mitre / heimdall2

Heimdall Enterprise Server 2 lets you view, store, and compare automated security control scan results.
Other
207 stars 61 forks source link

Display all "non-standard" sub-descriptions in same locations as "caveat" #2295

Open ejaronne opened 2 years ago

ejaronne commented 2 years ago

Currently we have a convention whereby we overlay using a "caveat" subdescription which is placed at top of test results tab and near the top of items in the details tab. I see others in the field overlaying with their own sub-descriptions (such as "re-cast"), and I'd like to automatically include those in the same location as we do with Caveat.

No, I won't name what those field subdescriptions are. Rather, we can reasonably start building a set of the standard ones that come from the STIG or CIS and anything else is considered additional.

Do not try to anticipate every corner case.

ejaronne commented 2 years ago

Phase 2: Do similar for hdf2asff converter

Phase 3: Update CAAT and csv exporters accordingly.

This is about making validation content relevant and preserving context.

camdenmoors commented 2 years ago

This should show reference fields inside the details tab

camdenmoors commented 2 years ago

To clarify, this is for adding non-standard descriptions to the same location as caveat as well as adding all descriptions to the Details tab.

Related PR #2681 adds justification and rationale.

image