 5.10 + tags: + - vulnerability-mgmt + - metrics + - vmm-measurement + Number of vulnerabilities/severity/layer: + uuid: 0ec92899-a5cb-4649-984b-2fb1d6c784ad + risk: |- + Failing to convey the number of vulnerabilities by severity and layer (app/infra) might undermine the effectiveness of product teams. This might lead to ignorance of findings. + measure: |- + Measurement and communication of vulnerabilities per severity for components like applications and split it depending on the layer (e.g. app/infra). At least quarterly. + description: |- + Communication can be performed in a simple way, e.g. text based during the build process. + This activity depends on at least one security testing implementation. + Layers to consider (SCA): + - Cloud provider (if insights are possible) + - Runtimes, e.g. Kubernetes nodes + - Base images and container images + - Application + + Layers to consider SAST/DAST: + - Cloud provider + - Runtime, e.g. Kubernetes + - Base images and container images + - Application + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 2 + usefulness: 3 + level: 2 + dependsOn: [] + implementation: [] + references: + samm2: + - I-DM-B-2 + iso27001-2022: + - 5.25 + - 5.12 + - 5.13 + - 5.10 + tags: + - vulnerability-mgmt + - metrics + - vmm-measurement + Patching mean time to resolution via PR: + uuid: 86d490b9-d798-4a5b-a011-ab9688014c46 + risk: |- + Without measuring Mean Time to Resolution (MTTR) related to patching, it is challenging to identify delays in the patching process. Unaddressed vulnerabilities can be exploited by attackers, leading to potential security breaches and data loss. + measure: |- + Measurement and communication of patching Mean Time to Resolution (MTTR) in alignment with Service Level Agreements (SLAs), conducted at least on a quarterly basis. + This includes the measurement of the existence of a properly configured automated pull request (PR) tool (e.g., Dependabot or Renovate) in a repository. + In addition, the measurement of the time from opening an automated PR to merging it. + + Average time to patch is visualized per component/project/team. + difficultyOfImplementation: + knowledge: 1 + time: 1 + resources: 2 + usefulness: 3 + level: 2 + dependsOn: + - 8ae0b92c-10e0-4602-ba22-7524d6aed488 #Automated PRs for patches + implementation: [] + references: + samm2: + - I-DM-B-2 + iso27001-2022: + - 5.25 + - 5.12 + - 5.13 + - 5.10 + tags: + - patching + - metrics + - vmm-measurements + SLA per criticality: # is this the definition of SLAs or the measurement? + uuid: 51f3fce5-b5c8-4683-8c41-e785fe4f3b5f + risk: |- + Not communicating how many applications are adhering to SLAs based on the criticality of vulnerabilities can lead to delayed remediation of + critical security issues, increasing the risk of exploitation and potential damage to the organization. + measure: |- + Measurement and communication of how many of the vulnerabilities handling per severity for components like applications are aligned to SLAs. + This is performed for the hole organization and doesn't need to be broken down (yet) on team/product/application. + At least quarterly. + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 2 + usefulness: 3 + level: 3 + dependsOn: [] + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-defectdojo + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/purify + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/business-friendly-vulnerability-metrics + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/defectdojo-client + references: + samm2: + - I-DM-B-2 + iso27001-2022: + - 5.25 + - 5.12 + - 5.13 + - 5.10 + tags: + - vulnerability-mgmt + - metrics + - vmm-measurements + Patching mean time to resolution via production: + uuid: 77ffc53e-9f3d-41f4-92d3-02f04f9b6b0f + risk: |- + Without measuring Mean Time to Resolution (MTTR) related to patching, it is challenging to identify delays in the patching process. Unaddressed vulnerabilities can be exploited by attackers, leading to potential security breaches and data loss. + measure: |- + Measurement and communication of the time from the availability of a patch to its deployment in production in alignment with Service Level Agreements (SLAs), conducted at least on a quarterly basis. + Average time to patch is visualized per component/project/team. + difficultyOfImplementation: + knowledge: 1 + time: 1 + resources: 2 + usefulness: 3 + level: 4 + dependsOn: + - 86d490b9-d798-4a5b-a011-ab9688014c46 # Patching mean time to resolution via PR + - 8ae0b92c-10e0-4602-ba22-7524d6aed488 # Automated PRs for patches + implementation: [] + references: + samm2: + - I-DM-B-2 + iso27001-2017: + - 16.1.4 + iso27001-2022: + - 5.25 + tags: + - patching + - metrics + - vmm-measurements + Generation of response statistics: + uuid: c922981b-65ed-40f3-a947-96fee9a0125f + risk: No or delayed reaction to findings leads to potential exploitation of findings. + measure: Creation and response statistics (e.g. Mean Time to Resolution) of findings. This is also referred to as _Mean Time to Resolve_. + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 1 + usefulness: 3 + dependsOn: + - Usage of a vulnerability management system + level: 3 + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-defectdojo + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/purify + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/business-friendly-vulnerability-metrics + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/defectdojo-client + references: + samm2: + - I-DM-B-2 + - I-SB-B-3 + iso27001-2017: + - 16.1.4 + - 8.2.3 + iso27001-2022: + - 5.25 + - 5.10 + tags: + - vulnerability-mgmt + - metrics + - vmm-measurements + comments: "The [DefectDojo-Client](https://github.com/SDA-SE/defectdojo-client/tree/master/statistic-client) generates statistics from OWASP DefectDojo and places the results in a [Github repository](https://github.com/pagel-pro/cluster-image-scanner-all-results)." + Fix rate per repo/product: + uuid: cf0d600e-114d-4887-9059-d81c53805f0d + risk: |- + Not communicating how many applications are adhering to SLAs based on the criticality of vulnerabilities can lead to delayed remediation of + critical security issues, increasing the risk of exploitation and potential damage to the organization. + measure: |- + Measurement and communication of the number of vulnerabilities handled per severity level for components such as applications, ensuring alignment with SLAs. + The rate should be broken down by team, product, application, repository, and/or service. This analysis should be conducted at least quarterly. + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 2 + usefulness: 3 + level: 3 + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-defectdojo + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/purify + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/business-friendly-vulnerability-metrics + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/defectdojo-client + references: + samm2: + - I-DM-B-2 + iso27001-2022: + - 5.25 + - 5.12 + - 5.13 + - 5.10 + tags: + - vulnerability-mgmt + - metrics + - vmm-measurements + diff --git a/src/assets/YAML/default/InformationGathering/_meta.yaml b/src/assets/YAML/default/InformationGathering/_meta.yaml index 646d2cc..cea4d30 100755 --- a/src/assets/YAML/default/InformationGathering/_meta.yaml +++ b/src/assets/YAML/default/InformationGathering/_meta.yaml @@ -2,4 +2,4 @@ _meta: label: Information Gathering icon: Information Gathering.png description: |- - A markdown description of this dimension. + Gathering of Information diff --git a/src/assets/YAML/default/TestAndVerification/ApplicationTests.yaml b/src/assets/YAML/default/TestAndVerification/ApplicationTests.yaml index 4efbe99..4266f36 100755 --- a/src/assets/YAML/default/TestAndVerification/ApplicationTests.yaml +++ b/src/assets/YAML/default/TestAndVerification/ApplicationTests.yaml @@ -19,7 +19,7 @@ Test and Verification: implementation: [] references: samm2: - - V-ST-3-B + - V-RT-B-3 iso27001-2017: - 14.2.3 - 14.2.8 @@ -45,7 +45,7 @@ Test and Verification: level: 3 references: samm2: - - V-ST-3-B + - V-RT-A-3 iso27001-2017: - 14.2.3 - 14.2.8 @@ -75,7 +75,7 @@ Test and Verification: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/karma references: samm2: - - V-ST-3-B + - V-RT-A-3 iso27001-2017: - 14.2.3 - 14.2.8 @@ -100,10 +100,10 @@ Test and Verification: level: 4 implementation: [] dependsOn: - - Defined deployment process + - 67e1a9aa-9fbf-4ec5-a2de-400f01960c51 # Automated deployment process references: samm2: - - V-ST-3-B + - V-RT-A-3 iso27001-2017: - 14.2.3 - 14.2.8 diff --git a/src/assets/YAML/default/TestAndVerification/Consolidation.yaml b/src/assets/YAML/default/TestAndVerification/Consolidation.yaml index e0f366d..c012cca 100755 --- a/src/assets/YAML/default/TestAndVerification/Consolidation.yaml +++ b/src/assets/YAML/default/TestAndVerification/Consolidation.yaml @@ -2,25 +2,32 @@ --- Test and Verification: Consolidation: - Advanced visualization of defects: - uuid: 7a82020c-94d1-471c-bbd3-5f7fe7df4876 + Fix based on accessibility: + uuid: 0c10a7f7-f78f-49f2-943d-19fdef248fed risk: - Correlation of the vulnerabilities of different tools to have an overview - of the the overall security level per component/project/team is not given. - measure: Findings are visualized per component/project/team. + Overwhelming volume of security findings from automated testing tools. This might lead to ignorance of findings. + measure: |- + Implement a simple risk-based prioritization framework for vulnerability remediation based on accessibility of the applications. difficultyOfImplementation: knowledge: 2 - time: 4 + time: 2 resources: 1 - usefulness: 2 - level: 4 + usefulness: 4 + level: 3 + meta: + implementationGuide: |- + Develop a scoring system for asset accessibility, considering factors like: + - Whether the asset is internet-facing (highly recommended) + - The number of network hops required to reach the asset (recommended) + - Authentication requirements for access (recommended) + dependsOn: + - 44f2c8a9-4aaa-4c72-942d-63f78b89f385 # Treatment of defects with severity high or higher: + #- 3260a15f-2df0-4173-8790-f11de2cb525a # Access applications accessibility TODO + - 2a44b708-734f-4463-b0cb-86dc46344b2f # Inventory of production components implementation: - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-defectdojo - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/purify - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/business-friendly-vulnerability-metrics references: samm2: - - I-DM-3-B + - I-DM-A-3 iso27001-2017: - 16.1.4 - 8.2.1 @@ -31,64 +38,38 @@ Test and Verification: - 5.12 - 5.13 - 5.10 - isImplemented: false - evidence: "" - comments: "" - Generation of Response Statistics: - uuid: c922981b-65ed-40f3-a947-96fee9a0125f - risk: No or delayed reaction to findings leads to potential exploitation of findings. - measure: Creation and response statistics of findings. This is also referred to as _Mean Time to Resolve_. + tags: ["vuln-action", "defect-management"] + Advanced visualization of defects: + uuid: 7a82020c-94d1-471c-bbd3-5f7fe7df4876 + risk: + Correlation of the vulnerabilities of different tools to have an overview + of the the overall security level per component/project/team is not given. + measure: Findings are visualized per component/project/team. difficultyOfImplementation: knowledge: 2 - time: 2 + time: 4 resources: 1 - usefulness: 3 - dependsOn: - - Usage of a vulnerability management system - level: 3 + usefulness: 2 + level: 4 implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-defectdojo - $ref: src/assets/YAML/default/implementations.yaml#/implementations/purify - $ref: src/assets/YAML/default/implementations.yaml#/implementations/business-friendly-vulnerability-metrics - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/defectdojo-client references: samm2: - - I-DM-2-B + - I-DM-A-3 iso27001-2017: - 16.1.4 + - 8.2.1 + - 8.2.2 - 8.2.3 iso27001-2022: - 5.25 + - 5.12 + - 5.13 - 5.10 isImplemented: false evidence: "" - comments: "The [DefectDojo-Client](https://github.com/SDA-SE/defectdojo-client/tree/master/statistic-client) generates statistics from OWASP DefectDojo and places the results in a [Github repository](https://github.com/pagel-pro/cluster-image-scanner-all-results)." - Generation of Patch Management Statistics: - uuid: 785e34ef-40c6-487a-984c-3e7706c9bc1f - risk: Delays in patch response lead to an increased attack surface through longer exposure of known vulnerabilities. - measure: Average time to patch is visualized per component/project/team. - difficultyOfImplementation: - knowledge: 2 - time: 2 - resources: 1 - usefulness: 2 - level: 3 - dependsOn: - - A patch policy is defined - - Automated PRs for patches - implementation: - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-defectdojo - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/purify - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/business-friendly-vulnerability-metrics - references: - samm2: - - I-DM-3-B - iso27001-2017: - - 16.1.4 - iso27001-2022: - - 5.25 - isImplemented: false - evidence: "" comments: "" Integration