-
Notifications
You must be signed in to change notification settings - Fork 26
Security_Controls
Rev: 20231114
-
ITSG 33 : Security Control Catalogue : https://www.cyber.gc.ca/en/guidance/annex-3a-security-control-catalogue-itsg-33
-
AU-1 - family: audit and accountability - class: technical - AU-1 : audit and accountability policy and procedures
-
AU-2 - family: audit and accountability - class: technical - AU-2 : auditable events
-
AU-3 - family: audit and accountability - class: technical - AU-3 : content of audit records
-
AU-4 - family: audit and accountability - class: technical - AU-4 : audit storage capacity
-
AU-4(1) - family: audit and accountability - class: technical - AU-4.1 : audit storage capacity | transfer to alternate storage
-
AU-6 - family: audit and accountability - class: technical - AU-6 : audit review, analysis, and reporting
-
AU-8 - family: audit and accountability - class: technical - AU-8 : time stamps
-
AU-12 - family: audit and accountability - class: technical - AU-12 : audit generation
-
CM-1 - family: configuration management - class: operational - CM-1: configuration management policy and procedures
-
CM-2 - family: configuration management - class: operational - CM-2: baseline configuration
-
CM-3 - family: configuration management - class: operational - CM-3: configuration change control
-
CM-5 - family: configuration management - class: operational - CM-5: access restrictions for change
-
CM-6 - family: configuration management - class: operational - CM-6: configuration settings
-
CM-7 - family: configuration management - class: operational - CM-7: least functionality
-
CM-7(5) - family: configuration management - class: operational - CM-7.5: least functionality | authorized software / whitelisting
-
CM-8 - family: configuration management - class: operational - CM-8: information system component inventory
-
CM-9 - family: configuration management - class: operational - CM-9: configuration management plan
-
CP-1 - family: contingency planning (continuity planning) - class: operational - CP-1 : contingency planning policy and procedures
-
IR-1 - family: incident response - class: operational - IR-1 incident response policy and procedures
-
IR-9 - family: incident response - class: operational - IR-9 : information spillage response
-
MA-1 - family: maintenance - class: operational - MA-1 : system maintenance policy and procedures
-
MA-3(3) - family: maintenance - class: operational - MA-3 : maintenance tools | prevent unauthorized removal
-
RA-1 - family: risk assessment - class: management - RA-1 : risk assessment policy and procedures
-
RA-2 - family: risk assessment - class: management - RA-2 : security categorization
-
RA-3 - family: risk assessment - class: management - RA-3 : risk assessment
https://github.com/GoogleCloudPlatform/pubsec-declarative-toolkit/issues/560
Check removed files
delete mode 100644 solutions/client-landing-zone/client-folder/standard/applications-infrastructure/host-project/securitycontrols.md
delete mode 100644 solutions/client-landing-zone/logging-project/securitycontrols.md
delete mode 100644 solutions/core-landing-zone/lz-folder/audits/logging-project/securitycontrols.md
Example visuals for extract and/or live compliance dashboard
d3js.org based or mermaid in-line-repo markup (generated) in https://github.com/GoogleCloudPlatform/pubsec-declarative-toolkit/wiki/Security_Controls
https://observablehq.com/@kerryrodden/sequences-sunburst https://d3js.org/ https://github.com/GoogleCloudPlatform/pbmm-on-gcp-onboarding/blob/main/docs/google-cloud-security-controls.md#controls-coverage https://mermaid.js.org/#/flowchart?id=graph
See exercise at compliance dashboard and automated security control mapping extract - so we don't have to manually create one of these
or the wiki based editing of