edgexfoundry / edgexfoundry/edgex-docs

Provide assurance case why EdgeX security requirements are met [ossf silver]

Open
#900 0 comments 0 reactions 0 assignees View on GitHub
documentation
Dominant language
HTML
Stars
44
Forks
88
PR merge metrics
No merged PRs in 30d

Description

# 📚 Docs or Wiki Bug Report

### Description [**REQUIRED**]

OpenSSF Silver Badge requirement:
_The project MUST provide an assurance case that justifies why its security requirements are met. The assurance case MUST include: a description of the threat model, clear identification of trust boundaries, an argument that secure design principles have been applied, and an argument that common implementation security weaknesses have been countered. (URL required) [assurance_case]
An assurance case is "a documented body of evidence that provides a convincing and valid argument that a specified set of critical claims regarding a system’s properties are adequately justified for a given application in a given environment" (["Software Assurance Using Structured Assurance Case Models", Thomas Rhodes et al, NIST Interagency Report 7608](https://www.nist.gov/publications/software-assurance-using-structured-assurance-case-models)). Trust boundaries are boundaries where data or execution changes its level of trust, e.g., a server's boundaries in a typical web application. It's common to list secure design principles (such as Saltzer and Schroeer) and common implementation security weaknesses (such as the OWASP top 10 or CWE/SANS top 25), and show how each are countered. The [BadgeApp assurance case](https://github.com/coreinfrastructure/best-practices-badge/blob/master/doc/security.md) may be a useful example. This is related to documentation_security, documentation_architecture, and implement_secure_design._

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.