of vulnerability issues into the development process: uuid: ce970c9b-da94-41cf-bd78-8c15357b7e8e @@ -108,7 +89,7 @@ Test and Verification: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/dast references: samm2: - - I-DM-2-B + - I-DM-A-2 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 16.1.4 @@ -140,7 +121,7 @@ Test and Verification: implementation: [] references: samm2: - - I-DM-2-B + - I-DM-A-2 iso27001-2017: - 16.1.4 - 8.2.1 @@ -156,25 +137,42 @@ Test and Verification: comments: "" Simple false positive treatment: uuid: c1acc8af-312e-4503-a817-a26220c993a0 - risk: - As false positive occur during each test, all vulnerabilities might be - ignored. - measure: - False positives are suppressed so they will not show up on the next - tests again. Most security tools have the possibility to suppress false positives. - A Vulnerability Management System might be used. + description: | + Security tests may produce false positives (or _"false alarms"_), findings that are incorrectly identified as vulnerabilities. + + It is important distinguish these from true positive vulnerabilities to avoid wasting time and resources on non-issues. + + False positive treatment ensures that findings from security tests are triaged and documented, allowing teams to distinguish between real vulnerabilities and false positives. This reduces unnecessary work and helps maintain focus on true risks. + + Some positive findings might be considered an _accepted risk_ by the organization. This must also be documented. + risk: | + If false positives are not managed, teams may ignore all findings, leading to real vulnerabilities being overlooked and increasing the risk of exploitation. Specially, if tests are automated an run daily. + measure: | + Findings from security tests must be triaged and outcomes persisted/documented to: + - Prevent re-analysis of known issues in subsequent test runs + - Track accepted risks vs false positives + - Enable consistent decision-making across teams + + At this maturity level, a simple tracking system suffices - tools need only distinguish between "triaged" and "untriaged" findings, without complex categorization. Some tools refer to this as "suppression" of findings. + + Samples for false positive handling: + - [OWASP Dependency Check](https://jeremylong.github.io/DependencyCheck/general/suppression.html) + - [Kubescape with VEX](https://kubescape.io/blog/2023/12/07/kubescape-support-for-vex-generation/) + - [OWASP DefectDojo Risk Acceptance](https://docs.defectdojo.com/en/working_with_findings/findings_workflows/risk_acceptances/) and [False Positive Handling](https://docs.defectdojo.com/en/working_with_findings/intro_to_findings/#triage-vulnerabilities-using-finding-status) + assessment: | + A process is defined for triaging and documenting false positives and accepted risks + level: 1 difficultyOfImplementation: knowledge: 1 time: 1 resources: 1 usefulness: 4 - level: 1 implementation: - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-defect-dojo + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-defectdojo - $ref: src/assets/YAML/default/implementations.yaml#/implementations/purify references: samm2: - - I-DM-2-A + - I-DM-A-1 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 16.1.6 @@ -182,8 +180,49 @@ Test and Verification: - Not explicitly covered by ISO 27001 - too specific - 5.27 isImplemented: false + tags: ["false-positive", "defect-management", "scanning", "sca", "sats", "dast"] evidence: "" comments: "" + Artifact-based false positive treatment: + uuid: 8f2b4d5a-3c1e-4b7a-9d8f-2e6c4a1b5d7f + risk: + Without artifact-specific false positive handling, teams must repeatedly + triage the same findings across different versions or deployments of the + same component, leading to inefficient use of security resources. + measure: |- + Implement false positive marking and temporary acceptance of findings + based on specific artifacts (applications, components, or repositories). + This allows teams to suppress findings for specific versions or builds + while maintaining visibility for future releases. + description: |- + Artifact-based false positive treatment enables more granular control + over finding suppression by linking decisions to specific code artifacts, + container images, or application versions. This approach helps maintain + security oversight while reducing repeated analysis overhead. + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 2 + usefulness: 3 + level: 2 + dependsOn: + - c1acc8af-312e-4503-a817-a26220c993a0 # Simple false positive treatment + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-defectdojo + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/purify + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/dependencyTrack + references: + samm2: + - I-DM-A-2 + - I-DM-B-2 + - I-SB-B-3 + iso27001-2017: + - 16.1.4 + - 16.1.6 + iso27001-2022: + - 5.25 + - 5.27 + tags: ["false-positive", "defect-management", "scanning", "sca", "sats", "dast"] Simple visualization of defects: uuid: 55f4c916-3a34-474d-ad96-9a9f7a4f6a83 risk: @@ -204,7 +243,7 @@ Test and Verification: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/purify references: samm2: - - I-DM-1-B + - I-DM-A-2 iso27001-2017: - 16.1.4 - 8.2.1 @@ -231,42 +270,48 @@ Test and Verification: implementation: [] references: samm2: - - I-DM-2-B + - I-DM-A-2 iso27001-2017: - 16.1.4 - 12.6.1 iso27001-2022: - 8.8 - 5.25 - isImplemented: false - evidence: "" + tags: ["vuln-action", "defect-management"] comments: "" - Treatment of defects with severity high or higher: + Treatment of defects with high or critical severity: uuid: 44f2c8a9-4aaa-4c72-942d-63f78b89f385 - risk: Vulnerabilities with severity high or higher are not visible. - measure: - Vulnerabilities with severity high or higher are added to the quality - gate. + description: | + All security problems that are rated as "high" or "critical" must be fixed before the software can be released or used in production. This means that if a serious vulnerability is found, it cannot be ignored or postponed. + risk: | + If serious security problems are not fixed, attackers could exploit them to steal data, disrupt services, or cause other harm. Ignoring these issues puts the organization, its customers, and its reputation at risk. + measure: | + - Make it a rule that all _high_ or _critical_ security findings must be fixed before the software is approved for release or use. + - Track these issues and make sure they are resolved quickly. + assessment: | + - Provide evidence that vulnerabilities are treated within the defined time frame in production. For example via the DSOMM activity [Number of vulnerabilities/severity](./activity-description?uuid=bc548cba-cb82-4f76-bd4b-325d9d256279) or [Patching mean time to resolution via PR](./activity-description?uuid=86d490b9-d798-4a5b-a011-ab9688014c46) with extra deployment statistics. + comments: False positive analysis, specially for static analysis, is time consuming. + level: 1 difficultyOfImplementation: knowledge: 2 time: 2 resources: 1 usefulness: 4 - level: 1 - comments: False positive analysis, specially for static analysis, is time consuming. references: samm2: - - I-DM-2-B + - I-DM-A-2 iso27001-2017: - 16.1.4 - 12.6.1 iso27001-2022: - 8.8 - 5.25 - implementation: [] - isImplemented: false + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/trivy + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/grype + tags: ["vuln-action", "defect-management"] evidence: "" - Treatment of defects with severity middle: + Treatment of defects with medium severity: uuid: 9cac3341-fe83-4079-bef2-bfc4279eb594 risk: Vulnerabilities with severity middle are not visible. measure: Vulnerabilities with severity middle are added to the quality gate. @@ -279,7 +324,7 @@ Test and Verification: comments: False positive analysis, specially for static analysis, is time consuming. references: samm2: - - I-DM-2-B + - I-DM-A-2 iso27001-2017: - 16.1.4 - 12.6.1 @@ -287,8 +332,49 @@ Test and Verification: - 8.8 - 5.25 implementation: [] - isImplemented: false - evidence: "" + tags: ["vuln-action", "defect-management"] + Global false positive treatment: + uuid: 9e3a7c2f-1b4d-4e8a-a5c6-7f2b9d1e3a8c + risk: + Without centralized false positive management across environments, + organizations face inconsistent security decisions, duplicated analysis + efforts, and potential security gaps when the same findings are handled + differently across applications and teams. + measure: |- + Implement global false positive and acceptance management that applies + consistently across all applications. This enables organization-wide security decisions and reduces redundant + analysis of common false positives. + description: |- + Global false positive treatment allows (security) teams to make + organization-wide decisions about specific vulnerabilities or finding + patterns. When a finding is marked as a false positive or temporarily + accepted at the global level, this decision automatically applies to + all applications in the specified environment, ensuring consistency + and operational efficiency. + difficultyOfImplementation: + knowledge: 3 + time: 3 + resources: 2 + usefulness: 4 + level: 3 + dependsOn: + - 8f2b4d5a-3c1e-4b7a-9d8f-2e6c4a1b5d7f # Artifact-based false positive treatment + - 85ba5623-84be-4219-8892-808837be582d # Usage of a vulnerability management system + implementation: + references: + samm2: + - I-DM-B-2 + - I-DM-A-3 + - I-SB-B-3 + iso27001-2017: + - 16.1.3 + - 16.1.4 + - 16.1.6 + iso27001-2022: + - 6.8 + - 5.25 + - 5.27 + tags: ["false-positive", "defect-management"] Usage of a vulnerability management system: uuid: 85ba5623-84be-4219-8892-808837be582d risk: @@ -296,20 +382,29 @@ Test and Verification: In addition a correlation of the same finding from different tools is not possible. measure: - Aggregation of vulnerabilities in one tool reduce the workload to mark - false positives. + Aggregation of vulnerabilities in one tool reduce the workload to handle them, e.g. mark as false positives. difficultyOfImplementation: knowledge: 3 time: 3 resources: 2 usefulness: 2 + dependsOn: + - f2f0f274-c1a0-4501-92fe-7fc4452bc8ad # EPSS/CISA KEV + - 6217fe11-5ed7-4cf4-9de4-555bcfa6fe87 # Each team has a security champion + - 185d5a74-19dc-4422-be07-44ea35226783 # Office Hours level: 3 + description: |- + For known vulnerabilities a processes to estimate the exploit ability of a vulnerability is recommended. + + To implement a security culture including training, office hours and security champions can help integrating + security scanning at scale. Such activities help to understand why a vulnerability is potentially critical and needs handling. implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-defectdojo - $ref: src/assets/YAML/default/implementations.yaml#/implementations/purify + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/SecObserve references: samm2: - - I-DM-1-B + - I-DM-A-3 iso27001-2017: - 12.6.1 - 16.1.3 @@ -322,6 +417,89 @@ Test and Verification: - 5.25 - 5.26 - 5.27 - isImplemented: false - evidence: "" - comments: "" + Integration in development process: + uuid: aaffa73f-59f6-4267-b0ab-732f3d13e90d + risk: |- + Not integrating vulnerability handling into the development process may result in product teams ignoring findings. + + Security joke: We will gain 100% false negatives. + measure: |- + Integration of findings into the development process. E.g. adding findings to the backlog of products teams. + description: |- + Validating Findings by Security Engineers Pros: + - Ensures accuracy and relevance of findings before they reach product teams + - Reduces false positives, saving development teams time and effort + - Might provides a layer of expertise in assessing the severity and impact of vulnerabilities + + Validating Findings by Security Engineers Cons: + - Requires a sufficient number of skilled security engineers, which might be challenging for some organizations + - May slow down the process if security engineers are overloaded with validation tasks + - For Software Composition Analysis findings (known vulnerabilities) I, as a sec. eng., struggle to analysis if it is a false positive/true positive due to a lack of insights in the application + + Pushing Findings Directly to Product Teams Pros: + - Accelerates the process by immediately notifying product teams of potential vulnerabilities + - Empowers product teams to take swift action in addressing security issues + Pushing Findings Directly to Product Teams Cons: + - Increases the workload on product teams, potentially leading to frustration + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 2 + usefulness: 3 + level: 3 + dependsOn: [] + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/jira + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-defectdojo + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/purify + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/defectdojo-client + references: + samm2: + - I-DM-A-2 + iso27001-2022: + - 5.25 + - 5.12 + - 5.13 + - 5.10 + tags: + - vulnerability-mgmt + - vmm-measurements + Treatment of defects per protection