-
Notifications
You must be signed in to change notification settings - Fork 61
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request #1445 from IBM/develop
chore: Trestle release
- Loading branch information
Showing
31 changed files
with
1,239 additions
and
230 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
23 changes: 0 additions & 23 deletions
23
tests/data/author/0.0.1/test_1_md_format/bad_instance_reordered.md
This file was deleted.
Oops, something went wrong.
23 changes: 23 additions & 0 deletions
23
...author/governed_folders/good_instance_with_template_type/architecture_test_1.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,23 @@ | ||
--- | ||
authors: | ||
- Tim | ||
- Jane | ||
- Sally | ||
owner: Joe | ||
valid: | ||
from: 2020-01-01 | ||
to: 2099-12-31 | ||
x-trestle-template-type: architecture | ||
--- | ||
|
||
# System architecture | ||
|
||
Here is some content | ||
|
||
## Overview | ||
|
||
And some more | ||
|
||
## Security model | ||
|
||
And even more |
23 changes: 23 additions & 0 deletions
23
...author/governed_folders/good_instance_with_template_type/architecture_test_2.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,23 @@ | ||
--- | ||
authors: | ||
- Tim | ||
- Jane | ||
- Sally | ||
owner: Joe | ||
valid: | ||
from: 2020-01-01 | ||
to: 2099-12-31 | ||
x-trestle-template-type: architecture | ||
--- | ||
|
||
# System architecture | ||
|
||
Here is some content | ||
|
||
## Overview | ||
|
||
And some more | ||
|
||
## Security model | ||
|
||
And even more |
27 changes: 27 additions & 0 deletions
27
...data/author/governed_folders/good_instance_with_template_type/network_test_1.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,27 @@ | ||
--- | ||
authors: | ||
- Tim | ||
- Jane | ||
- Sally | ||
owner: Joe | ||
valid: | ||
from: 2020-01-01 | ||
to: 2099-12-31 | ||
x-trestle-template-type: network | ||
--- | ||
|
||
# Network architecture | ||
|
||
Lots of stuff about the network overall including some diagrams. | ||
|
||
## External interconnections | ||
|
||
Here I put a table which describes the connections beyond my audit boundary with 3rd parties. | ||
|
||
## Corporate interconnections | ||
|
||
Here I describe interconnections into corporate systems. | ||
|
||
## Out of scope interconnections | ||
|
||
Here I describe interconnections that are out of scope because they occur outside of the current audit boundary. |
27 changes: 27 additions & 0 deletions
27
...data/author/governed_folders/good_instance_with_template_type/network_test_2.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,27 @@ | ||
--- | ||
authors: | ||
- Tim | ||
- Jane | ||
- Sally | ||
owner: Joe | ||
valid: | ||
from: 2020-01-01 | ||
to: 2099-12-31 | ||
x-trestle-template-type: network | ||
--- | ||
|
||
# Network architecture | ||
|
||
Lots of stuff about the network overall including some diagrams. | ||
|
||
## External interconnections | ||
|
||
Here I put a table which describes the connections beyond my audit boundary with 3rd parties. | ||
|
||
## Corporate interconnections | ||
|
||
Here I describe interconnections into corporate systems. | ||
|
||
## Out of scope interconnections | ||
|
||
Here I describe interconnections that are out of scope because they occur outside of the current audit boundary. |
22 changes: 22 additions & 0 deletions
22
...hor/governed_folders/good_instance_without_template_type/architecture_test_1.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,22 @@ | ||
--- | ||
authors: | ||
- Tim | ||
- Jane | ||
- Sally | ||
owner: Joe | ||
valid: | ||
from: 2020-01-01 | ||
to: 2099-12-31 | ||
--- | ||
|
||
# System architecture | ||
|
||
Here is some content | ||
|
||
## Overview | ||
|
||
And some more | ||
|
||
## Security model | ||
|
||
And even more |
22 changes: 22 additions & 0 deletions
22
...hor/governed_folders/good_instance_without_template_type/architecture_test_2.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,22 @@ | ||
--- | ||
authors: | ||
- Tim | ||
- Jane | ||
- Sally | ||
owner: Joe | ||
valid: | ||
from: 2020-01-01 | ||
to: 2099-12-31 | ||
--- | ||
|
||
# System architecture | ||
|
||
Here is some content | ||
|
||
## Overview | ||
|
||
And some more | ||
|
||
## Security model | ||
|
||
And even more |
26 changes: 26 additions & 0 deletions
26
