redhat-cop / pathfinder

Apache License 2.0
41 stars 37 forks source link

RFE: Add mitigation option to each question #207

Open edseymour opened 4 years ago

edseymour commented 4 years ago

Following an application assessment it, the application may be shown as being unsuitable for migration.

However, it is possible that steps, or strategies, are put in place, which render this judgement obsolete and making the migration of the application possible.

This change would add an option to answered questions, that would allow the risk to migration to be downgraded, either partially to amber, or fully to green. It would make sense to include a comment option so that the downgrade could include some contextual reasoning for the change.

For example, an application would be subject to regulatory law, such as PCI, and therefore appears with at least one 'red' answer. The company decides to make the platform PCI compliant, adopting Red Hat's PCI compliance guidance. The application's assessment is revised with a mitigation note being added to this question, and a reason stating that the platform will be PCI compliant. The application report no longer shows the application as not appropriate for migration, and the associated aggregated bubble chart shifts the application to the right.