bcgov / bcgov/cloud-pathfinder

Add Custom policy for Threat Prevention in learning mode suggested by CP Security Engineer

Open
#2,720 0 comments 0 reactions 0 assignees View on GitHub
Security
Dominant language
Jinja
Stars
2
Forks
7
PR merge metrics
No merged PRs in 30d

Description

**Describe the Issue**
To add custom policy for FW to assess our traffic for Threat Prevention.

**Additional Context**
- Forge, Assembly, and then Live ??
- Learning Mode
- Threat Emulation, Threat Extraction, Antibot, Antivirus, IPS
- Start from smaller scope

**Acceptance Criteria**
- [ ] the policy is activated
- [ ] learning mode generates some insight
A set of pre-defined requirement that need to be met in order to mark the user story as “done”. See below for team agreement details.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by clarifying the intended Forge, Assembly, and Live scope, the smaller initial traffic scope, and which Threat Prevention controls are required: Threat Emulation, Threat Extraction, Antibot, Antivirus, and IPS. Verify how the custom firewall policy is activated and how Learning Mode insights are observed. Done means the policy is active and Learning Mode has generated insight.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.