...a/author/governed_folders/good_instance_without_template_type/network_test_1.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,26 @@ | ||
--- | ||
authors: | ||
- Tim | ||
- Jane | ||
- Sally | ||
owner: Joe | ||
valid: | ||
from: 2020-01-01 | ||
to: 2099-12-31 | ||
--- | ||
|
||
# Network architecture | ||
|
||
Lots of stuff about the network overall including some diagrams. | ||
|
||
## External interconnections | ||
|
||
Here I put a table which describes the connections beyond my audit boundary with 3rd parties. | ||
|
||
## Corporate interconnections | ||
|
||
Here I describe interconnections into corporate systems. | ||
|
||
## Out of scope interconnections | ||
|
||
Here I describe interconnections that are out of scope because they occur outside of the current audit boundary. |
26 changes: 26 additions & 0 deletions
26
...a/author/governed_folders/good_instance_without_template_type/network_test_2.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,26 @@ | ||
--- | ||
authors: | ||
- Tim | ||
- Jane | ||
- Sally | ||
owner: Joe | ||
valid: | ||
from: 2020-01-01 | ||
to: 2099-12-31 | ||
--- | ||
|
||
# Network architecture | ||
|
||
Lots of stuff about the network overall including some diagrams. | ||
|
||
## External interconnections | ||
|
||
Here I put a table which describes the connections beyond my audit boundary with 3rd parties. | ||
|
||
## Corporate interconnections | ||
|
||
Here I describe interconnections into corporate systems. | ||
|
||
## Out of scope interconnections | ||
|
||
Here I describe interconnections that are out of scope because they occur outside of the current audit boundary. |
59 changes: 59 additions & 0 deletions
59
.../data/author/governed_folders/instance_with_diff_heading_levels/architecture.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,59 @@ | ||
--- | ||
authors: | ||
- Tim | ||
- Jane | ||
- Sally | ||
owner: Joe | ||
valid: | ||
from: 2020-01-01 | ||
to: 2099-12-31 | ||
--- | ||
|
||
# Vulnerability Management (VULN) Defect Checks | ||
## 0. Vulnerability Management Workflow | ||
### 0.1 Data Sources | ||
### 0.2 Fetchers | ||
### 0.3 Data Store | ||
### 0.4 Policy Engine | ||
### 0.5 Ticketing System | ||
## 1. Facts Data Model | ||
### 1.1 Devices | ||
#### Server | ||
#### KubernetesCluster | ||
#### ContainerImage | ||
### 1.2 Vulnerabilities | ||
#### ResourceScan | ||
#### ResourceScanFinding | ||
#### ResourceScanResult | ||
### 1.3 Thresholds | ||
#### CISOOverride | ||
#### CISAKEV | ||
### 1.4 Risks | ||
#### VulnDeviations | ||
### 1.5 Scanner Definition | ||
#### ScannerConfiguration | ||
## 2. Defect Checks | ||
### Sub-capability: Reduce Software/ Firmware Vulnerabilities | ||
#### Vulnerable Software/ Firmware | ||
##### Purpose | ||
##### Assessment Criteria | ||
###### Inputs | ||
###### Rules | ||
####### vuln_prod_os_scan_duedate_check | ||
######## Type | ||
######## Rationale Statement | ||
######## Impact Statement | ||
######## Implementation Description | ||
######## Audit Procedure(s) | ||
######## Remediation Procedure(s) | ||
######## Parameters | ||
####### vuln_prod_os_scan_warning_duedate_check_warning | ||
######## Type | ||
######## Rationale Statement | ||
######## Impact Statement | ||
######## Implementation Description | ||
######## Audit Procedure(s) | ||
######## Remediation Procedure(s) | ||
######## Parameters | ||
###### Additional Outputs | ||
##### Assessment Objectives |
30 changes: 30 additions & 0 deletions
30
tests/data/author/governed_folders/template_folder_headling_levels/architecture.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,30 @@ | ||
--- | ||
authors: | ||
- Tim | ||
- Jane | ||
- Sally | ||
owner: Joe | ||
valid: | ||
from: 2020-01-01 | ||
to: 2099-12-31 | ||
--- | ||
|
||
# { Security Capability Name } Defect Checks | ||
## 1. Facts Data Model | ||
### Sub-Capability: { _insert name of subcapability_} | ||
## 2. Defect Checks | ||
### Sub-capability: { _insert sub-capability name_} | ||
#### { _insert defect check name_} | ||
##### Assessment Criteria | ||
###### Inputs | ||
###### Rules | ||
####### { Rule Name} | ||
######## Type | ||
######## Rationale Statement | ||
######## Impact Statement | ||
######## Implementation Description | ||
######## Audit Procedure(s) | ||
######## Remediation Procedure(s) | ||
######## Parameters | ||
###### Additional Outputs | ||
##### Assessment Objectives |
Oops, something went wrong.