Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Explore CISecurity collaboration #15

Open
JonZeolla opened this issue Jul 29, 2022 · 5 comments
Open

Explore CISecurity collaboration #15

JonZeolla opened this issue Jul 29, 2022 · 5 comments
Assignees

Comments

@JonZeolla
Copy link
Member

It seems that CISecurity is working on OSCAL for their benchmarks. Looking to set up collaboration conversations.

@JonZeolla JonZeolla self-assigned this Jul 29, 2022
@JonZeolla
Copy link
Member Author

Pending an introduction by Zeal

@xee5ch
Copy link
Contributor

xee5ch commented Aug 3, 2022

FYI, their baselines control catalog (sorry, not I misspoke, I assume baselines might mean something specific an different than I how use it) are already public and they accept feedback via GH issues.

https://github.com/CISecurity/CISControls_OSCAL/

@JonZeolla
Copy link
Member Author

Intro has been sent, working on initial discussion

@JonZeolla
Copy link
Member Author

Had an initial discussion this morning; more coming, collaboration likely and may loop in other entities including NIST and the CSA

@JonZeolla
Copy link
Member Author

Here are my notes from today:

CIS provides Mapping as a Service - controls only, which is a very popular service that tool vendors and orgs look at.

Looking for all frameworks to be represented in OSCAL, and map together as needed. Some work on refining mapping methodologies; opportunity for collaboration. Internally they plan to come up with use cases and think about the end goal of the mapping. They currently use ideas like superset and intersection, but are also looking to be able to identify gaps during mapping exercises.

CSA CCM is 4.0 in OSCAL; CIS has mapped, but no unique IDs yet.

  • Want unique IDs for their benchmarks.

Cloud providers are interested.

CSA does have CCM 4.0 in OSCAL, not sure where it resides

CIS mapping to CSA is in https://github.com/CISecurity/CISControls_OSCAL

If we want to talk about coming together for a mapping methodology.

CIS Meets with CSA and NIST regularly; going to work on a method to collaborate more together instead of individually. Consider a CIS Workbench community or GitHub discussions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: 🏗 In progress
Development

No branches or pull requests

2 participants