Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Document secure development practices as OSCAL component #18

Open
7 tasks
aj-stein-gsa opened this issue Oct 10, 2024 · 1 comment
Open
7 tasks

Document secure development practices as OSCAL component #18

aj-stein-gsa opened this issue Oct 10, 2024 · 1 comment
Labels
enhancement New feature or request

Comments

@aj-stein-gsa
Copy link
Contributor

User Story

As a software developer, system engineer, or architect that will want to use this library and its dependencies for integration into a part of my system, I want clear documentation about the security process and characteristics of the development software and development process. Ideally, we want to see this in the form of an OSCAL component so we can use documentation and evidence to also integrate into our own security documentation.

Goals

  • Decide on secure software practices
  • Decide on secure software deployment (development and operations)
  • Act on the above
  • Document them with OSCAL components

Dependencies

We probably need to threat model this system after considering the other components: metaschema-java, liboscal-java, and their combination with the oscal-cli as we use it today.

Acceptance Criteria

  • All website and readme documentation affected by the changes in this issue have been updated.
  • A Pull Request (PR) is submitted that fully addresses the goals of this User Story. This issue is referenced in the PR.
  • The CI-CD build process runs without any reported errors on the PR. This can be confirmed by reviewing that all checks have passed in the PR.

Revisions

No response

@aj-stein-gsa aj-stein-gsa added the enhancement New feature or request label Oct 10, 2024
@wandmagic
Copy link
Collaborator

see #23

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants