cloud-gov / compliance

Compliance automation for cloud.gov
Other
36 stars 22 forks source link

Update our key SSP diagrams (Data Flow Diagram and Network Diagram) #167

Closed brittag closed 8 years ago

brittag commented 8 years ago

In order for compliance reviewers and other documentation readers to understand our system, the cloud.gov diagrams in our SSP need to be very accurate and up to date.

How to do this:

The best available diagrams that we have right now are in this folder. The two key diagrams are the Figure 10-4 Data Flow Diagram and the Cloud-gov-boundary diagram (called Figure 10-1 Network Diagram in our SSP). Both of these need various updates. We don't seem to have source files for these (see this thread).

For example, some updates we probably need for Data Flow:

And for example, some updates we probably need for the Boundary / Network Diagram:

Terminology should match the terminology we're using in the SSP. The latest SSP draft is here. Ideally the capitalization/spelling should match our content guide for consistency (nice to have; not a blocker). Please ask me if you have questions about keeping our terminology consistent. :D

Acceptance Criteria

After this is done, we will need to make sure there are large versions available to readers, which is a separate task tracked at https://github.com/18F/cg-compliance/issues/166.

brittag commented 8 years ago

cc @mogul since he'll need these updated diagrams for the JAB product briefing (https://github.com/18F/cg-product/issues/153)

mogul commented 8 years ago

If we need to recreate any of them: Britta suggests that we use Google Drawings since it enables us to collaborate, leave comments, etc. and still export as SVG for inclusion in repositories. There's a template with AWS icons, if that's helpful. I'll ask only that we include a link back to the current drawing's URL somewhere inconspicuous (either in the drawing footer or in the .svg itself) since the exported SVG is not the canonical source.

mogul commented 8 years ago

Since I'll be coming off of vacation directly into DC the night before our meeting, please just replace the appropriate diagrams/links in the FedRAMP product briefing presentation directly!

mogul commented 8 years ago

Just to be explicit: We need to update these by next Tuesday, 8/2!

brittag commented 8 years ago

We also made a cloud.gov team folder for system diagrams.

Noting followup tasks as a checklist for reference:

mogul commented 8 years ago

A couple other points not previously captured here:

brittag commented 8 years ago

Adam updated both of these. 🎉 They are in this Diagrams folder - I added a subfolder called "Latest key diagrams used in SSP" and put the two final versions in there as an effort at clarity.

I've updated these in the FedRAMP product briefing presentation. I've also updated these in the SSP, and I've added the latest versions to the SSP Attachments folder.

marshallpmp commented 7 years ago

Can anyone share a sample boundary diagram, that shows the level of detail needed? New to this thread (and Github in general). marshall_pmp@comcast.net

LinuxBozo commented 7 years ago

@marshallpmp All of our current diagrams are available to view at https://diagrams.fr.cloud.gov, and the source at https://github.com/18F/cg-diagrams