requirement: + uuid: 2b7cc923-bdaf-43e3-8fb4-a995b7783969 + risk: |- + Not defining the protection requirement of applications can lead to wrong prioritization, delayed remediation of + critical security issues, increasing the risk of exploitation and potential damage to the organization. + measure: |- + Defining the protection requirement and the corresponding handling of vulnerabilities per severity for components like applications are aligned to SLAs. + This is performed for the hole organization and doesn't need to be broken down (yet) on team/product/application. + At least quarterly. + description: |- + The protection requirements for an application should consider: + - Data criticality + - Application accessibility (internal vs. external) + - Regulatory compliance + - Other relevant factors + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 2 + usefulness: 3 + level: 3 + dependsOn: [] + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-defectdojo + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/purify + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/business-friendly-vulnerability-metrics + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/defectdojo-client + references: + samm2: + - I-DM-A-2 + iso27001-2022: + - 5.25 + - 5.12 + - 5.13 + - 5.10 + tags: + - vulnerability-mgmt + - metrics + - vmm-measurements diff --git a/src/assets/YAML/default/TestAndVerification/DynamicDepthForApplications.yaml b/src/assets/YAML/default/TestAndVerification/DynamicDepthForApplications.yaml index 33c4165..c3cded1 100755 --- a/src/assets/YAML/default/TestAndVerification/DynamicDepthForApplications.yaml +++ b/src/assets/YAML/default/TestAndVerification/DynamicDepthForApplications.yaml @@ -17,7 +17,7 @@ Test and Verification: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/coveragepy references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - not explicitly covered by ISO 27001 - too specific - part of periodic review, PDCA @@ -30,7 +30,9 @@ Test and Verification: uuid: 9711f871-f79d-4573-8d4f-d2c98fd0d18e risk: Parts of the service are not covered during the scan, because JavaScript - is not getting executed. Therefore, the co + is not getting executed. Therefore, the coverage of client-side dynamic + components is limited, leading to potential security risks and undetected + vulnerabilities. measure: Usage of a spider which executes dynamic content like JavaScript, e.g. via Selenium. @@ -44,7 +46,7 @@ Test and Verification: - Usage of different roles references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - 14.2.3 - 14.2.8 @@ -77,7 +79,7 @@ Test and Verification: - Usage of different roles references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - not explicitly covered by ISO 27001 - too specific iso27001-2022: @@ -104,7 +106,7 @@ Test and Verification: - Usage of different roles references: samm2: - - V-ST-2-A + - V-RT-B-1 iso27001-2017: - not explicitly covered by ISO 27001 - too specific iso27001-2022: @@ -134,7 +136,7 @@ Test and Verification: - Usage of different roles references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - 14.2.8 - 14.2.3 @@ -158,7 +160,7 @@ Test and Verification: - Simple Scan references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - 14.2.3 - 14.2.8 @@ -166,7 +168,6 @@ Test and Verification: - 8.32 - 8.29 implementation: - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/pact-io - $ref: src/assets/YAML/default/implementations.yaml#/implementations/citrusframework isImplemented: false evidence: "" @@ -194,7 +195,7 @@ Test and Verification: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/arachni references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - 14.2.3 - 14.2.8 @@ -220,7 +221,7 @@ Test and Verification: - Simple Scan references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - not explicitly covered by ISO 27001 - too specific - 14.2.3 @@ -254,7 +255,7 @@ Test and Verification: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-securecodebox references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - 12.6.1 - 14.2.5 diff --git a/src/assets/YAML/default/TestAndVerification/DynamicDepthForInfrastructure.yaml b/src/assets/YAML/default/TestAndVerification/DynamicDepthForInfrastructure.yaml index f0859e6..20db40e 100755 --- a/src/assets/YAML/default/TestAndVerification/DynamicDepthForInfrastructure.yaml +++ b/src/assets/YAML/default/TestAndVerification/DynamicDepthForInfrastructure.yaml @@ -19,7 +19,7 @@ Test and Verification: implementation: [] references: samm2: - - V-ST-1-A + - V-RT-AB-1 iso27001-2017: - 12.1.3 - 14.2.3 @@ -54,7 +54,7 @@ Test and Verification: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-amass references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - 13.1.3 - 14.2.3 @@ -113,7 +113,7 @@ Test and Verification: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/k8spurger references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - 13.1.3 - 14.2.3 @@ -142,10 +142,10 @@ Test and Verification: implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/netassert dependsOn: - - Segmented networks for virtual environments + - 4ce24abd-8ba6-494c-828d-4d193e28e4a1 # Isolated networks for virtual environments references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - 13.1.3 - 14.2.3 @@ -154,8 +154,6 @@ Test and Verification: - 8.22 - 8.32 - 8.29 - isImplemented: false - evidence: "" comments: "" Test of the configuration of cloud environments: uuid: 7bb70764-9392-4462-935d-e55b2e148199 @@ -208,7 +206,7 @@ Test and Verification: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/htc-hydra references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - 9.4.3 iso27001-2022: diff --git a/src/assets/YAML/default/TestAndVerification/StaticDepthForApplications.yaml b/src/assets/YAML/default/TestAndVerification/StaticDepthForApplications.yaml index c2056c0..21a7637 100755 --- a/src/assets/YAML/default/TestAndVerification/StaticDepthForApplications.yaml +++ b/src/assets/YAML/default/TestAndVerification/StaticDepthForApplications.yaml @@ -18,7 +18,7 @@ Test and Verification: - Defined build process references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - Not explicitly covered by ISO 27001 - too specific - 14.2.1 @@ -30,6 +30,7 @@ Test and Verification: comments: "" Test libyear: <<: *Exclusion-of-source-code-duplicates + uuid: 87b54313-fafd-4860-930f-5ef132b3e4ad risk: Vulnerabilities in running artifacts stay for long and might get exploited. measure: |- Test `libyear`, which provides a good insight how good patch management is. @@ -49,6 +50,7 @@ Test and Verification: - patching Test for Time to Patch: <<: *Exclusion-of-source-code-duplicates + uuid: 13af1227-3dd1-4d4f-a9e9-53deb793c18f risk: Automatic PRs for dependencies are overlooked resulting in known vulnerabilities in production artifacts. measure: |- Test of the Time to Patch (e.g. based on Mean Time to Close automatic PRs) @@ -72,6 +74,7 @@ Test and Verification: - patching Test for Patch Deployment Time: <<: *Exclusion-of-source-code-duplicates + uuid: 0cb2c39a-3cec-4353-b3ab-8d70daf4c9d2 risk: Automatic PRs for dependencies are overlooked resulting in known vulnerabilities in production artifacts. dependsOn: - Automated PRs for patches @@ -93,7 +96,7 @@ Test and Verification: - patching Dead code elimination: <<: *Exclusion-of-source-code-duplicates - uuid: d17dbff0-1f10-492a-b4c7-17bb59a0a711 + uuid: a8d7d1f1-fc24-49ab-8fb6-f3a03da9c61d risk: Dead code increases the attack surface (use of hard coded credentials and variables, sensitive information) @@ -114,12 +117,11 @@ Test and Verification: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/fortify-vscode-extension - $ref: src/assets/YAML/default/implementations.yaml#/implementations/checkmarx-vscode-extension - $ref: src/assets/YAML/default/implementations.yaml#/implementations/appscan-vscode-extension - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/pre-commit - $ref: src/assets/YAML/default/implementations.yaml#/implementations/pre-commit-microsoft - $ref: src/assets/YAML/default/implementations.yaml#/implementations/pre-commit-synopsis references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - Hardening is not explicitly covered by ISO 27001 - too specific - 13.1.3 @@ -140,14 +142,14 @@ Test and Verification: knowledge: 2 time: 2 resources: 2 - usefulness: 4 - level: 2 + usefulness: 3 + level: 3 implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/stoplight-spectral - $ref: src/assets/YAML/default/implementations.yaml#/implementations/api-oas-checker references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - 14.2.1 - 14.2.5 @@ -156,8 +158,8 @@ Test and Verification: - 8.27 # Secure system architecture and engineering principles - 8.28 # Secure coding isImplemented: false - evidence: "" - comments: "" + dependsOn: + - 2a44b708-734f-4463-b0cb-86dc46344b2f # Inventory of production components Static analysis for all components/libraries: uuid: f4ff841d-3b2a-45d9-853e-5ec7ecbcb054 risk: Used components like libraries and legacy applications might have vulnerabilities @@ -171,10 +173,12 @@ Test and Verification: dependsOn: - Static analysis for important client side components - Static analysis for important server side components + - 2a44b708-734f-4463-b0cb-86dc46344b2f # Inventory of production components implementation: [] references: samm2: - - V-ST-2-A + - V-ST-A-2 + - I-SB-B-3 iso27001-2017: - 12.6.1 iso27001-2022: @@ -205,9 +209,11 @@ Test and Verification: dependsOn: - Static analysis for important client side components - Static analysis for important server side components + - 2a44b708-734f-4463-b0cb-86dc46344b2f # Inventory of production components references: samm2: - - V-ST-2-A + - V-ST-A-2 + - I-SB-B-3 iso27001-2017: - 12.6.1 iso27001-2022: @@ -238,9 +244,10 @@ Test and Verification: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/appscan-vscode-extension dependsOn: - Defined build process + - 2a44b708-734f-4463-b0cb-86dc46344b2f # Inventory of production components references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - 12.6.1 iso27001-2022: @@ -270,9 +277,11 @@ Test and Verification: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/appscan-vscode-extension dependsOn: - Defined build process + - 2a44b708-734f-4463-b0cb-86dc46344b2f # Inventory of production components references: samm2: - - V-ST-2-A + - V-ST-A-2 + - I-SB-B-3 iso27001-2017: - 12.6.1 iso27001-2022: @@ -295,11 +304,12 @@ Test and Verification: implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/pmd - $ref: src/assets/YAML/default/implementations.yaml#/implementations/stylecop - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/sonarqube + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/eslint + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/sonarqube-lint - $ref: src/assets/YAML/default/implementations.yaml#/implementations/github-super-linter references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - 12.6.1 - 14.2.1 @@ -311,6 +321,36 @@ Test and Verification: isImplemented: false evidence: "" comments: "" + Exploit likelihood estimation: + uuid: f2f0f274-c1a0-4501-92fe-7fc4452bc8ad + description: | + Severity-based vulnerability triage alone generates a lot false positives, requiring a more refined approach. + + Use the likelihood of exploitation by using *known exploited vulnerabilities* (CISA KEV), or prediction models such as + *Exploit Prediction Scoring System* (EPSS). + risk: | + Without proper prioritization, organizations may waste time and effort on low-risk vulnerabilities while neglecting critical ones. + measure: | + Use CISA KEV and EPSS to prioritize vulnerabilities that are more likely to be exploited. + difficultyOfImplementation: + knowledge: 2 + time: 2 + resources: 2 + usefulness: 4 + level: 2 + dependsOn: + - d918cd44-a972-43e9-a974-eff3f4a5dcfe # SCA for server + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/cisa-kev + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/epss + references: + samm2: + - V-ST-A-2 + - I-SB-B-3 + iso27001-2017: + - 12.6.1 + iso27001-2022: + - 8.8 Software Composition Analysis (client side): uuid: 07fe8c4f-ae33-4409-b1b2-cf64cfccea86 risk: Client side components might have vulnerabilities. @@ -323,6 +363,8 @@ Test and Verification: level: 3 dependsOn: - Defined build process + - 2a44b708-734f-4463-b0cb-86dc46344b2f # Inventory of production components + - f2f0f274-c1a0-4501-92fe-7fc4452bc8ad # EPSS/CISA KEV implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/retire-js - $ref: src/assets/YAML/default/implementations.yaml#/implementations/npm-audit @@ -330,16 +372,19 @@ Test and Verification: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/github-dependabot references: samm2: - - V-ST-2-A + - V-ST-A-2 + - I-SB-B-2 iso27001-2017: - 12.6.1 iso27001-2022: - 8.8 isImplemented: false + tags: ["defect-management", "sca"] evidence: "" comments: "" Software Composition Analysis (server side): uuid: d918cd44-a972-43e9-a974-eff3f4a5dcfe + description: Use a tool like trivy and concentrate on application related vulnerabilities. At this stage, ignore vulnerabilities in container base images used in