18F / dashboard

DEPRECATED: A site to track our projects' status and much, much more...
Other
44 stars 25 forks source link

Research: user needs for compliance director #304

Open ultrasaurus opened 8 years ago

ultrasaurus commented 8 years ago

Goal: be able to automatically update the dashboard about when projects are preparing for ATO and/or in review, and when ATO is granted and any relevant info

@NoahKunin has expectations about dashboard serving compliance needs

We would like to have a detailed understanding of what exactly is needed, how dashboard might serve those needs and which subset of projects apply

There is a file (system-security-plan.yml) in some projects that seems to be related to the ATO status of that project

Questions about fields in system-security-plan.yml:

mtorres253 commented 8 years ago

I will check the compliance toolkit channel to get more information about this request. @NoahKunin is on vacation but will circle with him when he gets back.

DavidEBest commented 8 years ago

@afeld is writing up a page on SSPs here: https://github.com/18F/before-you-ship/pull/67

afeld commented 8 years ago

@ultrasaurus Hopefully most of your questions should be answered in there...would love feedback!

Why wouldn't the ATO status be recorded here?

SSPs are provided in order for the ATO to be completed. That being said, I think the intention is that it should be kept up-to-date by the project team, so we could add one if folks think it would be useful.

How do we consolidate if possible the data here with the data in .about.yml?

Good point! We can change the schema however we want, so if you have specific suggestions, let us know!

/cc @geramirez