bcgov / nr-forests-access-management

Authorization solution for BC natural resource sector
Apache License 2.0
8 stars 2 forks source link

Data Collection To Support the STRA for FAM #468

Closed ArogeG closed 1 year ago

ArogeG commented 1 year ago

Describe the task The MISO recommends that we conduct a preliminary STRA for FAM to support a faster completion and approval of FAM's STRA. This will require the following

  1. STRIDE/NIST
  2. ISO 27000 (To be confirmed)
  3. OCIO Defensible security checklist

Acceptance Criteria

https://app.zenhub.com/files/486378283/40de0ecb-b7df-49de-8f72-611587697394/download

https://app.zenhub.com/files/486378283/e96fe6ef-662f-49e2-bbc9-00c55db52a05/download

Additional context Here is the email from the BCSC Security team with the requirements for STRA, SOAR and other tasks.https://app.zenhub.com/files/486378283/c76b1bd4-b8a1-4e3b-aaa4-6118022aab89/download

webgismd commented 1 year ago

For WAVA istore requests we can go through Lucas and the NRIDs TIER 3 team to request.

basilv commented 1 year ago

Use STRIDE or NIST, not both. Unclear if ISO is separately needed or an option. OCIO checklist is required as well.

gormless87 commented 1 year ago

Closing as draft STRA has been prepared by contract resources.

WAVA completed.