Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Address EXO comment and structural changes in the baseline document #436

Merged
merged 17 commits into from
Jul 26, 2023

Conversation

buidav
Copy link
Collaborator

@buidav buidav commented Jul 13, 2023

🗣 Description

  • Reformatted the baseline document with new structure and policy identifiers
  • Refine and update policy statements to address pilot feedback.
  • Updated implementation steps for any out-of-date instructions
  • Address the EXO baseline portion of Fix EXO deprecated alert policies in MS.EXO.16.1 #29 . Code updates need to be made in defender.

Added to this PR from the TODOs.

TODO: address code updates in #429
TODO: add rationale to the baseline document Issue: #434 PR: #447

💭 Motivation and context

Looks like closing keywords no longer work if the base branch isn't the default branch?

closes #285
closes #247

🧪 Testing

  • Retested instructions for the EXO policies on commercial and GCC tenants.
  • Addressed comments in the comments matrix.

✅ Pre-approval checklist

  • This PR has an informative and human-readable title.
  • Changes are limited to a single goal - eschew scope creep!
  • All future TODOs are captured in issues, which are referenced
    in code comments.
  • All relevant type-of-change labels have been added.
  • All relevant repo and/or project documentation has been updated
    to reflect the changes in this PR.

✅ Pre-merge checklist

✅ Post-merge checklist

@buidav buidav added the baseline-document Issues relating to the text in the baseline documents themselves label Jul 13, 2023
@buidav buidav added this to the Emerald milestone Jul 13, 2023
@buidav buidav self-assigned this Jul 13, 2023
@buidav buidav changed the base branch from main to emerald July 13, 2023 16:10
Copy link
Collaborator

@schrolla schrolla left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Part 1 of my review that covers Introduction through DLP (Section 8). I split my comments up so I could get this set out for remediation as I work on the remainder in a separate review. Part 2 is my highest priority to complete next.

baselines/exo.md Show resolved Hide resolved
baselines/exo.md Show resolved Hide resolved
baselines/exo.md Outdated Show resolved Hide resolved
baselines/exo.md Outdated Show resolved Hide resolved
baselines/exo.md Outdated Show resolved Hide resolved
baselines/exo.md Outdated Show resolved Hide resolved
baselines/exo.md Outdated Show resolved Hide resolved
baselines/exo.md Outdated Show resolved Hide resolved
baselines/exo.md Show resolved Hide resolved
baselines/exo.md Show resolved Hide resolved
Copy link
Collaborator

@schrolla schrolla left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See individual comments. Many are simply updating the Defender mappings to point to the new policy group names rather than the SHALL/SHOULD old style naming.

baselines/exo.md Show resolved Hide resolved
baselines/exo.md Outdated Show resolved Hide resolved
baselines/exo.md Show resolved Hide resolved
baselines/exo.md Outdated Show resolved Hide resolved
baselines/exo.md Outdated Show resolved Hide resolved
baselines/exo.md Outdated Show resolved Hide resolved
baselines/exo.md Show resolved Hide resolved
baselines/exo.md Outdated Show resolved Hide resolved
baselines/exo.md Show resolved Hide resolved
baselines/exo.md Outdated Show resolved Hide resolved
@buidav buidav force-pushed the 285-clarify-several-polices-in-exo-2 branch from 58fa8e4 to 1ad2362 Compare July 19, 2023 04:38
@buidav buidav requested a review from schrolla July 19, 2023 19:12
@buidav
Copy link
Collaborator Author

buidav commented Jul 19, 2023

@schrolla Addressed all of your comments. Comments addressed have a 👍🚀.
Ready for another pass.

baselines/exo.md Outdated Show resolved Hide resolved
baselines/exo.md Outdated Show resolved Hide resolved
baselines/exo.md Outdated Show resolved Hide resolved
@buidav
Copy link
Collaborator Author

buidav commented Jul 20, 2023

@Dylan-MITRE Addressed your feedback. I'm avoiding commenting directly because the unit tests are running every time I submit a comment 😱. Any comment with a 👍🚀 means I've addressed it with your suggestion.

@schrolla changed the links to Defender to be relative.
Looking at it now a replace all to the absolute path for the pdf version should be achievable with little work.

baselines/exo.md Outdated Show resolved Hide resolved
@buidav buidav force-pushed the 285-clarify-several-polices-in-exo-2 branch from a5c288a to fb7763d Compare July 25, 2023 04:17
Copy link
Collaborator

@schrolla schrolla left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Found two minor typos when looking over other revisions made. Should be a quick fix with the suggestions to remove the extra character.

baselines/exo.md Outdated Show resolved Hide resolved
baselines/exo.md Outdated Show resolved Hide resolved
buidav and others added 6 commits July 25, 2023 13:59
Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>
Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>
Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>
Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>
@buidav buidav force-pushed the 285-clarify-several-polices-in-exo-2 branch from 0d7f031 to f7dcc13 Compare July 25, 2023 21:06
@nanda-katikaneni nanda-katikaneni merged commit ea6754e into emerald Jul 26, 2023
2 of 5 checks passed
@schrolla schrolla deleted the 285-clarify-several-polices-in-exo-2 branch August 7, 2023 20:22
crutchfield pushed a commit that referenced this pull request Aug 23, 2023
…436)

* adjudicate exo comments and refactor implementation

* address #29 in the baseline document

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Get-OrganizationConfig Spacing

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Defender apostrophe typo fix

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* first pass at addressing comments

* address all current feedback

* clean up Defender duplicated policy linking

* clean up missing clarification

* address 2nd round of feedback

* clean up the defender links round 2

* fix the brain fart

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* spacing the rationale

---------

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>
schrolla added a commit that referenced this pull request Sep 1, 2023
…436)

* adjudicate exo comments and refactor implementation

* address #29 in the baseline document

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Get-OrganizationConfig Spacing

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Defender apostrophe typo fix

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* first pass at addressing comments

* address all current feedback

* clean up Defender duplicated policy linking

* clean up missing clarification

* address 2nd round of feedback

* clean up the defender links round 2

* fix the brain fart

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* spacing the rationale

---------

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>
schrolla added a commit that referenced this pull request Nov 2, 2023
…436)

* adjudicate exo comments and refactor implementation

* address #29 in the baseline document

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Get-OrganizationConfig Spacing

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Defender apostrophe typo fix

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* first pass at addressing comments

* address all current feedback

* clean up Defender duplicated policy linking

* clean up missing clarification

* address 2nd round of feedback

* clean up the defender links round 2

* fix the brain fart

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* spacing the rationale

---------

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>
schrolla added a commit that referenced this pull request Nov 2, 2023
…436)

* adjudicate exo comments and refactor implementation

* address #29 in the baseline document

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Get-OrganizationConfig Spacing

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* Defender apostrophe typo fix

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* first pass at addressing comments

* address all current feedback

* clean up Defender duplicated policy linking

* clean up missing clarification

* address 2nd round of feedback

* clean up the defender links round 2

* fix the brain fart

* Update baselines/exo.md

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>

* spacing the rationale

---------

Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
baseline-document Issues relating to the text in the baseline documents themselves
Projects
None yet
4 participants