mojaloop / project

Repo to track product development issues for the Mojaloop project.
Other
23 stars 15 forks source link

Review NIST Special Publication (SP) 800-171 and 172 and identify alignment areas with Mojaloop #2051

Closed godfreykutumela closed 3 years ago

godfreykutumela commented 3 years ago

Goal:

As a OSS Developer

I want to review NIST Special Publication (SP) 800-171 and 172

so that I can identify alignment areas with Mojaloop.

Acceptance Criteria:

Complexity: <Low Uncertainty: Low


Tasks:

Done

Pull Requests:

Follow-up:

Dependencies:

Accountability:

godfreykutumela commented 3 years ago

I have reviewed NIST 171 and the only section I recommend we baseline against is section 3.3 AUDIT AND ACCOUNTABILITY. To be further explored as part of https://github.com/mojaloop/project/issues/2029 NIST.SP.800-171r2.pdf

godfreykutumela commented 3 years ago

Review Summary

NIST 172 enhanced security requirements focus on the following key elements, which are essential to addressing the APT:

The above recommendations have to be addressed as part of switch architecture and hub operational processes in order to fully embrace the APT requirements of NIST 172.

Flexibility in Applying NIST 172

Certain enhanced security requirements may be too difficult or cost-prohibitive for organizations to meet internally. In these situations, the use of external service providers21 can be leveraged to satisfy the requirements. The services include but are not limited to:

Finally, specific implementation guidance associated with the enhanced security requirements is beyond the scope of this publication. Organizations have maximum flexibility in the methods, techniques, technologies, and approaches used to satisfy the enhanced security requirements

godfreykutumela commented 3 years ago

IAM requirements in section 3.5 should be referenced as part of our IAM architecture.