the service. risk: Server side components might have vulnerabilities. measure: Tests for known vulnerabilities in server side components (e.g. backend/middleware) @@ -352,22 +397,25 @@ Test and Verification: level: 2 dependsOn: - Defined build process + - 2a44b708-734f-4463-b0cb-86dc46344b2f # Inventory of production components implementation: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-dependency-che - $ref: src/assets/YAML/default/implementations.yaml#/implementations/dependencyTrack - $ref: src/assets/YAML/default/implementations.yaml#/implementations/retire-js - $ref: src/assets/YAML/default/implementations.yaml#/implementations/npm-audit - $ref: src/assets/YAML/default/implementations.yaml#/implementations/github-dependabot + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/trivy references: samm2: - - V-ST-2-A + - V-ST-A-2 + - I-SB-B-2 iso27001-2017: - 12.6.1 iso27001-2022: - 8.8 - isImplemented: false - evidence: "" - comments: "" + tags: + - vmm-testing + tags: ["false-positive", "defect-management", "scanning", "sca", "sats", "dast"] Usage of multiple analyzers: uuid: 297be001-8d94-41ee-ab29-207020d423c0 risk: @@ -387,7 +435,7 @@ Test and Verification: implementation: [] references: samm2: - - V-ST-3-A + - V-ST-A-3 iso27001-2017: - 12.6.1 - 14.2.1 diff --git a/src/assets/YAML/default/TestAndVerification/StaticDepthForInfrastructure.yaml b/src/assets/YAML/default/TestAndVerification/StaticDepthForInfrastructure.yaml index fb8994b..47e6d25 100755 --- a/src/assets/YAML/default/TestAndVerification/StaticDepthForInfrastructure.yaml +++ b/src/assets/YAML/default/TestAndVerification/StaticDepthForInfrastructure.yaml @@ -2,27 +2,6 @@ --- Test and Verification: Static depth for infrastructure: - Analyze logs: - uuid: b217c8bb-5d61-4b41-a675-1083993f83b1 - risk: Not aware of attacks happening. - measure: Check logs for keywords. - difficultyOfImplementation: - knowledge: 2 - time: 2 - resources: 2 - usefulness: 3 - level: 3 - implementation: - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/sigmahq - references: - samm2: [] - iso27001-2017: - - ISO 27001:2017 mapping is missing - iso27001-2022: - - ISO 27001:2022 mapping is missing - isImplemented: false - evidence: "" - comments: "" Test for image lifetime: uuid: ddfe7c3c-b7a4-4cba-9041-b044d4a34e5b risk: @@ -39,7 +18,7 @@ Test and Verification: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/clusterscanner references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - 12.6.1 - 14.2.5 @@ -49,7 +28,7 @@ Test and Verification: isImplemented: false evidence: "" comments: "" - Test for known vulnerabilities: + Software Composition Analysis: uuid: 26e1c6d5-5632-4ec7-80d2-e564b98732ad risk: Known vulnerabilities in infrastructure components like container images @@ -63,17 +42,18 @@ Test and Verification: level: 4 description: Subscribing to Github projects and reading release notes might help. Software Composition Analysis for infrastructure might help, but is often too fine-granular. implementation: - - $ref: src/assets/YAML/default/implementations.yaml#/implementations/https-github-com-a + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/trivy - $ref: src/assets/YAML/default/implementations.yaml#/implementations/registries-like-quay - $ref: src/assets/YAML/default/implementations.yaml#/implementations/dependencyTrack references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - 12.6.1 iso27001-2022: - 8.8 isImplemented: false + tags: ["scanning", "sca"] evidence: "" comments: "" Test for malware: @@ -95,7 +75,7 @@ Test and Verification: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/clusterscanner references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - 12.2.1 iso27001-2022: @@ -116,7 +96,7 @@ Test and Verification: implementation: [] references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - 12.6.1 - 14.2.5 @@ -147,7 +127,7 @@ Test and Verification: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/vuls references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - 12.6.1 - 14.2.1 @@ -157,12 +137,12 @@ Test and Verification: isImplemented: false evidence: "" comments: "" - Test for stored secrets: + Test for stored secrets in code: uuid: c6e3c812-56e2-41b0-ae01-b7afc41a004c risk: - Stored secrets in git history, in container images or directly in code + Stored secrets in git history or directly in code shouldn't exists because they might be exposed to unauthorized parties. - measure: Test for secrets in code, container images and history + measure: Test for secrets in code and git history difficultyOfImplementation: knowledge: 2 time: 1 @@ -174,7 +154,36 @@ Test and Verification: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/go-pillage-registrie references: samm2: - - V-ST-1-A + - V-ST-A-1 + iso27001-2017: + - vcs usage is not explicitly covered by ISO 27001 - too specific + - 9.4.3 + - 10.1.2 + iso27001-2022: + - vcs usage is not explicitly covered by ISO 27001 - too specific + - 5.17 + - 8.24 + isImplemented: false + evidence: "" + comments: "" + Test for stored secrets in build artifacts: + uuid: d5e6303c-d5c6-4d59-b258-a3b9de38a07f + risk: + Stored secrets in container images or other build artifacts + shouldn't exists because they might be exposed to unauthorized parties. + measure: Test for secrets in container images and other artifacts + difficultyOfImplementation: + knowledge: 2 + time: 1 + resources: 2 + usefulness: 2 + level: 1 + implementation: + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/trufflehog + - $ref: src/assets/YAML/default/implementations.yaml#/implementations/go-pillage-registrie + references: + samm2: + - V-ST-A-1 iso27001-2017: - vcs usage is not explicitly covered by ISO 27001 - too specific - 9.4.3 @@ -204,7 +213,7 @@ Test and Verification: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/kubesec references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - System hardening is not explicitly covered by ISO 27001 - too specific - 12.6.1 @@ -242,7 +251,7 @@ Test and Verification: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/vuls references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - 12.6.1 - 14.2.1 @@ -269,7 +278,7 @@ Test and Verification: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/clusterscanner references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - ISO 27001:2017 mapping is missing iso27001-2022: @@ -295,7 +304,7 @@ Test and Verification: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/kube-bench references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - System hardening is not explicitly covered by ISO 27001 - too specific - 12.6.1 @@ -331,7 +340,7 @@ Test and Verification: - $ref: src/assets/YAML/default/implementations.yaml#/implementations/dockerfilelint references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - System hardening, virtual environments are not explicitly covered by ISO 27001 - too specific @@ -340,12 +349,10 @@ Test and Verification: - 14.2.8 - 14.2.1 iso27001-2022: - - System hardening, virtual environments are not explicitly covered by ISO - 27001 - too specific + - System hardening, virtual environments are not explicitly covered by ISO 27001 - too specific - 8.8 - 8.32 - 8.29 - 8.25 isImplemented: false - evidence: "" - comments: "" + diff --git a/src/assets/YAML/default/TestAndVerification/Test-Intensity.yaml b/src/assets/YAML/default/TestAndVerification/Test-Intensity.yaml index ee9ee4c..398d2cf 100755 --- a/src/assets/YAML/default/TestAndVerification/Test-Intensity.yaml +++ b/src/assets/YAML/default/TestAndVerification/Test-Intensity.yaml @@ -1,7 +1,7 @@ # yaml-language-server: $schema=../../schemas/dsomm-schema-test-and-verification.json --- Test and Verification: - Test-Intensity: + Test Intensity: Creation and application of a testing concept: uuid: 79ef8103-e1ed-4055-8df8-fd2b2015bebe risk: Scans might use a too small or too high test intensity. @@ -19,7 +19,7 @@ Test and Verification: implementation: [] references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - 14.2.2 - 14.2.3 @@ -53,7 +53,7 @@ Test and Verification: implementation: [] references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - 12.6.1 - 14.2.1 @@ -70,7 +70,7 @@ Test and Verification: risk: Time pressure and ignorance might lead to false predictions for the test intensity. - measure: The intensity of the used tools are not modified to safe time. + measure: The intensity of the used tools are not modified to save time. difficultyOfImplementation: knowledge: 1 time: 1 @@ -80,7 +80,7 @@ Test and Verification: implementation: [] references: samm2: - - V-ST-1-A + - V-ST-A-1 iso27001-2017: - 12.6.1 - 14.2.1 @@ -105,11 +105,11 @@ Test and Verification: time: 3 resources: 5 usefulness: 3 - level: 1 + level: 3 implementation: [] references: samm2: - - V-ST-2-A + - V-ST-A-2 iso27001-2017: - 12.6.1 - 14.2.1 @@ -121,7 +121,7 @@ Test and Verification: isImplemented: false evidence: "" comments: "" - Regular tests: + Regular automated tests: uuid: 598897a2-358e-441f-984c-e12ec4f6110a risk: After pushing source code to the version control system, any delay in @@ -138,7 +138,8 @@ Test and Verification: implementation: [] references: samm2: - - I-SB-3-A + - I-SB-A-3 + - V-ST-A-3 iso27001-2017: - 14.2.3 - 14.2.8 diff --git a/src/assets/YAML/default/implementations.yaml b/src/assets/YAML/default/implementations.yaml index ff8e035..8d590ae 100755 --- a/src/assets/YAML/default/implementations.yaml +++ b/src/assets/YAML/default/implementations.yaml @@ -9,7 +9,7 @@ implementations: uuid: 86c6bdba-73c0-4c99-bbda-81b85c9fe2a4 name: Enforcement of commit signing tags: [signing] - url: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/defining-the-mergeability-of-pull-requests/managing-a-branch-protection-rule + url: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/managing-a-branch-protection-rule description: |- Usage of branch protection rules signing-of-commits: @@ -19,6 +19,12 @@ implementations: url: https://git-scm.com/book/en/v2/Git-Tools-Signing-Your-Work description: |- Signing of commits in git + chaosmonkey: + uuid: c117e79b-8223-4e55-9da5-efbf5d741c15 + name: Chaos Monkey + tags: [chaos, testing] + url: https://github.com/Netflix/chaosmonkey + description: Chaos Monkey is a resiliency tool that helps applications tolerate random instance failures. Chaos Monkey randomly terminates virtual machine instances and containers that run inside of your production environment. Exposing engineers to failures more frequently incentivizes them to build resilient services. ci-cd-tools: uuid: b4bfead3-5fb6-4dd0-ba44-5da713bd22e4 name: CI/CD tools @@ -31,7 +37,7 @@ implementations: name: API Security Maturity Model for Authorization tags: [api] url: https://curity.io/resources/learn/the-api-security-maturity-model/ - container-technologi: + container-technology: uuid: ed6b6340-6c7f-4e13-8937-f560d3f5db11 name: Container technologies and orchestration like Docker, Kubernetes tags: [] @@ -41,6 +47,11 @@ implementations: name: CWE Top 25 Most Dangerous Software Weaknesses tags: ["documentation", "threat"] url: https://cwe.mitre.org/top25/archive/2020/2020_cwe_top25.html + cwe-838: + uuid: ae97c9b0-308c-4dab-bff9-bf3330a897dc + name: CWE-838 Inappropriate Encoding for Output Context + tags: ["documentation", "cwe"] + url: https://cwe.mitre.org/data/definitions/838.html docker-content-trust: uuid: ee81f93f-8230-4cfb-a132-ae4ec61cb8e6 name: Docker Content Trust @@ -59,11 +70,16 @@ implementations: uuid: 9af7624e-0729-4eeb-b257-ebaf65f70355 name: A Point in Time Recovery for databases should be implemented. tags: [] - blue-green-deploymen: + blue-green-deployment: uuid: 4fb3d95c-07c0-4cbb-b396-5054aba751c2 name: Blue/Green Deployments tags: [] url: https://martinfowler.com/bliki/BlueGreenDeployment.html + canary-deployment: + uuid: cd49f792-a158-4b93-ac55-fd773954b217 + name: Canary release + tags: [] + url: https://martinfowler.com/bliki/CanaryRelease.html docker: uuid: cc47b2e3-6ee5-4926-af3a-d418ef91c8ba name: Docker @@ -81,15 +97,15 @@ implementations: kubernetes-admission: uuid: 2a76300f-6b1f-4a51-b925-134c36b723af name: - Kubernetes Admission Controller can whitelist registries and/or whitelist - a signing key. + Kubernetes Admission Controller can whitelist registries and/or whitelist a signing key. tags: [] url: https://medium.com/slalom-technology/build-a-kubernetes-dynamic-admission-controller-for-container-registry-whitelisting-b46fe020e22d + test-url-expects: [403] dependabot: uuid: d6292c7d-aab7-43d3-a7c6-1e443b5c1aa4 name: dependabot tags: ["auto-pr", "patching"] - url: https://dependabot.com/ + url: https://docs.github.com/en/code-security/getting-started/dependabot-quickstart-guide renovate: uuid: 8228266e-e04f-40ba-94c8-bfadc5310920 name: renovate @@ -100,9 +116,14 @@ implementations: name: Jenkins tags: [] url: https://www.jenkins.io/ + maven: + uuid: eb6de6b9-e060-4902-ae6f-604ffc386b63 + name: Maven + tags: [] + url: https://maven.apache.org/ sample-concept-1: uuid: 1a463242-b480-46f6-a912-b51ec1c1558d - name: "Sample concept: \n(1" + name: "Sample concept" tags: [] description: "Sample concept: \n(1) each container has a set lifetime and