Closed lukas-krecan closed 1 month ago
Sorry, added
For this one, we should probably change the dictionary definition of evidences
from:
I feel as if evidences
should just be a Profile instead to give flexibility across the entirety of the schema, similar to how OSINT
is now - since any type of event could be implicated in a greater detection or case management context.
When reporting Compliance Finding, we want to specify which File, API or Device caused us to trigger the finding. For example, if we have a terraform file which creates an AWS ec2 instance with public 22 port, we want to point to the file where we found the issue.
Description of changes: