OWASP / OWASP/OpenCRE

NIST 800-53 - more granular mapping on control enhancement level

Open
#589 4 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
180
Forks
137
Avg merge
3d 23h
Merged PRs (30d)
21

Description

Regarding NIST 800-53 in OpenCRE I noticed that the mapping is created only on the control level so it does not include control enhancements e.g., AC-2 is linked to 724-770 but AC-2(5) "Inactivity logout" is not linked to any other though it could be linked to 065-782 "Ensure session timeout (soft/hard)".
Is there a plan to create a NIST 800-53 mapping at this level in the future, or would you be open to contributions regarding this granularity? I mean it's surely more maintenance and in general mapping at the right abstraction layer between different frameworks is not a trivial question but I think it would make sense to match up sub-controls/control enhancements this way due to the fact that NIST 800-53 is a widely used framework.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files or tests are named. Start by locating the current NIST 800-53 control-level mapping and compare the AC-2 to 724-770 example with AC-2(5) and 065-782. Done requires an agreed scope and abstraction approach for enhancement-level mappings before implementation can begin.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.