Objectives
Document OSCAL Compass Security Self Assessment and populate the link information in each repo level security-insights.yml
Resources
Guide on Self Assessment from CNCF STAG
There is an existing SELF_ASSESSMENT.md file that can be used for collaboration, but this can also be documented in another platform or location for easier real-time collaboration before moving into the markdown.
Guidance on each section from the original CNCF template is preserved in Markdown comments and are included in each sub task for the relevant section.
Some sections may be relevant to the OSCAL Compass project as a whole and others like Actors and Actions may require breaking down by sub-project to fully capture of the security considerations for the reader.
Core components that should be considered in scope include:
compliance-trestle and associated repos (including Agile Authoring)
compliance-to-policy and associated repos
Completion Criteria
Objectives
Document OSCAL Compass Security Self Assessment and populate the link information in each repo level
security-insights.ymlResources
Guide on Self Assessment from CNCF STAG
There is an existing
SELF_ASSESSMENT.mdfile that can be used for collaboration, but this can also be documented in another platform or location for easier real-time collaboration before moving into the markdown.Guidance on each section from the original CNCF template is preserved in Markdown comments and are included in each sub task for the relevant section.
Some sections may be relevant to the OSCAL Compass project as a whole and others like
ActorsandActionsmay require breaking down by sub-project to fully capture of the security considerations for the reader.Core components that should be considered in scope include:
compliance-trestleand associated repos (including Agile Authoring)compliance-to-policyand associated reposCompletion Criteria