Open aaronlippold opened 5 years ago
This issue has evolved as we have evolved the HDF standard. Please consolidate this ticket generally:
many of these items are either done or in progress ... if we want ... we should break these into issues and close this one.
I know I am repeating myself in various issues on this but I hope this collects a lot of these ideas.
We should also write up a 'HDF Profile and Control' Stype guide that would help lay out a lot of these 'standards' that we have established.
I am sure many of these will break out into smaller sub-issues on the vaious projects.
I am also very sure that all this stuff will have to go into the guide referenced above.
The below are used in many overlays and tailoring profiles
/vulnerability/
vulnerability_discussion ( in xccdf, csv and xls for example )
/justification/
caveat
etc.
[ ] That we allow for allow for three new types: desc, justification, caveat, discussion a. That
caveat
and orjustification
are appended to the 'Finding Details' in all the converters and Heidmall Applications b. We also allow for/*caveat*/
and/*justification*/
- such thatmyorg-/_caveat
is discovered. c. thatdiscussion
or/*discussion*/
be appended to the bottom of the general description - such thatvulnerability_discussion
would be discovered.[ ] That we support both text based impacts and numeric based impacts in our parsing and conversations to allow for better user interface ( in xccdf, csv, xccdf etc. )
[x] That we update
inspec_tools
andheimdall_tools
to use the new sub-sections[ ] That the sub-descriptions are grouped and created together in the control logically:
desc [ req ]
title [ req ]
impact [ req ]
desc vuln (opt)
vuln (opt)
desc caveat (opt)
desc caveat (opt)
{ tags, nist: [reg || UM-1] => if STIG || CIS cci: [req || N/A] => if STIG || CIS cis_cdc [ req || N/A ] => IF CIS }
desc check [ req ]
desc fix [ req ]
ref *
(opt)describe blocks
[ req ]