Куда я попал?
OWASP DSOMM
Framework
Test and Verification
Для проведения оценки соответствия по документу войдите в систему.
Список требований
-
Level 3: High adoption of security practices: Treatment of defects with severity middle
Risk:
Vulnerabilities with severity middle are not visible.
Measure:
Vulnerabilities with severity middle are added to the quality gate.
Difficulty of Implementation:
Knowledge: Medium (two disciplines)
Time: Medium
Resources: Low
Usefulness:HighОбязательно для уровня зрелости 1 2 3 -
Level 5: Advanced deployment of security practices at scale: Treatment of all defects
Risk:
Vulnerabilities with severity low are not visible.
Measure:
All vulnerabilities are added to the quality gate.
Difficulty of Implementation:
Knowledge: High (two disciplines)
Time: Very High
Resources: Low
Usefulness:
MediumОбязательно для уровня зрелости 1 2 3 4 5 -
Level 5: Advanced deployment of security practices at scale: Coverage of service to service communication
Risk:
Service to service communication is not covered.
Measure:
Service to service communication is dumped and checked.
Difficulty of Implementation:
Knowledge: Very High (three or more disciplines)
Time:
Resources: Medium
Usefulness:
HighОбязательно для уровня зрелости 2 3 4 5 -
Level 3: High adoption of security practices: Analyze logs
Risk:
Not aware of attacks happening.
Measure:
Check logs for keywords.
Difficulty of Implementation:
Knowledge: Medium (two disciplines)
Time: Medium
Resources: Medium
Usefulness:
High
Implementation:- SigmaHQ
- Tags
- URL
- https://github.com/SigmaHQ/sigma
- Description
- Tags
Обязательно для уровня зрелости 1 2 3 - SigmaHQ
-
Level 3: High adoption of security practices: Test for new image version
Risk:
When a new version of an image is available, it might fix security vulnerabilities.
Measure:
Check for new images of containers in production.
Difficulty of Implementation:
Knowledge: High (two disciplines)
Time: High
Resources: Low
Usefulness:
MediumОбязательно для уровня зрелости 1 2 3
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.