GSA / data.gov

Main repository for the data.gov service
https://data.gov
Other
621 stars 98 forks source link

Update SSPP per Assessment Findings #4922

Open tdlowden opened 1 week ago

tdlowden commented 1 week ago

Date of report: 9/12/24 Severity: Moderate Due date: 12/1/24

Due date is based on severity and described in RA-5. 15-days for Critical, 30-days for High, and 90-days for Moderate and lower.

Brief description

Per the data.gov ATO assessment, various changes need to be made to the SSP. More at Finding 3 https://docs.google.com/document/d/1JsNFKCXRcIjp6V0jI6Q4YLu7kngDiQMysv9fCii9lFk/edit

tdlowden commented 1 week ago

In my initial pass, I was able to address 14 of 24 suggestions. Will schedule time with developers to resolve the remaining 10.

tdlowden commented 1 day ago

All recommendations addressed with suggestions at https://docs.google.com/document/d/1CofqNr-cd9GEmdrB4gf9dSd7GjHwcW5G3-3K1n4bTaY/edit?tab=t.0#heading=h.17dp8vu

@hkdctol should we notify the security team?