@@ -388,7 +388,7 @@ Build and Deployment:
388388 usefulness : 4
389389 level : 1
390390 dependsOn :
391- - Continuous Integration
391+ - Defined build process
392392 implementation :
393393 - uuid : b4bfead3-5fb6-4dd0-ba44-5da713bd22e4
394394 name : CI/CD tools
@@ -564,7 +564,7 @@ Build and Deployment:
564564 exists (gathered manually or automatically).
565565 dependsOn :
566566 - Defined deployment process
567- - 2a44b708-734f-4463-b0cb-86dc46344b2f
567+ - Inventory of production components
568568 difficultyOfImplementation :
569569 knowledge : 2
570570 time : 2
@@ -690,7 +690,7 @@ Build and Deployment:
690690 measure : A documented inventory of dependencies used in artifacts like container
691691 images and containers exists.
692692 dependsOn :
693- - 83057028-0b77-4d2e-8135-40969768ae88
693+ - Inventory of production artifacts
694694 - SBOM of components
695695 difficultyOfImplementation :
696696 knowledge : 2
@@ -2492,7 +2492,7 @@ Culture and Organization:
24922492 usefulness : 3
24932493 level : 2
24942494 dependsOn :
2495- - 2a44b708-734f-4463-b0cb-86dc46344b2f
2495+ - Inventory of production components
24962496 implementation :
24972497 - uuid : 227d786c-dd76-4b81-b0b2-62389ab8f0fb
24982498 name : OWASP DefectDojo
@@ -3100,7 +3100,7 @@ Implementation:
31003100 usefulness : 3
31013101 level : 3
31023102 dependsOn :
3103- - e7598ac4-b082-4e56-b7df-e2c6b426a5e2
3103+ - Require a PR before merging
31043104 implementation :
31053105 - uuid : b1b88bc5-5a22-4888-a27b-acce3d9fe29a
31063106 name : Improve code quality with branch policies
@@ -3146,7 +3146,7 @@ Implementation:
31463146 usefulness : 4
31473147 level : 3
31483148 dependsOn :
3149- - e7598ac4-b082-4e56-b7df-e2c6b426a5e2
3149+ - Require a PR before merging
31503150 implementation :
31513151 - uuid : b1b88bc5-5a22-4888-a27b-acce3d9fe29a
31523152 name : Improve code quality with branch policies
@@ -3288,7 +3288,7 @@ Implementation:
32883288 usefulness : 4
32893289 level : 3
32903290 dependsOn :
3291- - e7598ac4-b082-4e56-b7df-e2c6b426a5e2
3291+ - Require a PR before merging
32923292 implementation :
32933293 - uuid : b1b88bc5-5a22-4888-a27b-acce3d9fe29a
32943294 name : Improve code quality with branch policies
@@ -5489,7 +5489,7 @@ Information Gathering:
54895489 usefulness : 3
54905490 level : 2
54915491 dependsOn :
5492- - 8ae0b92c-10e0-4602-ba22-7524d6aed488
5492+ - Automated PRs for patches
54935493 implementation : []
54945494 references :
54955495 samm2 :
@@ -5526,8 +5526,8 @@ Information Gathering:
55265526 usefulness : 3
55275527 level : 4
55285528 dependsOn :
5529- - 86d490b9-d798-4a5b-a011-ab9688014c46
5530- - 8ae0b92c-10e0-4602-ba22-7524d6aed488
5529+ - Patching mean time to resolution via PR
5530+ - Automated PRs for patches
55315531 implementation : []
55325532 references :
55335533 samm2 :
@@ -5831,8 +5831,8 @@ Test and Verification:
58315831 - The number of network hops required to reach the asset (recommended)
58325832 - Authentication requirements for access (recommended)
58335833 dependsOn :
5834- - 44f2c8a9-4aaa-4c72-942d-63f78b89f385
5835- - 2a44b708-734f-4463-b0cb-86dc46344b2f
5834+ - Treatment of defects with severity high or higher
5835+ - Inventory of production components
58365836 implementation : ~
58375837 references :
58385838 samm2 :
@@ -6322,9 +6322,9 @@ Test and Verification:
63226322 resources : 2
63236323 usefulness : 2
63246324 dependsOn :
