mitre / heimdall2

Heimdall Enterprise Server 2 lets you view, store, and compare automated security control scan results.
Other
204 stars 61 forks source link

[EPIC] Checklist Mapper #4195

Open Hookwitz opened 1 year ago

Hookwitz commented 1 year ago

This epic is to help keep track of the open issues regarding checklist mapping <-> ohdf format

Any new issues/bugs should be linked to this for tracking until the feature has been fully implemented. When feature is complete, verify it resolved the issues attached and close them out.

From the heimdall repo:

V1

4047 Heimdall JSON to CKL BUG

3051 Move export ckl function within hdf-converters

5554 STIG name

V2

3578 Combine multiple HDF to one CKL

5634 Better input validation on export modal

4604 Test and improve nist to cci mapping

5688 Add Help text to export modal

5689 Research classification settings in checklist export

5690 Update source for checklist export

4523 Update version comment name in checklist export

5694 Investigate comment versioning

GUI

3719 Switch from Results page to Checklist page instead of exporting and re-loading

SAF CLI repo

The convert functions need to be connected to the hdf-converters library #1075 SAF-CLI Fix hdf2ckl as it produces invalid CKL files #385 SAF-CLI Move hdf2ckl function with hdf-converters

Hookwitz commented 1 year ago

Closed

4204 Tracking Forward Checklist to HDF mapper/conversion issue

Hookwitz commented 1 year ago

tag.gid should be mapped to Vuln_Num Also, the Vuln_discussion should include the "satisifes" line for the control example in #4047 - currently it is split out into a tag and needs to be reintroduced into the discussion.