is\ @@ -125,12 +146,13 @@ implementations: uuid: be757cb3-63d6-4a63-9c4e-e10b746fd47a name: Fedora CoreOS tags: [] - url: https://getfedora.org/coreos + url: https://fedoraproject.org/coreos/ distroless-usage: uuid: a92c4f8f-a918-406a-b1e5-70acfc0477bd name: Distroless or Alpine tags: [] url: https://itnext.io/which-container-images-to-use-distroless-or-alpine-96e3dab43a22 + test-url-expects: [403] threat-modeling-play: uuid: fd0f282b-a065-4464-beed-770c604a5f52 name: Threat Modeling Playbook @@ -161,14 +183,14 @@ implementations: name: Threagile tags: [threat-modeling] url: https://github.com/Threagile/threagile - don-t-forget-evil-u: + don-t-forget-evil-user-stories: uuid: bb5b8988-021b-452a-a914-bd36887b6860 - name: "[Don't Forget EVIL U" + name: "Don't Forget EVIL User stories" tags: [] - url: https://www.owasp.org/index.php/Agile_Software_Development + url: https://medium.com/serious-scrum/evil-user-storys-story-telling-for-it-security-e4a9ec94193c + test-url-expects: [403] description: - "[Do not Forget EVIL User Stories](https://www.owasp.org/index.php/Agile_Software_Development:_Don%27t_Forget_EVIL_User_Stories)\ - \ and [Practical Security Stories and Security Tasks for Agile Development Environments](http://safecode.org/publication/SAFECode_Agile_Dev_Security0712.pdf)" + "Do not Forget _Evil_ User Stories and [Practical Security Stories and Security Tasks for Agile Development Environments](https://safecode.org/publication/SAFECode_Agile_Dev_Security0712.pdf)" libyear: uuid: 2fff917f-205e-4eab-2e0e-1fab8c04bf33 name: libyear @@ -180,26 +202,12 @@ implementations: uuid: 1fff917f-205e-4eab-ae0e-1fab8c04bf3a name: OWASP Juice Shop tags: [training] - url: https://github.com/bkimminich/juice-shop + url: https://github.com/juice-shop/juice-shop description: |- In case you do not have the budget to hire an external security expert, an option is to use the OWASP JuiceShop on a "hacking Friday" - owasp-cheatsheet-ser: + owasp-cheatsheet-series: uuid: 1c3f2f7a-5031-4687-9d69-76c5178c74e1 name: OWASP Cheatsheet Series - tags: [secure coding] - url: https://cheatsheetseries.owasp.org/ - owasp-juiceshop: - uuid: 81476121-67dd-4ba9-a67b-e78a23050c28 - name: OWASP JuiceShop - tags: [] - url: https://github.com/bkimminich/juice-shop - description: - "In case you do not have the budget to hire an external security\ - \ expert, an option\nis to use the [OWASP JuiceShop](https://github.com/bkimminich/juice-shop)\ - \ on a \"hacking Friday\"" - https-cheatsheetse: - uuid: 99080ac7-60cd-46af-93a1-a53a33597cba - name: https://cheatsheetseries.owasp.org/ tags: [training, secure coding] url: https://cheatsheetseries.owasp.org/ owasp-security-champ: @@ -251,17 +259,17 @@ implementations: uuid: 7bf90650-a53a-4581-a214-1afd5de3a059 name: OWASP MASVS tags: [] - url: https://github.com/OWASP/owasp-masvs - cis-kubernetes-bench: + url: https://github.com/OWASP/masvs + cis-kubernetes-benchmark: uuid: edaec98d-dac7-4dfd-8ab3-42c471d5b9ff - name: CIS Kubernetes Bench for Security + name: CIS Kubernetes Benchmark for Security tags: [] - url: https://www.cisecurity.org/cis-benchmarks/ - cis-docker-bench-for: + url: https://www.cisecurity.org/benchmark/kubernetes + cis-docker-benchmark: uuid: 4dd23c4a-5a7e-4917-82cf-d00e0f04482f - name: CIS Docker Bench for Security + name: CIS Docker Benchmark for Security tags: [] - url: https://www.cisecurity.org/cis-benchmarks/ + url: https://www.cisecurity.org/benchmark/docker for-example-for-cont: uuid: f4d7c796-8574-4a88-ab00-98d245a115ef name: For example for Cont @@ -277,18 +285,18 @@ implementations: url: https://attack.mitre.org/matrices/enterprise/cloud/ description: |- Attack matrix for cloud - attack-matrix-contai: + attack-matrix-containers: uuid: 59881520-4c69-4922-a44e-99044a77de2b name: Attack Matrix Containers tags: [mitre] - url: https://attack.mitre.org/matrices/enterprise/cloud/ + url: https://attack.mitre.org/matrices/enterprise/containers/ description: |- Attack matrix for containers attack-matrix-kubern: uuid: 9fbc47ad-82bc-46d1-bba9-66815ab79935 name: Attack Matrix Kubernetes tags: [mitre] - url: https://www.microsoft.com/security/blog/2020/04/02/attack-matrix-kubernetes/ + url: https://www.microsoft.com/en-US/security/blog/2020/04/02/attack-matrix-kubernetes/ description: |- Attack matrix for kubernetes istio: @@ -358,14 +366,9 @@ implementations: uuid: cc55cba1-ea0a-466e-99c5-337c9da2b00e name: Plugins tags: [] - smartcard: - uuid: e76a395a-8d6a-4e25-a175-6cf25409b755 - name: Smartcard - tags: [] - url: https://d3fend.mitre.org/technique/d3f:Multi-factorAuthentication/ yubikey: uuid: d5981117-9bc2-45ed-b4a4-383135dc13d8 - name: YubiKey + name: YubiKey - Smartcard tags: [] url: https://d3fend.mitre.org/technique/d3f:Multi-factorAuthentication/ sms: @@ -381,12 +384,12 @@ implementations: uuid: 41fda224-2980-443c-bfd4-0a1d4b520cb9 name: HTTP-Basic Authentication tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:WebAuthentication/ + url: https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/Authentication vpn: uuid: e506f60b-747b-44b1-8fe8-f67ccd8f290e name: VPN tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:VPN/ + url: https://d3fend.mitre.org/dao/artifact/d3f:VPNServer/ for-applications-ch: uuid: d7fb1f5a-05e3-49f7-ae67-00bfb8f8410c name: "For applications: Check default encoding" @@ -404,7 +407,7 @@ implementations: uuid: ba6bd46c-2069-4f4d-b26c-7334a7553339 name: authentication tags: [] - url: https://d3fend.mitre.org/dao/artifact/d3f:Authentication/ + url: https://d3fend.mitre.org/dao/artifact/d3f:AuthenticationServer/ rsyslog: uuid: 79f88310-d63e-471d-8e63-8c77f2281b66 name: rsyslog @@ -413,7 +416,7 @@ implementations: logstash: uuid: 7a8fad2e-d642-4972-8501-74591b23feab name: logstash - url: https://www.elastic.co/guide/en/logstash/current/getting-started-with-logstash.html + url: https://www.elastic.co/docs/reference/logstash/getting-started-with-logstash tags: [tool, logging] fluentd: uuid: f5da3a20-ab64-4ecf-b4e1-660c80036e45 @@ -430,17 +433,21 @@ implementations: name: OWASP Logging CheatSheet url: https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html tags: [logging, documentation] + owasp-dom-xss-cheats: + uuid: 2d61e48f-bade-4332-a383-adc50c29673a + name: OWASP DOM based XSS Prevention CheatSheet + url: https://cheatsheetseries.owasp.org/cheatsheets/DOM_based_XSS_Prevention_Cheat_Sheet.html + tags: [] + owasp-parameterization-cheats: + uuid: d880fa0f-9dbb-454e-a003-d844fad31ab4 + name: OWASP Parameterization CheatSheet + url: https://cheatsheetseries.owasp.org/cheatsheets/Query_Parameterization_Cheat_Sheet.html + tags: [] elk-stack: uuid: 38fe9d00-df8b-44b6-910d-ca0f02b5c5d3 name: ELK-Stack tags: [] - url: https://www.elastic.co/elk-stack - https-ht-transpare: - uuid: 84ef86ea-ada4-4e10-ae4f-a5bb77dcae5d - name: https://ht.transpare - tags: [] - url: https://ht.transparencytoolkit.org/FileServer/FileServer/OLD - description: https://ht.transparencytoolkit.org/FileServer/FileServer/OLD%20Fileserver/books/SICUREZZA/Addison.Wesley.Security.Metrics.Mar.2007.pdf + url: https://www.elastic.co/elastic-stack/ prometheus: uuid: ddf221df-3517-42e4-b23d-c1d9a162744c name: Prometheus @@ -450,16 +457,11 @@ implementations: uuid: 73f6a52c-4fc2-45dc-991b-d5911b6c1ef8 name: collected tags: [] - httpunit: - uuid: 3bd40005-f180-4b95-907d-ec5b58ac1f20 - name: HttpUnit - tags: [] - url: http://httpunit.sourceforge.net/ junit: uuid: cc2eec82-f3a7-4ae5-9ccb-3d75352b2e4d name: JUnit tags: [unittest] - url: https://junit.org/junit5/ + url: https://junit.org/ karma: uuid: fd56720a-ad4b-487c-b4c3-897a688672c4 name: Karma @@ -479,10 +481,13 @@ implementations: url: https://github.com/faloker/purify/ description: | The goal of Purify to be an easy-in-use and efficient tool to simplify a workflow of managing vulnerabilities delivered from various (even custom) tools. - see-other-actions-e: - uuid: 44c08670-78dc-47ee-a4c1-2503ca6b6cf8 - name: See other actions, e.g. "Treatment of defects with severity high". - tags: [] + SecObserve: + uuid: d899488c-5799-4df1-a14c-3bb92fec3ac3 + name: SecObserve + tags: [vulnerability management system] + url: https://github.com/SecObserve/SecObserve + description: | + SecObserve is an open source vulnerability and license management system for software development teams and cloud environments. It supports a variety of open source vulnerability scanners and integrates into CI/CD pipelines. sast: uuid: aaad322e-806e-4c51-b78d-6551f7dc376a name: SAST @@ -500,11 +505,6 @@ implementations: "At DAST (Dynamic Application Security Testing): vulnerabilities are classified and can be assigned to server-side and client-side teams." url: https://d3fend.mitre.org/dao/artifact/d3f:DynamicAnalysisTool/ - owasp-defect-dojo: - uuid: bb9d0f2d-f8bc-46b5-bbc7-7dbcf927191c - name: OWASP Defect Dojo - tags: [] - url: https://github.com/DefectDojo/django-DefectDojo owasp-dependency-che: uuid: 06334caf-8be6-487a-96b1-d41c7ed5f207 name: OWASP Dependency Check @@ -518,7 +518,7 @@ implementations: uuid: 7063cf8c-cd98-480f-8ef7-11cf241d2366 name: OWASP Code Pulse tags: [] - url: https://www.owasp.org/index.php/OWASP_Code_Pulse + url: https://owasp.org/www-project-code-pulse/ ajax-spider: uuid: 6583fd5f-4314-4b39-9265-de72f861c8cb name: Ajax Spider @@ -573,7 +573,7 @@ implementations: uuid: b99c9d52-dd1a-4aef-8699-65173cf978ce name: HTC Hydra tags: [password] - url: https://www.htc-cs.com/en/products/htc-hydra/ + url: https://github.com/vanhauser-thc/thc-hydra netassert: uuid: fffa6fb9-1fae-4852-88dc-c7086961330c name: netassert @@ -588,7 +588,7 @@ implementations: uuid: f085295e-46a3-4c8d-bbc3-1ac6b9dfcf2a name: OWASP Amass tags: [] - url: https://github.com/OWASP/Amass + url: https://github.com/owasp-amass/amass k8spurger: uuid: 8fea20ad-e332-4aa8-b1f1-aa9deb635dc1 name: K8sPurger @@ -630,6 +630,7 @@ implementations: name: npm audit tags: [] url: https://docs.npmjs.com/cli/audit + test-url-expects: [301] sigmahq: uuid: 1adf1ac0-8572-407b-a358-3976d9a225e2 name: SigmaHQ @@ -641,7 +642,7 @@ implementations: tags: [] url: https://github.com/wagoodman/dive clusterscanner: - url: https://github.com/SDA-SE/clusterscanner + url: https://github.com/SDA-SE/cluster-image-scanner uuid: 3c9ac78c-0fd4-43f4-8211-c915f9ef685f name: ClusterScanner tags: @@ -699,17 +700,27 @@ implementations: uuid: d90fefc9-4e5d-420f-ac87-eeb165bf0ee6 name: truffleHog tags: [] - url: https://github.com/dxa4481/truffleHog + url: https://github.com/trufflesecurity/trufflehog go-pillage-registrie: uuid: 382873e2-8604-4410-ae5e-b0f5ccdee835 name: go-pillage-registries tags: [] url: https://github.com/nccgroup/go-pillage-registries - https-github-com-a: + trivy: uuid: 7f500e95-2110-44c4-a1f8-cd7ef5d9eb6b - name: https://github.com/aquasecurity/trivy + name: Trivy tags: [] url: https://github.com/aquasecurity/trivy + syft: + uuid: 7543a6f2-3850-47a9-bb2f-0987e2af6f6a + name: Syft + tags: [sbom, dependency] + url: https://github.com/anchore/syft + grype: + uuid: 7970af6e-a7d3-4359-a6ea-301d26b16329 + name: Grype + tags: [sbom, dependency, vulnerability] + url: https://github.com/anchore/grype registries-like-quay: uuid: 8737c6c0-4e90-400a-bf9a-f8e399913b57 name: Registries like quay @@ -726,38 +737,40 @@ implementations: threat-matrix-for-storage: uuid: 1c56dbea-e067-44e2-8d3b-0a1205a70617 name: Threat Matrix for Storage - url: https://www.microsoft.com/security/blog/2021/04/08/threat-matrix-for-storage/ + url: https://www.microsoft.com/en-US/security/blog/2021/04/08/threat-matrix-for-storage/ tags: [documentation, storage, cluster, kubernetes] defend-the-core-kubernetes: uuid: b7a92886-aec9-4bf4-94c4-07cc191a97af name: Defend the core kubernetes security at every layer - url: https://thenewstack.io/defend-the-core-kubernetes-security-at-every-layer/ + url: https://thenewstack.io/defend-the-core-kubernetes-security-at-every-layer/ tags: [documentation, cluster, kubernetes] business-friendly-vulnerability-metrics: uuid: 3b99799c-e875-4cc2-aad7-5ce4564a1cde name: Business friendly vulnerability management metrics url: https://medium.com/uber-security-privacy/business-friendly-vulnerability-management-metrics-cfd702fd7705 + test-url-expects: [403] tags: [documentation, vulnerability, vulnerability management system] kubescape: uuid: 893d9f37-2142-4490-996c-e43b55064d3d name: kubescape - url: https://github.com/armosec/kubescape + url: https://github.com/kubescape/kubescape tags: [kubernetes, vulnerability, misconfiguration] description: _Testing if Kubernetes is deployed securely as defined in Kubernetes Hardening Guidance by to NSA and CISA_ azuredevops: uuid: b1b88bc5-5a22-4888-a27b-acce3d9fe29a name: Improve code quality with branch policies - url: https://docs.microsoft.com/en-us/azure/devops/repos/git/branch-policies?view=azure-devops + url: https://learn.microsoft.com/en-us/azure/devops/repos/git/branch-policies?view=azure-devops tags: [source-code-protection, scm] github-policies: uuid: 99211481-de9c-4358-880e-628366416a27 name: About protected branches - url: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/defining-the-mergeability-of-pull-requests/about-protected-branches + url: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/about-protected-branches