6325- - f2f0f274-c1a0-4501-92fe-7fc4452bc8ad
6326- - 6217fe11-5ed7-4cf4-9de4-555bcfa6fe87
6327- - 185d5a74-19dc-4422-be07-44ea35226783
6325+ - Exploit likelihood estimation
6326+ - Each team has a security champion
6327+ - Office Hours
63286328 level : 3
63296329 description : " For known vulnerabilities a processes to estimate the exploit
63306330 ability of a vulnerability is recommended.\n\n To implement a security culture
@@ -6946,7 +6946,7 @@ Test and Verification:
69466946 tags : []
69476947 url : https://github.com/controlplaneio/netassert
69486948 dependsOn :
6949- - Segmented networks for virtual environments
6949+ - Isolated networks for virtual environments
69506950 references :
69516951 samm2 :
69526952 - V-ST-2-A
@@ -7104,7 +7104,7 @@ Test and Verification:
71047104 - https://www.opencre.org/rest/v1/standard/DevSecOps+Maturity+Model+(DSOMM)/Static
71057105 depth for applications/017d9e26-42b5-49a4-b945-9f59b308fb99
71067106 dependsOn :
7107- - 2a44b708-734f-4463-b0cb-86dc46344b2f
7107+ - Inventory of production components
71087108 tags :
71097109 - none
71107110 teamsImplemented :
@@ -7199,7 +7199,7 @@ Test and Verification:
71997199 usefulness : 4
72007200 level : 3
72017201 dependsOn :
7202- - d918cd44-a972-43e9-a974-eff3f4a5dcfe
7202+ - Software Composition Analysis (server side)
72037203 implementation :
72047204 - uuid : aa507341-9531-42cd-95cf-d7b51af47086
72057205 name : Known Exploited Vulnerabilities
@@ -7303,8 +7303,8 @@ Test and Verification:
73037303 level : 3
73047304 dependsOn :
73057305 - Defined build process
7306- - 2a44b708-734f-4463-b0cb-86dc46344b2f
7307- - f2f0f274-c1a0-4501-92fe-7fc4452bc8ad
7306+ - Inventory of production components
7307+ - Exploit likelihood estimation
73087308 implementation :
73097309 - uuid : aa54a82c-d628-4d42-9bc8-1aa269cd91c7
73107310 name : retire.js
@@ -7369,7 +7369,7 @@ Test and Verification:
73697369 level : 2
73707370 dependsOn :
73717371 - Defined build process
7372- - 2a44b708-734f-4463-b0cb-86dc46344b2f
7372+ - Inventory of production components
73737373 implementation :
73747374 - uuid : 06334caf-8be6-487a-96b1-d41c7ed5f207
73757375 name : OWASP Dependency Check
@@ -7441,7 +7441,7 @@ Test and Verification:
74417441 dependsOn :
74427442 - Static analysis for important client side components
74437443 - Static analysis for important server side components
7444- - 2a44b708-734f-4463-b0cb-86dc46344b2f
7444+ - Inventory of production components
74457445 implementation : []
74467446 references :
74477447 samm2 :
@@ -7505,7 +7505,7 @@ Test and Verification:
75057505 dependsOn :
75067506 - Static analysis for important client side components
75077507 - Static analysis for important server side components
7508- - 2a44b708-734f-4463-b0cb-86dc46344b2f
7508+ - Inventory of production components
75097509 references :
75107510 samm2 :
75117511 - V-ST-2-A
@@ -7572,7 +7572,7 @@ Test and Verification:
75727572 - sast
75737573 dependsOn :
75747574 - Defined build process
7575- - 2a44b708-734f-4463-b0cb-86dc46344b2f
7575+ - Inventory of production components
75767576 references :
75777577 samm2 :
75787578 - V-ST-2-A
@@ -7634,7 +7634,7 @@ Test and Verification:
76347634 - sast
76357635 dependsOn :
76367636 - Defined build process
7637- - 2a44b708-734f-4463-b0cb-86dc46344b2f
7637+ - Inventory of production components
76387638 references :
76397639 samm2 :
76407640 - V-ST-2-A
0 commit comments