From c71fa46e179c3c594f3575e11ffbc8fcee19ffae Mon Sep 17 00:00:00 2001 From: Timo Pagel Date: Wed, 15 Nov 2023 13:21:08 +0100 Subject: [PATCH] =?UTF-8?q?=F0=9F=A4=96=20fmt?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- CHANGELOG.md | 7 ++++++ src/assets/YAML/generated/generated.yaml | 27 ++++++++++++++++-------- 2 files changed, 25 insertions(+), 9 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 513ebae..23d1c69 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,10 @@ +## [1.10.1](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.10.0...v1.10.1) (2023-11-15) + + +### Bug Fixes + +* references ([6d7f7ba](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/commit/6d7f7ba57413a0b484e83b07bcd54b07d66c10d0)) + # [1.9.0](https://github.com/devsecopsmaturitymodel/DevSecOps-MaturityModel-data/compare/v1.8.2...v1.9.0) (2023-11-15) diff --git a/src/assets/YAML/generated/generated.yaml b/src/assets/YAML/generated/generated.yaml index 2cff25a..58e0627 100644 --- a/src/assets/YAML/generated/generated.yaml +++ b/src/assets/YAML/generated/generated.yaml @@ -4868,11 +4868,13 @@ Implementation: implementation: [] references: samm2: - - TODO: Develop an advanced threat management framework that includes rigorous - input validation strategies. + - D-SR-3-A + iso27001-2017: + - Hardening is not explicitly covered by ISO 27001 - too specific + - 13.1.3 iso27001-2022: - - TODO: Incorporate advanced WAF input validation processes into the organization's - ISMS. + - Hardening is not explicitly covered by ISO 27001 - too specific + - 8.22 openCRE: - https://www.opencre.org/rest/v1/standard/DevSecOps+Maturity+Model+(DSOMM)/Infrastructure Hardening/f0e01814-3b88-4bd0-a3a9-f91db001d20b-advanced @@ -4904,9 +4906,13 @@ Implementation: implementation: [] references: samm2: - - TODO: Identify and implement SAMM security practices relevant to WAF configuration. + - D-SR-3-A + iso27001-2017: + - Hardening is not explicitly covered by ISO 27001 - too specific + - 13.1.3 iso27001-2022: - - TODO: Integrate WAF deployment with ISO 27001 controls for system hardening. + - Hardening is not explicitly covered by ISO 27001 - too specific + - 8.22 openCRE: - https://www.opencre.org/rest/v1/standard/DevSecOps+Maturity+Model+(DSOMM)/Infrastructure Hardening/f0e01814-3b88-4bd0-a3a9-f91db001d20b @@ -4938,10 +4944,13 @@ Implementation: implementation: [] references: samm2: - - TODO: Establish advanced SAMM security practices for WAF management. + - D-SR-3-A + iso27001-2017: + - Hardening is not explicitly covered by ISO 27001 - too specific + - 13.1.3 iso27001-2022: - - TODO: Ensure WAF processes are integrated into the overall security management - in accordance with ISO 27001 standards. + - Hardening is not explicitly covered by ISO 27001 - too specific + - 8.22 openCRE: - https://www.opencre.org/rest/v1/standard/DevSecOps+Maturity+Model+(DSOMM)/Infrastructure Hardening/f0e01814-3b88-4bd0-a3a9-f91db001d20b