tags: [source-code-protection, scm] - sonarqube: + sonarqube-lint: uuid: aa5ded61-5380-4da6-9474-afc36a397682 name: In-Depth Linting of Your TypeScript While Coding - url: https://blog.sonarsource.com/in-depth-linting-of-your-typescript-while-coding + url: https://medium.com/@elenavilchik/in-depth-linting-of-your-typescript-while-coding-1d084affbf0 + test-url-expects: [403] tags: [ide, linting] stylecop: uuid: 0b7ec352-0c36-4de1-8912-617fc6c608fe @@ -768,71 +781,37 @@ implementations: uuid: 5b52a841-c281-45fd-b68f-0a93aa6fa398 name: Fortify Extension for Visual Studio Code url: https://marketplace.visualstudio.com/items?itemName=fortifyvsts.fortify-extension-for-vs-code + test-url-expects: [404] tags: [ide, sast] appscan-vscode-extension: uuid: 3f5a493d-12d0-4468-b9fa-c3e4eae89ffb name: HCL AppScan CodeSweep url: https://marketplace.visualstudio.com/items?itemName=HCLTechnologies.hclappscancodesweep + test-url-expects: [404] tags: [ide, sast] checkmarx-vscode-extension: uuid: cf1213fd-8bfa-4a97-bf8b-937c93f31005 name: Setting Up the Visual Studio Code Extension Plugin url: https://checkmarx.atlassian.net/wiki/spaces/SD/pages/1759216424/Setting+Up+the+Visual+Studio+Code+Extension+Plugin + test-url-expects: [302] tags: [ide, sast] pre-commit-microsoft: uuid: 58ac9dea-b6c7-4698-904e-df89a9451c82 name: DevSecOps control Pre-commit - url: https://docs.microsoft.com/en-us/azure/cloud-adoption-framework/secure/devsecops-controls#plan-and-develop + url: https://learn.microsoft.com/en-us/security/zero-trust/develop/secure-devops-environments-zero-trust tags: [pre-commit] pre-commit-synopsis: uuid: 8da8d115-0f4e-40f0-a3ce-484a49e845fb name: Building your DevSecOps pipeline 5 essential activities - url: https://www.synopsys.com/blogs/software-security/devsecops-pipeline-checklist/ + url: https://www.blackduck.com/blog/devsecops-pipeline-checklist/ tags: [pre-commit] dependencyTrack: uuid: 500399bd-7dfc-47fd-99d8-b55cefb760a9 - name: Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track takes a unique and highly beneficial approach by leveraging the capabilities of Software Bill of Materials (SBOM). - url: https://github.com/DependencyTrack/dependency-track - tags: [sca, inventory, OpenSource, "Supply Chain", vulnerability] - juice-shop: - uuid: c021aa72-c71c-43e4-9573-717b74d6c19d - name: OWASP Juice Shop - tags: [training] - url: https://github.com/bkimminich/juice-shop - description: |- - In case you do not have the budget to hire an external security expert, an option is to use the OWASP JuiceShop on a "hacking Friday" - dvwa: - uuid: e1282ab3-7ffd-4ee5-a564-8e9af070979d - name: Damn Vulnerable Web Application - tags: [training] - description: |- - Simple Application with intended vulnerabilities. HTML based. - loggingCheatSheet: - uuid: 032ca7cc-67dc-46bc-9702-3580a3c9d1a9 - name: OWASP Logging CheatSheet - url: https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html - tags: [logging, documentation] - zap: - uuid: 84a2a907-a6fb-4ceb-8e21-f65c0d633445 - name: OWASP Zap - tags: [vulnerability, scanner] - url: https://github.com/zaproxy/zaproxy + name: Dependency-Track description: | - The OWASP Zed Attack Proxy (ZAP) is one of the world's most popular free security tools and is actively maintained by a dedicated international team of ... - secureCodeBox: - uuid: dc0995a5-ff13-4cfc-b95f-07bf8a30b6ab - name: OWASP secureCodeBox - tags: [vulnerability, scanner-orchestration] - url: https://github.com/secureCodeBox/secureCodeBox - description: | - secureCodeBox is a kubernetes based, modularized toolchain for continuous security scans of your software project. Its goal is to orchestrate and easily automate a bunch of security-testing tools out of the box. - K8sPurger: - uuid: 7a019f5e-a77d-4f4a-89a6-d5107054a2cb - name: K8sPurger - tags: [vulnerability, scanner, dast, infrastructure] - url: https://github.com/yogeshkk/K8sPurger - description: | - Hunt Unused Resources In Kubernetes. + Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track takes a unique and highly beneficial approach by leveraging the capabilities of Software Bill of Materials (SBOM). + url: https://github.com/DependencyTrack/dependency-track + tags: [sca, inventory, OpenSource, "Supply Chain", vulnerability, inventory] hashicorp-vault: uuid: e3a2ffc8-313f-437e-9663-b24591568209 name: Hashicorp Vault @@ -860,7 +839,7 @@ implementations: uuid: f011de6e-ab7c-4ec7-af55-03427271ab32 name: Coverage.py tags: [testing, coverage] - url: https://github.com/nedbat/coveragepy + url: https://github.com/coveragepy/coveragepy description: | Code coverage measurement for Python github-dependabot: @@ -917,6 +896,7 @@ implementations: name: terraform tags: [IaC] url: https://www.terraform.io/ + test-url-expects: [308] description: | Terraform enables infrastructure automation for provisioning, compliance, and management of any cloud, datacenter, and service. packj: @@ -926,10 +906,74 @@ implementations: url: https://github.com/ossillate-inc/packj description: | Packj is a tool to detect software supply chain attacks. It can detect malicious, vulnerable, abandoned, typo-squatting, and other "risky" packages from popular open-source package registries, such as NPM, RubyGems, and PyPI. - apiMyth: + api-myths: uuid: 6150533e-58ca-4b52-a9b2-6226545d9ea0 name: Top 5 API Security Myths That Are Crushing Your Business tags: [documentation, waf] url: https://thehackernews.com/2022/11/top-5-api-security-myths-that-are.html description: | There are several myths and misconceptions about API security. These myths about securing APIs are crushing your business + backstage: + uuid: 2210e02b-a856-4da4-8732-5acd77e20fca + name: Backstage + tags: [documentation, inventory] + url: https://github.com/backstage/backstage + description: | + Backstage is an open-source platform designed to create developer portals. At its core is a centralized software catalog that brings organization to your microservices and infrastructure. + image-metadata-collector: + uuid: 879bd03f-8de1-43d6-b492-d974181bfa6c + name: Image Metadata Collector + tags: [documentation, inventory, kubernetes] + url: https://github.com/SDA-SE/image-metadata-collector/ + description: | + Collects namespaces and namespaces including responsible team and contact info through annotations/labels from Kubernetes clusters. Results are available in JSON and can be uploaded to S3, github and an API. + jira: + uuid: 889444eb-de68-4367-bada-a66f8cb9733a + name: Jira + tags: [documentation, issue, proprietary] + url: https://jira.atlassian.com/ + description: |- + Jira is a bug tracking and project management tool developed by Atlassian, used by development teams for tracking issues, planning sprints, and managing software releases. It offers features for creating and managing tasks, assigning them to team members, and monitoring progress through customizable workflows and dashboards. + epss: + uuid: e39afc58-8195-4600-92c6-11922e3a141b + name: Exploit Prediction Scoring System + tags: [vulnerability] + url: https://www.first.org/epss/ + description: |- + Estimates the likelihood that a software vulnerability will be exploited. + cisa-kev: + uuid: aa507341-9531-42cd-95cf-d7b51af47086 + name: Known Exploited Vulnerabilities + tags: [vulnerability] + url: https://www.cisa.gov/known-exploited-vulnerabilities-catalog + description: |- + A catalog of vulnerabilities that have been exploited. + owasp-secure-headers: + uuid: 370b7f35-4da7-4833-89d6-7266b82ea07e + name: OWASP Secure Headers Project + tags: [header, documentation] + url: https://owasp.org/www-project-secure-headers/ + description: |- + The OWASP Secure Headers Project (also called OSHP) describes HTTP response headers that your application can use + to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers + from running into easily preventable vulnerabilities. The OWASP Secure Headers Project intends to raise awareness + and use of these headers. + citrusframework: + uuid: 000b55f9-e6fd-4649-8290-27876a0409e2 + name: Citrus Fresh Integration Testing + tags: [framework, testing] + url: https://citrusframework.org/ + description: |- + Integration Test framework with focus on messaging applications and Microservices. + signing-of-containers: + uuid: 9368abfb-cf37-477a-9091-a804d2de9148 + name: Signing of containers + tags: [signing, container, build] + url: https://www.aquasec.com/cloud-native-academy/supply-chain-security/container-image-signing/ + description: Container technology automatically creates a hash for images, which can be used. + immutable-images: + uuid: 638b3691-c9a5-45fa-9ba8-e40aeea32766 + name: Immutable images + tags: [deployment, container, build] + url: https://kubernetes.io/blog/2022/09/29/enforce-immutability-using-cel/#immutablility-after-first-modification + description: Immutable images are an other way, e.g. by using a registry, which doesn't allow overriding of images. diff --git a/src/assets/YAML/generated/README.md b/src/assets/YAML/generated/README.md deleted file mode 100644 index d8e2c1d..0000000 --- a/src/assets/YAML/generated/README.md +++ /dev/null @@ -1 +0,0 @@ -In this folder, the generated.yaml will be placed diff --git a/src/assets/YAML/meta.yaml b/src/assets/YAML/meta.yaml deleted file mode 100644 index e1b1b7e..0000000 --- a/src/assets/YAML/meta.yaml +++ /dev/null @@ -1,47 +0,0 @@ ---- -# -# Various strings and messages -# -strings: - en: &en - references: - samm2: - label: OWASP SAMM VERSION 2 - description: |- - Software Assurance Maturity Model - The Software Assurance Maturity Model (SAMM) is an open framework to help organizations formulate - and implement a strategy for software security that is tailored - to the specific risks facing the organization. - https://owaspsamm.org/blog/2020/01/31/samm2-release/ - iso27001-2017: - label: ISO 27001:2017 - description: |- - ISO 27001:2017 - iso27001-2022: - label: ISO 27001:2022 - description: |- - ISO 27001:2022 - labels: ['Very Low', 'Low', 'Medium', 'High', 'Very High'] - KnowledgeLabels: - [ - 'Very Low (one discipline)', - 'Low (one discipline)', - 'Medium (two disciplines)', - 'High (two disciplines)', - 'Very High (three or more disciplines)', - ] - hardness: ['Very soft', 'Soft', 'Medium', 'High', 'Very high'] - maturity_levels: - [ - 'Level 1: Basic understanding of security practices', - 'Level 2: Adoption of basic security practices', - 'Level 3: High adoption of security practices', - 'Level 4: Very high adoption of security practices', - 'Level 5: Advanced deployment of security practices at scale', - ] -# Default team -teams: ['Default', 'B', 'C'] -teamGroups: - GroupA: ['Default', 'B'] - GroupB: ['B', 'C'] - GroupC: ['Default', 'C'] diff --git a/src/assets/YAML/schemas/dsomm-schema-implementation.json b/src/assets/YAML/schemas/dsomm-schema-implementation.json index d94a192..b842e16 100644 --- a/src/assets/YAML/schemas/dsomm-schema-implementation.json +++ b/src/assets/YAML/schemas/dsomm-schema-implementation.json @@ -135,11 +135,17 @@ "iso27001-2022" ] }, - "isImplemented": { - "type": "boolean" + "teamsImplemented": { + "type": "array", + "items": { + "type": "object" + } }, - "evidence": { - "type": "string" + "teamsEvidence": { + "type": "array", + "items": { + "type": "object" + } }, "comments": { "type": "string" @@ -155,8 +161,6 @@ "level", "implementation", "references", - "isImplemented", - "evidence", "comments" ], "additionalProperties": false diff --git a/src/assets/YAML/schemas/dsomm-schema-test-and-verification.json b/src/assets/YAML/schemas/dsomm-schema-test-and-verification.json index 0a992f3..2a619bc 100644 --- a/src/assets/YAML/schemas/dsomm-schema-test-and-verification.json +++ b/src/assets/YAML/schemas/dsomm-schema-test-and-verification.json @@ -154,10 +154,7 @@ "usefulness", "level", "implementation", - "references", - "isImplemented", - "evidence", - "comments" + "references" ], "additionalProperties": false } @@ -169,4 +166,4 @@ "required": [ "Test and Verification" ] -} \ No newline at end of file +} diff --git a/src/assets/YAML/teams.yaml b/src/assets/YAML/teams.yaml deleted file mode 100644 index cbdecfa..0000000 --- a/src/assets/YAML/teams.yaml +++ /dev/null @@ -1,9 +0,0 @@ ---- -# -# Teams -# -teams: ['A', 'B', 'C'] -teamGroups: - AB: ['A', 'B'] - BC: ['B', 'C'] - AC: ['A', 'C'] diff --git a/yaml-generation/bib.php b/yaml-generation/bib.php index 53e0ef7..106d375 100644 --- a/yaml-generation/bib.php +++ b/yaml-generation/bib.php @@ -14,11 +14,16 @@ ini_set('display_startup_errors', 1); error_reporting(E_ALL); define('NUMBER_LEVELS', 4); -if (isset($_ENV["IS_IMPLEMENTED_WHEN_EVIDENCE"])) { - $enforce=boolval($_ENV["IS_IMPLEMENTED_WHEN_EVIDENCE"]); - define('IS_IMPLEMENTED_WHEN_EVIDENCE', $enforce); -}else { - define('IS_IMPLEMENTED_WHEN_EVIDENCE', false); +defineConstFromEnv("TEST_REFERENCED_URLS"); + + +function defineConstFromEnv($envVar) { + if (isset($_ENV[$envVar])) { + $value = boolval($_ENV[$envVar]); + define($envVar, $value); + }else { + define($envVar, false); + } } /** diff --git a/yaml-generation/functions.php b/yaml-generation/functions.php index d98a95b..422047a 100644 --- a/yaml-generation/functions.php +++ b/yaml-generation/functions.php @@ -41,9 +41,52 @@ function readYaml($file) { } } + + if (isset($ret['_yaml_references'])) { + foreach ($ret['_yaml_references'] as $include) { + if (preg_match('/^include\((\w+),\s*(.