bmarsh9 / gapps

Security compliance platform - SOC2, CMMC, ASVS, ISO27001, HIPAA, NIST CSF, NIST 800-53, CSC CIS 18, PCI DSS, SSF tracking. https://gapps.darkbanner.com
Other
440 stars 99 forks source link

Sample selection #23

Open SupaChop opened 1 year ago

SupaChop commented 1 year ago

I think it makes sense to include sample selection in the software for evidence control and management. This can be done two ways, the easy way would be to implement a numbers tool, which allows input of a range of numbers (rows) and the number of, or percentage or rows.

The second more intensive option would be to allow import of an excel or csv and the same range input mentioned above, but have the software automatically the select the samples themselves from the evidence.

Ideally these samples could then be linked to specific controls, but this could be considered a separate issues.