Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Group Discussion : CIS Benchmarks, BDD Testing and Tools Provisioning #84

Closed
mcleo-d opened this issue Nov 20, 2020 · 5 comments
Closed
Assignees
Labels
bdd Items related to BDD activities

Comments

@mcleo-d
Copy link
Member

mcleo-d commented Nov 20, 2020

Description

During 19th November 2020 #79, @peterrhysthomas, @abdullahgarcia, @leefaus, @eddie-knight and @jamilmina1 discussed if teams are running CIS benchmarking against implemented services and whether there are other BBD test mechanisms.

Action

To schedule a discussion group to explore the subject further and report to the main CSC project group. Notes on the original conversation include ...

  • CIS benchmark tools being explored for GCP. Is there wider group experience?
  • Benchmarking tools don't have the data required, so teams are assuming outcomes based on retrospective experiences.
  • Config scanning prior to deploy so evidence is documented that tests have run against known standards.
  • Continuous feedback that IAC is meeting the benchmark as requests for evidence made with small changes.
  • @eddie-knight contributes to https://github.com/citihub/probr, which could help resolve the problem.

Scheduled Group Meeting

Meeting scheduled with CSC project group for Wednesday 25th November @11:30am ET / 4:30pm GMT on the FINOS Community WebEx. All are invited to join.

@mcleo-d mcleo-d self-assigned this Nov 20, 2020
@mcleo-d mcleo-d added this to To do in Compliant Financial Infrastructure via automation Nov 20, 2020
@mcleo-d mcleo-d moved this from To do to Prioritised in Compliant Financial Infrastructure Nov 20, 2020
@mcleo-d mcleo-d moved this from Prioritised to In progress in Compliant Financial Infrastructure Nov 25, 2020
@mcleo-d
Copy link
Member Author

mcleo-d commented Nov 26, 2020

The following Cloud Service Certification group members met on Wednesday 25th November @11:30am ET / 4:30pm GMT

Name GitHub Profile Firm
Lee Faus @leefaus Armory
Alfred Tommy @alfredtommy Searce
Paul Jones -- CitiHub
Eric Tice @erictice Wipro
Abdullah Garcia @abdullahgarcia JPMC
Jamil Mina @jamilmina1 Red Hat
Eddie Knight @eddie-knight CitiHub

Discussion Points

Outcomes

@mcleo-d mcleo-d added the bdd Items related to BDD activities label Feb 12, 2021
@mcleo-d mcleo-d moved this from In progress to Sprint 1 - 25th March (Sprint Start) to 22nd April (Sprint End) in Compliant Financial Infrastructure Mar 25, 2021
@mcleo-d mcleo-d moved this from Sprint 1 - 25th March (Start) to 22nd April (End) to Sprint 2 - 22nd April to ... in Compliant Financial Infrastructure Apr 28, 2021
@iantivey
Copy link

iantivey commented Apr 28, 2021

Late to the party here, but we have a couple of things that might offer some assistance for this issue -

  1. For AKS, we have transposed the GKE CIS Benchmarks onto AKS and have almost complete coverage of the relevant items, plus some additional tests that aren't covered by GKE. Some of the implementations run OPA under the covers. We've tried a few iterations and have now settled on a standardised way to spec the rego policies and BDD feature files.
  2. We have the Probr Kubernetes pack running against a GKE instance in our demo environment. We believe this demonstrates the value of using Probr for testing, because we're able to use the same code to test against both Azure and Google services without any changes to the code, even though the implementations of the controls are quite different (e.g. Azure implements pod security using Azure Policy, Google use Kube PodSecurityPolicy).

@mcleo-d
Copy link
Member Author

mcleo-d commented Apr 28, 2021

Thanks for the information above @iantivey 🚀

I'm going to tag @eddie-knight as he's keeping CSC informed on the benefits of Probr and is working close on the approach with @leefaus. Here's a link to @leefaus' conftest PR #91

Can the information above be used to create Probr integration stories with @eddie-knight as we move from Sprint 2 into Sprint 3?

Let me know your thoughts 💭

James.

@mcleo-d
Copy link
Member Author

mcleo-d commented Jul 1, 2021

@leefaus - The Armory CCLA is now signed and you have been added to the FINOS CLA Bot. You are also free to move forward according to the following comment ... #119 (comment)

cc @eddie-knight

@mcleo-d
Copy link
Member Author

mcleo-d commented Jul 15, 2021

Closed as superseded by #91, #62, #128

@mcleo-d mcleo-d closed this as completed Jul 15, 2021
Compliant Financial Infrastructure automation moved this from Sprint 3 - 17th June to 15th July '21 to Done Jul 15, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bdd Items related to BDD activities
Projects
Archived in project
Development

No branches or pull requests

2 participants