@@ -124,10 +124,24 @@ Build and Deployment:
124124 usefulness : 3
125125 level : 2
126126 implementation :
127- - Container technology automatically creates a hash for images, which can be
128- used.
129- - Immutable images are an other way, e.g. by using a registry, which doesn't
130- allow overriding of images.
127+ - uuid : 9368abfb-cf37-477a-9091-a804d2de9148
128+ name : Signing of containers
129+ tags :
130+ - signing
131+ - container
132+ - build
133+ url : https://www.aquasec.com/cloud-native-academy/supply-chain-security/container-image-signing/
134+ description : Container technology automatically creates a hash for images,
135+ which can be used.
136+ - uuid : 638b3691-c9a5-45fa-9ba8-e40aeea32766
137+ name : Immutable images
138+ tags :
139+ - deployment
140+ - container
141+ - build
142+ url : https://kubernetes.io/blog/2022/09/29/enforce-immutability-using-cel/#immutablility-after-first-modification
143+ description : Immutable images are an other way, e.g. by using a registry,
144+ which doesn't allow overriding of images.
131145 dependsOn :
132146 - Defined build process
133147 references :
@@ -2463,7 +2477,7 @@ Culture and Organization:
24632477 B : false
24642478 C : false
24652479 Determining the protection requirement :
2466- uuid : 123e4567-e89b-12d3-a456-426614174000
2480+ uuid : 72737130-472c-4984-80f8-9ab2f1c2ed5d
24672481 risk : " Not defining the protection requirement of applications can lead to wrong
24682482 prioritization, delayed remediation of \n critical security issues, increasing
24692483 the risk of exploitation and potential damage to the organization."
@@ -2519,7 +2533,7 @@ Culture and Organization:
25192533 - 5.13
25202534 - 5.1
25212535 openCRE :
2522- - https://www.opencre.org/rest/v1/standard/DevSecOps+Maturity+Model+(DSOMM)/Process/123e4567-e89b-12d3-a456-426614174000
2536+ - https://www.opencre.org/rest/v1/standard/DevSecOps+Maturity+Model+(DSOMM)/Process/72737130-472c-4984-80f8-9ab2f1c2ed5d
25232537 tags :
25242538 - vulnerability-mgmt
25252539 - metrics
@@ -5845,7 +5859,7 @@ Test and Verification:
58455859 B : false
58465860 C : false
58475861 Integration in development process :
5848- uuid : 123e4567-e89b-12d3-a456-426614174000
5862+ uuid : aaffa73f-59f6-4267-b0ab-732f3d13e90d
58495863 risk : " Not integrating vulnerability handling into the development process may
58505864 result in product teams ignoring findings. \n\n Security joke: We will gain
58515865 100% false negatives."
@@ -5919,7 +5933,7 @@ Test and Verification:
59195933 - 5.13
59205934 - 5.1
59215935 openCRE :
5922- - https://www.opencre.org/rest/v1/standard/DevSecOps+Maturity+Model+(DSOMM)/Consolidation/123e4567-e89b-12d3-a456-426614174000
5936+ - https://www.opencre.org/rest/v1/standard/DevSecOps+Maturity+Model+(DSOMM)/Consolidation/aaffa73f-59f6-4267-b0ab-732f3d13e90d
59235937 tags :
59245938 - vulnerability-mgmt
59255939 - vmm-measurements
@@ -6166,7 +6180,7 @@ Test and Verification:
61666180 B : false
61676181 C : false
61686182 Treatment of defects per protection requirement :
6169- uuid : 123e4567-e89b-12d3-a456-426614174000
6183+ uuid : 2b7cc923-bdaf-43e3-8fb4-a995b7783969
61706184 risk : " Not defining the protection requirement of applications can lead to wrong
61716185 prioritization, delayed remediation of \n critical security issues, increasing
61726186 the risk of exploitation and potential damage to the organization."
@@ -6227,7 +6241,7 @@ Test and Verification:
62276241 - 5.13
62286242 - 5.1
62296243 openCRE :
6230- - https://www.opencre.org/rest/v1/standard/DevSecOps+Maturity+Model+(DSOMM)/Consolidation/123e4567-e89b-12d3-a456-426614174000
6244+ - https://www.opencre.org/rest/v1/standard/DevSecOps+Maturity+Model+(DSOMM)/Consolidation/2b7cc923-bdaf-43e3-8fb4-a995b7783969
62316245 tags :
62326246 - vulnerability-mgmt
62336247 - metrics
0 commit comments