+)\)$/', $include, $matches)) { + $team = $matches[1]; + $baseDir = dirname($file); + + $includeFile = $baseDir . DIRECTORY_SEPARATOR . $matches[2]; + echo "In file $file, including $includeFile for team $team\n"; + $includedContent = includeYamlAndSetTeamImplemented($includeFile, $team); + $ret = array_merge_recursive_ex($ret, $includedContent); + } + } + unset($ret['_yaml_references']); + } + return $ret; } +function includeYamlAndSetTeamImplemented($filename, $team) { + echo "File to include $filename"; + $content = yaml_parse_file($filename); + if ($content === false) { + echo "Error parsing YAML file: $filename\n"; + return array(); + } + // Add teamsImplemented for each activity + foreach ($content as $dimension => $subdimensions) { + foreach ($subdimensions as $subdimension => $elements) { + foreach ($elements as $activityName => $activity) { + if (is_array($elements) && (isset($activity['teamsEvidence']) || isset($activity['teamsImplemented']))) { + if (!isset($activity['teamsImplemented'])) { + echo "# setting teamsImplemented first time for team $team"; + $content[$dimension][$subdimension][$activityName]['teamsImplemented'] = array(); + } + if(array_key_exists('teamsEvidence', $activity)) { + echo "# adding team to teamsImplemented for team $team"; + $content[$dimension][$subdimension][$activityName]['teamsImplemented'][$team] = true ; + } + } + } + } + } + return $content; + +} /** * Get dimensions from yaml file. @@ -93,6 +136,21 @@ function getDimensions($filename = "data/generated/dimensions.yaml") { return $dimensions; } +/** + * Sort activities by their 'level' attribute within each subdimension. + * The uasort() is stable, i.e. it will retain the original order, within each level. + */ +function sortActivitiesByLevel($dimensions) { + foreach ($dimensions as $dimension => $subdimensions) { + foreach ($subdimensions as $subdimension => $elements) { + uasort($elements, function($a, $b) { + return ($a['level'] ?? 0) <=> ($b['level'] ?? 0); + }); + $dimensions[$dimension][$subdimension] = $elements; + } + } + return $dimensions; +} /** @@ -146,6 +204,57 @@ function getReferenceLabel($reference_id) { } +function getActivityNameByUuid($uuid, $dimensionsAggregated) { + foreach ($dimensionsAggregated as $dimension => $subdimensions) { + ksort($subdimensions); + foreach ($subdimensions as $subdimension => $elements) { + if (sizeof($elements) == 0) { + echo "unsetting $subdimension\n"; + unset($dimensionsAggregated[$dimension][$subdimension]); + continue; + } + if (substr($subdimension, 0, 1) == "_") { + continue; + } + + foreach ($elements as $activityName => $activity) { + if($activity["uuid"] == $uuid) { + return $activityName; + } + } + } + } + return null; +} + + +function getUuidByActivityName($activityName, $dimensionsAggregated) { + $activity = getActivityByActivityName($activityName, $dimensionsAggregated); + if ($activity) { + return $activity["uuid"]; + } else { + return null; + } +} + + +function getActivityByActivityName($activityName, $dimensionsAggregated) { + foreach ($dimensionsAggregated as $dimension => $subdimensions) { + ksort($subdimensions); + foreach ($subdimensions as $subdimension => $elements) { + if (substr($subdimension, 0, 1) == "_") { + continue; + } + + if (array_key_exists($activityName, $elements)) { + return $elements[$activityName]; + } + } + } + return null; +} + + /** * * @param unknown $headings @@ -225,6 +334,16 @@ function getReferences($references) { } +/** + * Push item to array at key, creating array if needed. + */ +function array_push_item_to(array &$array, $key, $value) { + if (!isset($array[$key])) { + $array[$key] = []; + } + array_push($array[$key], $value); +} + // TODO create testcases @@ -251,4 +370,4 @@ function test_readYaml() { } -?> \ No newline at end of file +?> diff --git a/yaml-generation/generateDimensions.bash b/yaml-generation/generateDimensions.bash index 68a773e..4d19d13 100755 --- a/yaml-generation/generateDimensions.bash +++ b/yaml-generation/generateDimensions.bash @@ -1,13 +1,29 @@ #!/bin/bash -docker run -e IS_IMPLEMENTED_WHEN_EVIDENCE=true -ti --rm --volume ${PWD}/../:/app wurstbrot/dsomm-yaml-generation bash -c 'cd /app/ && php yaml-generation/generateDimensions.php' - -#docker run --rm --interactive --tty --volume $PWD/:/app --user $(id -u):$(id -g) composer install \ -# --ignore-platform-reqs \ -# --no-interaction \ -# --no-plugins \ -# --no-scripts \ -# --prefer-dist -# -#cd .. -#docker run --rm --volume $PWD/:/app php:apache-buster bash -c 'apt-get update && apt-get -y dist-upgrade && apt-get -y install apt-utils libyaml-dev wget && pecl channel-update pecl.php.net && pecl install yaml && docker-php-ext-enable yaml && cd /app/ && php yaml-generation/generateDimensions.php' \ No newline at end of file +# Usage: +# ./generateDimensions.bash Generate model.yaml +# ./generateDimensions.bash --test-urls Test URLs in implementations.yaml +# ./generateDimensions.bash --start-dsomm Run local DSOMM with generated model.yaml + +cd "$(dirname "$0")"/.. + +# Use: docker | podman +if [ -z "${DOCKER_CMD}" ]; then + DOCKER_CMD=docker +fi + +echo Installing composer dependencies... +MSYS_NO_PATHCONV=1 $DOCKER_CMD run -ti --rm --volume "${PWD}:/app" wurstbrot/dsomm-yaml-generation bash -c 'cd /app/yaml-generation && composer install --no-interaction --no-plugins --no-scripts --prefer-dist' + +if [ "$1" = "--start-dsomm" ]; then + echo "Starting local DSOMM application..." + MSYS_NO_PATHCONV=1 $DOCKER_CMD run -ti --rm --volume "${PWD}/generated/model.yaml:/srv/assets/YAML/default/model.yaml" -p 8080:8080 wurstbrot/dsomm + +elif [ "$1" = "--test-urls" ]; then + echo "Test URLs in implementations.yaml..." + MSYS_NO_PATHCONV=1 $DOCKER_CMD run -e TEST_REFERENCED_URLS=true -ti --rm --volume "${PWD}:/app" wurstbrot/dsomm-yaml-generation bash -c 'cd /app/ && php yaml-generation/generateDimensions.php' | tee url-test-results.txt + +else + echo "Generating model.yaml..." + MSYS_NO_PATHCONV=1 $DOCKER_CMD run -e USERNAME=${USER:-$USERNAME} -ti --rm --volume "${PWD}:/app" wurstbrot/dsomm-yaml-generation bash -c 'cd /app/ && php yaml-generation/generateDimensions.php' +fi diff --git a/yaml-generation/generateDimensions.bat b/yaml-generation/generateDimensions.bat new file mode 100644 index 0000000..9ea6b72 --- /dev/null +++ b/yaml-generation/generateDimensions.bat @@ -0,0 +1,33 @@ +@echo off + +REM Usage: +REM ./generateDimensions.bash Generate model.yaml +REM ./generateDimensions.bash --test-urls Test URLs in implementations.yaml +REM ./generateDimensions.bash --start-dsomm Run local DSOMM with generated model.yaml + +setlocal +REM Change working directory to the project root +cd %~dp0\.. + +REM Use: docker | podman +if "%DOCKER_CMD%"=="" ( + set DOCKER_CMD=docker +) + +echo Installing composer dependencies... +%DOCKER_CMD% run -ti --rm --volume "%CD%:/app" wurstbrot/dsomm-yaml-generation bash -c "cd /app/yaml-generation && composer install --no-interaction --no-plugins --no-scripts --prefer-dist" + +if "%~1"=="--start-dsomm" ( + echo Start local DSOMM application... + %DOCKER_CMD% run -ti --rm --volume "%CD%/generated/model.yaml:/srv/assets/YAML/default/model.yaml" -p 8080:8080 wurstbrot/dsomm + +) else if "%~1"=="--test-urls" ( + echo Test URLs in implementations.yaml... + %DOCKER_CMD% run -e TEST_REFERENCED_URLS=true -ti --rm --volume "%CD%:/app" wurstbrot/dsomm-yaml-generation bash -c "cd /app/ && php yaml-generation/generateDimensions.php" | tee url-test-results.txt + +) else ( + echo Generate model.yaml... + %DOCKER_CMD% run -e USERNAME=%USERNAME% -ti --rm --volume "%CD%:/app" wurstbrot/dsomm-yaml-generation bash -c "cd /app/ && php yaml-generation/generateDimensions.php" + +) + diff --git a/yaml-generation/generateDimensions.php b/yaml-generation/generateDimensions.php index 6cf6908..5a504d7 100644 --- a/yaml-generation/generateDimensions.php +++ b/yaml-generation/generateDimensions.php @@ -2,38 +2,40 @@ require_once "functions.php"; -$metadata = readYaml("src/assets/YAML/meta.yaml"); -$teams = $metadata["teams"]; -if(sizeof($teams) == 0) { - echo "Warning: No teams defined"; -} -$teamsImplemented = array(); -foreach($teams as $team) { - $teamsImplemented[$team] = false; -} - +$errorMsg = array(); +$targetFolder = "generated"; +$inputFolder = "src/assets/YAML"; +$implementationReferenceFile = "$inputFolder/default/implementations.yaml"; +if (getenv('DSOMM_VERSION')) { // version comes as an arg to Dockerfile + $publisher = 'https://github.com/' . getenv('GITHUB_REPOSITORY'); +} else { + $publisher = getenv('USERNAME'); +} -$files = glob("src/assets/YAML/default/*/*.yaml"); -$dimensions=array(); +$files = glob("$inputFolder/default/*/*.yaml"); +$dimensions = array(); foreach ($files as $filename) { - //echo "Found $filename"; + echo "Reading $filename\n"; if (preg_match("/_meta.yaml/", $filename)) continue; + $dimension = getDimensions($filename); if (array_key_exists("_yaml_references", $dimension)) { unset($dimension['_yaml_references']); } $dimensions = array_merge_recursive($dimensions, $dimension); } +$dimensions = sortActivitiesByLevel($dimensions); -$files = glob("src/assets/YAML/custom/*/*.yaml"); -$dimensionsCustom=array(); -$dimensionsAggregated=array(); +$files = glob("$inputFolder/custom/*/*.yaml"); +$dimensionsCustom = array(); +$dimensionsAggregated = array(); foreach ($files as $filename) { - //echo "Found $filename"; + echo "Reading custom $filename\n"; $dimensionCustom = getDimensions($filename); - $dimensionsCustom = array_merge_recursive($dimensionsCustom, $dimensionCustom); + $dimensionsCustom = array_merge_recursive_ex($dimensionsCustom, $dimensionCustom); } + if (sizeof($files) > 0) { $dimensions = array_merge_recursive_ex($dimensions, $dimensionsCustom); foreach (getActions($dimensions) as list($dimension, $subdimension, $activities)) { @@ -46,16 +48,18 @@ } } } else { - $dimensionsAggregated=$dimensions; + $dimensionsAggregated = $dimensions; } +$dependencies = array(); +$activityIndex = array(); foreach ($dimensionsAggregated as $dimension => $subdimensions) { ksort($subdimensions); foreach ($subdimensions as $subdimension => $elements) { - if(sizeof($elements) == 0) { + if (sizeof($elements) == 0) { echo "unsetting $subdimension\n"; unset($dimensionsAggregated[$dimension][$subdimension]); - continue; + continue; } if (substr($subdimension, 0, 1) == "_") { continue; @@ -63,53 +67,290 @@ foreach ($elements as $activityName => $activity) { if (!array_key_exists("level", $activity)) { - echo "'$activityName' is not complete!"; - echo "
";
-                var_dump($activity);
-                echo "
"; - exit; + array_push($errorMsg,"Missing 'level' attribute in activity: '$activityName'"); + } + + // echo "$subdimension | $activityName\n"; + if (!array_key_exists("uuid", $activity)) { + array_push($errorMsg, "'$activityName' is missing an uuid in '$dimension'"); + } else { + $uuid = $dimensionsAggregated[$dimension][$subdimension][$activityName]["uuid"]; + $tmp_activityName = getActivityNameByUuid($uuid, $dimensionsAggregated); + if ($tmp_activityName != $activityName) { + array_push($errorMsg, "Duplicate UUID: $uuid in '$dimension'\n - ". $tmp_activityName ."\n - " . $activityName); + } + + if ($uuid != getUuidByActivityName($activityName, $dimensionsAggregated)) { + array_push($errorMsg, "Duplicate activity name: ". $activityName .""); + } } + + if (!array_key_exists("tags", $activity)) { - $dimensionsAggregated[$dimension][$subdimension][$activityName]["tags"] = [ "none" ]; + $dimensionsAggregated[$dimension][$subdimension][$activityName]["tags"] = ["none"]; } - if (!array_key_exists("teamsImplemented", $activity)) { - $dimensionsAggregated[$dimension][$subdimension][$activityName]["teamsImplemented"] = array(); + if (!array_key_exists("openCRE", $activity["references"])) { + $dimensionsAggregated[$dimension][$subdimension][$activityName]["references"]["openCRE"] = array(); + $dimensionsAggregated[$dimension][$subdimension][$activityName]["references"]["openCRE"][] = buildOpenCreUrl($dimension, $subdimension, $activityName); } - $evidenceImplemented = array(); - if(array_key_exists("evidence", $activity) && is_array($activity["evidence"]) && IS_IMPLEMENTED_WHEN_EVIDENCE) { - foreach($activity["evidence"] as $team => $evidenceForTeam) { - if(strlen($activity["evidence"][$team]) > 0) { - $evidenceImplemented[$team] = true; - }else { - echo "Warning: '$activityName -> evidence -> $team' has no evidence set but should have"; + if (array_key_exists("dependsOn", $activity)) { + foreach($activity['dependsOn'] as $index => $dependsOnName) { + if(!is_string($dependsOnName)) { + array_push($errorMsg, "The 'dependsOn' is not a string '" . json_encode($dependsOnName) . "' (in $activityName)"); + continue; } - } - } - if (!array_key_exists("openCRE", $activity["references"])) { - $dimensionsAggregated[$dimension][$subdimension][$activityName]["references"]["openCRE"] = array(); - $dimensionsAggregated[$dimension][$subdimension][$activityName]["references"]["openCRE"][] = "https://www.opencre.org/rest/v1/standard/DevSecOps+Maturity+Model+(DSOMM)/" . $subdimension . "/" . $dimensionsAggregated[$dimension][$subdimension][$activityName]["uuid"]; - } + // Load dependsOnName and dependsOnUuid, depending on actual content + $uuidRegExp = "/(uuid:)?