cncf / cncf/toc

[Initiative]: Cloud Native Security Controls Catalog Refresh

Open
#1,910 14 comments 6 reactions 1 assignee Claimed by @jpower432 View on GitHub
kind/initiative tag/security-and-compliance
Dominant language
HTML
Stars
1.9k
Forks
724
Avg merge
6d 12h
Merged PRs (30d)
4

Description

### Name

Cloud Native Security Controls Catalog Refresh

### Short description

Review and update the Cloud Native Security Controls Catalog

### Responsible group

TAG Security and Compliance

### Does the initiative belong to a subproject?

No

### Subproject name

_No response_

### Primary contact

Jenn Power (@jpower432)

### Additional contacts

@eddie-knight

### Initiative description

This initiative focuses on refreshing the [Cloud Native Security Controls Catalog](https://github.com/cncf/tag-security/tree/main/community/working-groups/archive/controls). The original catalog was created to provide specific, actionable controls for engineers, going beyond the high-level guidance found in the Cloud Native Security Whitepaper (CNSWP) and the Software Supply Chain Security Paper (SSCSP). The planned activities in this initiative would continue the next phase of work described in the [Phase One accouncement](https://github.com/cncf/tag-security/blob/main/community/working-groups/archive/controls/phase-one-announcement.md) to support automated assessment of the security controls.

Original TAG Security [issue](https://github.com/cncf/tag-security/issues/635) documenting the scope and purpose.

### Planned Activities

* **Define Catalog Use Cases**: Identify and document key use cases to clarify the catalog's value proposition. This includes determining if it can serve as a reference for project maintainers building best practice guides for their tools.

* **Assess Alignment with Existing Catalogs**: Analyze the catalog's overlap with the Open Source Project Security (OSPS) Baseline to ensure consistency and identify opportunities for collaboration.

* **Enable Automation**: Convert the current source of truth for control definitions to a format that can be easily managed in version control.
* The OpenSSF has a project called [`gemara`](https://github.com/ossf/gemara) that provides a library and schema for defining security controls catalogs in a way that can be authored directly while supporting OSCAL artifact generation that could be explored.

### Out of Scope

This initiative focuses on updating the existing controls and structure. Adding new control families and compliance framework mappings is out of scope and would be completed as a follow-on action if the Subproject is established.

### Deliverable(s) or exit criteria

The successful completion of this initiative is a decision on whether to continue maintaining the catalog under a Subproject. If the decision is to proceed, the following deliverables will be produced:

* A standardized, machine-readable security controls catalog ready for adoption by project maintainers and end-users.
* Guidance materials outlining the process for community contributions.
* A proposal to establish a Subproject for the ongoing maintenance and evolution of the catalog.

### Tracking document for meeting and progress

https://notes.cncf.io/64WPMKmDTOO2WnDI0av_Rw?view

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.