GSA / data.gov

Main repository for the data.gov service
https://data.gov
Other
607 stars 98 forks source link

[research 3d]: Malware-detection sidecar buildpack for cloud.gov apps #1716

Open mogul opened 4 years ago

mogul commented 4 years ago

User Story

In order to satisfy the requirements of NIST 800-53 Rev4 SI-3 for data.gov components running in cloud.gov, the data.gov team wants to achieve malicious code detection at the application instance level by implementing a malware-detection sidecar buildpack.

Acceptance Criteria

Background

Sidecar buildpacks enable the implementation of application level detection of malicious code in Cloud Foundry apps. We should use this capability to fill this compliance gap for data.gov and potentially many other cloud.gov tenants.

Security Considerations (required)

This change implements the description from control SI-3 in the data.gov SSP.

Sketch/options to consider

adborden commented 3 years ago

I suggest we treat this as a 3 day research story.... although it already looks bigger than 3 days of research.