\s*([0-9a-f]{6,}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{6,})/"; + if (preg_match($uuidRegExp, $dependsOnName, $matches)) { + $dependsOnUuid = $matches[2]; + $dependsOnName = getActivityNameByUuid($dependsOnUuid, $dimensionsAggregated); + if (is_null($dependsOnName)) { + array_push($errorMsg,"DependsOn non-existing activity uuid: $dependsOnUuid (in activity: '$activityName')"); + } else if ($matches[1] != "") { + echo "WARNING: DependsOn is prefixed by deprecated 'uuid:' for $dependsOnUuid (in activity: '$activityName'). Use activity name, or the uuid only\n"; + } + } else { + $dependsOnUuid = getUuidByActivityName($dependsOnName, $dimensionsAggregated); + if (is_null(getUuidByActivityName($dependsOnName, $dimensionsAggregated))) { + array_push($errorMsg,"DependsOn non-existing activity: '$dependsOnName' (in activity: $activityName)"); + } + } + // Trick emit_yaml() to have uuid plus a comment in a string. Removed in post-processing below. + $dimensionsAggregated[$dimension][$subdimension][$activityName]["dependsOn"][$index] = "{!$dependsOnUuid!}"; - $dimensionsAggregated[$dimension][$subdimension][$activityName]["teamsImplemented"] = array_merge($teamsImplemented, $dimensionsAggregated[$dimension][$subdimension][$activityName]["teamsImplemented"], $evidenceImplemented); - // can be removed in 2024 - if (array_key_exists("isImplemented", $activity)) { - unset($dimensionsAggregated[$dimension][$subdimension][$activityName]["evidence"]); - } + + // Build dependency graph + if (!array_key_exists($activityName, $activityIndex)) { + $activityIndex[$activityName] = count($activityIndex); + } + if (!array_key_exists($dependsOnName, $activityIndex)) { + $activityIndex[$dependsOnName] = count($activityIndex); + } + array_push_item_to($dependencies, $activityIndex[$dependsOnName], $activityIndex[$activityName]); + + } + } } } } + + foreach ($dimensionsAggregated as $dimension => $subdimensions) { - if(sizeof($subdimensions) == 0) { + if (sizeof($subdimensions) == 0) { echo "unsetting $dimension\n"; unset($dimensionsAggregated[$dimension]); } } -resolve_json_ref($dimensionsAggregated); +// Identify any issues regarding the references +$implementationReferences = readYaml($implementationReferenceFile)['implementations']; +$references = array("implementations" => $implementationReferences); +assertUniqueRefs($references, $errorMsg); +assertSecureUrlsInRefs($references, $errorMsg); +assertLiveUrlsInRefs($references, $errorMsg); + +resolveYamlReferences($dimensionsAggregated, $references, $errorMsg); -$dimensionsString = yaml_emit($dimensionsAggregated); -file_put_contents("src/assets/YAML/generated/generated.yaml", $dimensionsString); + +// Inform of any errors detected +if (count($errorMsg) > 0) { + echo "\n\nFound " . count($errorMsg) . " errors:\n"; + foreach ($errorMsg as $e) { + echo "ERROR: $e\n"; + } + exit("Please fix the errors"); +} + + +// Store generated data with meta document first +$metaDocument = array( + 'meta' => array( + 'version' => '__VERSION_PLACEHOLDER__', + 'released' => date('Y-m-d'), + 'publisher' => $publisher + ) +); +$modelString = yaml_emit_with_header($metaDocument, $dimensionsAggregated); + +// Post-process to add activity name as comment for `dependsOn` +preg_match_all('/\{!([0-9a-z-]{30,})!\}/', $modelString, $matches); +$uuids = array_unique($matches[1]); +foreach ($uuids as $uuid) { + $name = getActivityNameByUuid($uuid, $dimensionsAggregated); + // echo "Adding dependsOn-comment for $uuid: $name\n"; + $modelString = str_replace("'{!$uuid!}'", "$uuid # $name", $modelString); +} + +$targetGeneratedFile = getcwd() . "/$targetFolder/model.yaml"; +echo "\nSaved generated model: '$targetGeneratedFile'\n"; +file_put_contents($targetGeneratedFile, $modelString); + + +// Store dependency graph +$graphFilename = getcwd() . "/$targetFolder/dependency-tree.md"; +$graphFile = fopen($graphFilename, "w"); +$graphIntro = "## DSOMM Activity Dependencies\n\nThe activities in this DSOMM Model have the following dependencies."; +fwrite($graphFile, $graphIntro."\n\n"); +fwrite($graphFile, "```mermaid\n"); +fwrite($graphFile, "graph LR\n\n"); +// List all nodes +foreach ($activityIndex as $activityName => $key) { + $level = getActivityByActivityName($activityName, $dimensionsAggregated)["level"]; + $activityName = "L$level $activityName"; + $activityName = str_replace('(', '', $activityName); + $activityName = str_replace(')', '', $activityName); + fwrite($graphFile, "$key($activityName)\n"); +} +// Add links between nodes +fwrite($graphFile, "\n\n"); +foreach ($dependencies as $dad => $children) { + foreach ($children as $child) { + fwrite($graphFile, "$dad --> $child\n"); + } +} +// Tie all orphans to a common start node +fwrite($graphFile, "\n"); +foreach ($activityIndex as $activityName => $key) { + $isOrphan = true; + foreach ($dependencies as $dad => $children) { + if ($dad == $key) continue; + if (in_array($key, $children)) { + $isOrphan = false; + break; + } + } + if ($isOrphan) { + fwrite($graphFile, "O --> $key\n"); + } +} + +// Close the file +fwrite($graphFile, "```\n"); +fclose($graphFile); +echo "Saved dependency graph: '$graphFilename'\n\n"; + +function buildOpenCreUrl($dimension, $subdimension, $activityName) { + $baseUrl = "https://www.opencre.org/node/standard/"; + $DSOMM = "DevSecOps Maturity Model (DSOMM)"; + $url = $baseUrl . rawurlencode($DSOMM) . + "/section/" . rawurlencode($subdimension) . + "/subsection/" . rawurlencode($activityName); + return $url; +} + +function assertUniqueRefs($all_references, &$errorMsg) { + foreach ($all_references as $references) { + assertUniqueRefByKey($references, 'uuid', $errorMsg); + assertUniqueRefByKey($references, 'name', $errorMsg); + assertUniqueRefByKey($references, 'url', $errorMsg); + assertUniqueRefByKey($references, "\n description", $errorMsg); + } +} + +function assertUniqueRefByKey($references, $keyToAssert, &$errorMsg) { + $all_values = array(); + $printable_keyToAssert = $keyToAssert; + $keyToAssert = trim($keyToAssert); + + foreach ($references as $key => $reference) { + if (array_key_exists($keyToAssert, $reference)) { + $value = $reference[$keyToAssert]; + // echo "$key: $value\n"; + if (array_key_exists($value, $all_values)) { + array_push($errorMsg, "Duplicate '$keyToAssert' in reference file: '" . $all_values[$value] . "' and '$key': $printable_keyToAssert='$value'"); + } else { + $all_values[$value] = $key; + } + } + } +} + + +function assertSecureUrlsInRefs($all_references, &$errorMsg) { + foreach ($all_references as $references) { + foreach ($references as $id => $reference) { + foreach ($reference as $key => $value) { + if (is_string($value)) { + // echo "KEY: $key VAL: " . var_dump($value) . "\n"; + if (str_contains($value,'http://')) { + array_push($errorMsg, "Insecure url in '$key' of $id: " . $reference[$key]); + } + } + } + } + } +} + + +function assertLiveUrlsInRefs($all_references, &$errorMsg) { + if (TEST_REFERENCED_URLS) { + echo "\nTesting referenced URLs:\n"; + foreach ($all_references as $references) { + foreach ($references as $key => $reference) { + if (array_key_exists('url', $reference)) { + $url = $reference['url']; + echo " $key: $url\n"; + $err = assertLiveUrl($reference['url'], $reference['test-url-expects'] ?? []); + if ($err) { + echo " # $err\n"; + array_push($errorMsg, "Dead ref URL ($key): $err"); + } + } + } + } + echo "\n"; + } +} + + +function assertLiveUrl($url, $expectedStatusCodes = []):string { + $useragent = 'Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:135.0) Gecko/20100101 Firefox/135.0'; + + $curl = curl_init($url); + curl_setopt($curl, CURLOPT_USERAGENT, $useragent); + curl_setopt($curl, CURLOPT_HTTPHEADER, ['Accept-Language: en-US,en']); + curl_setopt($curl, CURLOPT_NOBODY, true); + curl_setopt($curl, CURLOPT_HEADER, true); + curl_setopt($curl, CURLOPT_FOLLOWLOCATION, false); + curl_setopt($curl, CURLOPT_RETURNTRANSFER, true); + curl_setopt($curl, CURLOPT_TIMEOUT, 5); + curl_setopt($curl, CURLOPT_CONNECTTIMEOUT, 5); + $response = curl_exec($curl); + + if (curl_errno($curl)) { + echo curl_error($curl); + curl_close($curl); + return "No reply"; + } + + // Extract header info + $statusCode = curl_getinfo($curl, CURLINFO_HTTP_CODE); + $redirectUrl = curl_getinfo($curl, CURLINFO_REDIRECT_URL ); + + curl_close($curl); + + if (isExpectedStatusCode($statusCode, $expectedStatusCodes)) { + return ""; + } + if ($statusCode == 301 || $statusCode == 302) { + return "Status code $statusCode redirects to: $redirectUrl"; + } + return "Status code: $statusCode: $url"; +} + +function isExpectedStatusCode($statusCode, $expectedStatusCodes) { + if (count($expectedStatusCodes) == 0) { + return $statusCode == 200; + } + + foreach ($expectedStatusCodes as $expectedStatusCode) { + if ($statusCode == $expectedStatusCode) { + return true; + } + } + return false; +} @@ -119,7 +360,8 @@ * @param unknown $activityName * @return unknown */ -function isActivityExisting($dimensions, $activityName) { +function isActivityExisting($dimensions, $activityName) +{ foreach (getActions($dimensions) as list($dimension, $subdimension, $activities)) { foreach ($activities as $activity => $activityContent) { if ($activity == $activityName) { @@ -130,14 +372,33 @@ function isActivityExisting($dimensions, $activityName) { return false; } +/** + * Creates a yaml string from $metaDocument plus $document separated with '---' + */ +function yaml_emit_with_header($metaDocument, $document) { + $metaString = yaml_emit($metaDocument); + $documentString = yaml_emit($document); + + // Combine both documents with proper YAML document separation + if (substr(rtrim($metaString), -3) === '...') { + // Remove trailing ... from meta document + $metaString = substr(rtrim($metaString), 0, -3); + } + + return $metaString . $documentString; +} + /** + * Merges two arrays recursively (just like the standard `array_merge_recursive()`), + * but will not create duplicates if the keys are numeric. * - * @param array $array1 - * @param array $array2 - * @return unknown + * @param array $array1 + * @param array $array2 + * @return merged array */ -function array_merge_recursive_ex(array $array1, array $array2) { +function array_merge_recursive_ex(array $array1, array $array2) +{ $merged = $array1; foreach ($array2 as $key => & $value) { @@ -156,40 +417,64 @@ function array_merge_recursive_ex(array $array1, array $array2) { } -/** - * Traverse in-place an array and replaces json-pointers. - * - * @param unknown $data (reference) +/* + * Traverse an array in-place and replaces yaml pointers. */ -function resolve_json_ref(&$data) { - - - /** - * - * @param unknown $value (reference) - * @param unknown $key - * @param unknown $ctx - */ - function resolve_json_ref_cb(&$value, $key, $ctx) { - if (! is_array($value)) { +function resolveYamlReferences(&$data, $references, &$errorMsg) +{ + function resolveYamlReferencesCallback(&$value, $key, $payload) + { + if (!is_array($value)) { return; } if (!array_key_exists('$ref', $value)) { - $ctx["ctx"] = &$value; - array_walk($value, "resolve_json_ref_cb", $ctx); + // Call recursively until $value contains a '$ref' child + array_walk($value, "resolveYamlReferencesCallback", $payload); + return; + } else { + list($context, $ref) = extractReference($value['$ref']); + if (is_null($context) || is_null($ref)) { + array_push($payload['errorMsg'],"Invalid syntax in reference file: '" . $value['$ref'] . "'"); return; } + if (!array_key_exists($context, $payload['references']) || + !array_key_exists($ref, $payload['references'][$context]) ) { + array_push($payload['errorMsg'],"Reference does not exist: '$context/$ref'"); + return; + } + + // Insert the actual reference object, instead of the reference link + $value = $payload['references'][$context][$ref]; + $payload['usedRefs']["$context/$ref"] = true; + } + } + - // echo "key: $key\nvalue: ".var_dump($ctx). "\n"; - $ctx["ctx"][$key] = readYaml($value['$ref']); + // Call resolve_yaml_references_cb for each and every node in the data array + $usedRefs = array(); + $payload = array('references' => &$references, 'errorMsg' => &$errorMsg, 'usedRefs' => &$usedRefs); + array_walk($data, "resolveYamlReferencesCallback", $payload); + // Inform of unused references + echo "\n"; + foreach ($references as $context => $refs) { + foreach ($refs as $ref => $refData) { + if (!array_key_exists("$context/$ref", $usedRefs)) { + echo "INFO: Reference never used: $context: $ref\n"; + } + } } +} - // Create a context variable to store - // the reference to the actual data, so that - // resolve_reference can replace them. - $ctx = array("ctx" => null); - array_walk($data, "resolve_json_ref_cb", $ctx); +/* + * Extract the context id and the reference id from the '$ref' value in the yaml + */ +function extractReference($str) { + $regExp = "~#/([\w-]+)/([\w-]+)~"; + if (preg_match($regExp, $str, $matches)) { + return array($matches[1], $matches[2]); + } + return null; }