This implementation automates reporting to verify compliance with GC Cloud Guardrails. SSC and TBS review the results. Cette mise en œuvre automatise la production de rapports afin de vérifier la conformité aux mesures de sécurité infonuagique du GC. SPC et SCT examinent les résultats.
Describe the bug
Can only see one control that relates to the Privileged Account Management Plan in Guardrail 2. Additionally, there are some file formats we are not supporting for documents that aren't "read" by our tool. For example this file could be uploaded as a .pdf and the department would be non-compliant.
To Reproduce
Steps to reproduce the behavior:
Go to v2.1.0
Dev or Test
Expected behavior
Expected to see two controls in GR2 that rely on the Privileged Account Management Plan existing.
Privileged Account Management Plan (Lifecycle of Account Management) (M)
Privileged Account Management Plan (Least Privilege Role Assignment) (M)
Screenshots
Questions
Are we going to have only one control for both validations?/ is this intentional?
Can we be more flexible on format options for files that aren't being read by the CaC tool?
We can either use one control (only one attestation file is required) for both validations or two separate controls (Need two attestation files with different names). The reference ticket 1 and ticket 2
Need to discuss the requirement for all attestation files. Currently, for a specific control pdf is supported; not for all control.
One document attestation for both validations would be great. i.e., we should still see the 2 itemnames for both in the workbook and that they pass when that one file has been uploaded.
Agreed that we should have a discussion. Overall thought is that we should only restrict format for files that our solution has to read/ grab information out of. to be continued..
Describe the bug Can only see one control that relates to the Privileged Account Management Plan in Guardrail 2. Additionally, there are some file formats we are not supporting for documents that aren't "read" by our tool. For example this file could be uploaded as a .pdf and the department would be non-compliant.
To Reproduce Steps to reproduce the behavior:
Expected behavior Expected to see two controls in GR2 that rely on the Privileged Account Management Plan existing.
Screenshots
Questions