mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-04 02:04:06 +00:00
feat(compliance): add name for each compliance (#7920)
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
This commit is contained in:
co-authored by
Pepe Fagoaga
parent
2200e65519
commit
fbda66c6d1
@@ -6,6 +6,7 @@ All notable changes to the **Prowler API** are documented in this file.
|
||||
|
||||
### Added
|
||||
- Default JWT keys are generated and stored if they are missing from configuration [(#8655)](https://github.com/prowler-cloud/prowler/pull/8655)
|
||||
- `compliance_name` for each compliance [(#7920)](https://github.com/prowler-cloud/prowler/pull/7920)
|
||||
|
||||
### Changed
|
||||
- Now the MANAGE_ACCOUNT permission is required to modify or read user permissions instead of MANAGE_USERS [(#8281)](https://github.com/prowler-cloud/prowler/pull/8281)
|
||||
|
||||
@@ -225,6 +225,7 @@ def generate_compliance_overview_template(prowler_compliance: dict):
|
||||
# Build compliance dictionary
|
||||
compliance_dict = {
|
||||
"framework": compliance_data.Framework,
|
||||
"name": compliance_data.Name,
|
||||
"version": compliance_data.Version,
|
||||
"provider": provider_type,
|
||||
"description": compliance_data.Description,
|
||||
|
||||
@@ -182,6 +182,7 @@ paths:
|
||||
type: string
|
||||
enum:
|
||||
- id
|
||||
- compliance_name
|
||||
- framework_description
|
||||
- name
|
||||
- framework
|
||||
@@ -8739,6 +8740,8 @@ components:
|
||||
properties:
|
||||
id:
|
||||
type: string
|
||||
compliance_name:
|
||||
type: string
|
||||
framework_description:
|
||||
type: string
|
||||
name:
|
||||
@@ -8752,6 +8755,7 @@ components:
|
||||
attributes: {}
|
||||
required:
|
||||
- id
|
||||
- compliance_name
|
||||
- framework_description
|
||||
- name
|
||||
- framework
|
||||
|
||||
@@ -239,6 +239,7 @@ class TestCompliance:
|
||||
Framework="Framework 1",
|
||||
Version="1.0",
|
||||
Description="Description of compliance1",
|
||||
Name="Compliance 1",
|
||||
)
|
||||
prowler_compliance = {"aws": {"compliance1": compliance1}}
|
||||
|
||||
@@ -248,6 +249,7 @@ class TestCompliance:
|
||||
"aws": {
|
||||
"compliance1": {
|
||||
"framework": "Framework 1",
|
||||
"name": "Compliance 1",
|
||||
"version": "1.0",
|
||||
"provider": "aws",
|
||||
"description": "Description of compliance1",
|
||||
|
||||
@@ -1959,6 +1959,7 @@ class ComplianceOverviewDetailSerializer(serializers.Serializer):
|
||||
|
||||
class ComplianceOverviewAttributesSerializer(serializers.Serializer):
|
||||
id = serializers.CharField()
|
||||
compliance_name = serializers.CharField()
|
||||
framework_description = serializers.CharField()
|
||||
name = serializers.CharField()
|
||||
framework = serializers.CharField()
|
||||
|
||||
@@ -3545,6 +3545,7 @@ class ComplianceOverviewViewSet(BaseRLSViewSet, TaskManagementMixin):
|
||||
),
|
||||
"name": requirement.get("name", ""),
|
||||
"framework": compliance_framework.get("framework", ""),
|
||||
"compliance_name": compliance_framework.get("name", ""),
|
||||
"version": compliance_framework.get("version", ""),
|
||||
"description": requirement.get("description", ""),
|
||||
"attributes": base_attributes,
|
||||
|
||||
@@ -7,6 +7,7 @@ All notable changes to the **Prowler SDK** are documented in this file.
|
||||
### Added
|
||||
- Support for AdditionalURLs in outputs [(#8651)](https://github.com/prowler-cloud/prowler/pull/8651)
|
||||
- Support for markdown metadata fields in Dashboard [(#8667)](https://github.com/prowler-cloud/prowler/pull/8667)
|
||||
- Add explicit "name" field for each compliance framework and include "FRAMEWORK" and "NAME" in CSV output [(#7920)](https://github.com/prowler-cloud/prowler/pull/7920)
|
||||
|
||||
### Changed
|
||||
- Update AWS Neptune service metadata to new format [(#8494)](https://github.com/prowler-cloud/prowler/pull/8494)
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "AWS-Account-Security-Onboarding",
|
||||
"Name": "AWS Account Security Onboarding",
|
||||
"Version": "",
|
||||
"Provider": "AWS",
|
||||
"Description": "Checklist when onboarding new AWS Accounts to existing AWS Organization.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "AWS-Audit-Manager-Control-Tower-Guardrails",
|
||||
"Name": "AWS Audit Manager Control Tower Guardrails",
|
||||
"Version": "",
|
||||
"Provider": "AWS",
|
||||
"Description": "AWS Control Tower is a management and governance service that you can use to navigate through the setup process and governance requirements that are involved in creating a multi-account AWS environment.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "AWS-Foundational-Security-Best-Practices",
|
||||
"Name": "AWS Foundational Security Best Practices",
|
||||
"Version": "",
|
||||
"Provider": "AWS",
|
||||
"Description": "The AWS Foundational Security Best Practices standard is a set of controls that detect when your deployed accounts and resources deviate from security best practices.",
|
||||
@@ -4730,4 +4731,4 @@
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "AWS-Foundational-Technical-Review",
|
||||
"Name": "AWS Foundational Technical Review",
|
||||
"Version": "",
|
||||
"Provider": "AWS",
|
||||
"Description": "The AWS Foundational Technical Review (FTR) assesses an AWS Partner's solution against a specific set of Amazon Web Services (AWS) best practices around security, performance, and operational processes that are most critical for customer success. Passing the FTR is required to qualify AWS Software Partners for AWS Partner Network (APN) programs such as AWS Competency and AWS Service Ready but any AWS Partner who offers a technology solution may request a FTR review through AWS Partner Central.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "AWS-Well-Architected-Framework-Reliability-Pillar",
|
||||
"Name": "AWS Well-Architected Framework Reliability Pillar",
|
||||
"Version": "",
|
||||
"Provider": "AWS",
|
||||
"Description": "Best Practices for the AWS Well-Architected Framework Reliability Pillar encompasses the ability of a workload to perform its intended function correctly and consistently when it’s expected to. This includes the ability to operate and test the workload through its total lifecycle.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "AWS-Well-Architected-Framework-Security-Pillar",
|
||||
"Name": "AWS Well-Architected Framework Security Pillar",
|
||||
"Version": "",
|
||||
"Provider": "AWS",
|
||||
"Description": "Best Practices for AWS Well-Architected Framework Security Pillar. The focus of this framework is the security pillar of the AWS Well-Architected Framework. It provides guidance to help you apply best practices, current recommendations in the design, delivery, and maintenance of secure AWS workloads.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "CIS",
|
||||
"Name": "CIS Amazon Web Services Foundations Benchmark v1.4.0",
|
||||
"Version": "1.4",
|
||||
"Provider": "AWS",
|
||||
"Description": "The CIS Benchmark for CIS Amazon Web Services Foundations Benchmark, v1.4.0, Level 1 and 2 provides prescriptive guidance for configuring security options for a subset of Amazon Web Services. It has an emphasis on foundational, testable, and architecture agnostic settings",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "CIS",
|
||||
"Name": "CIS Amazon Web Services Foundations Benchmark v1.5.0",
|
||||
"Version": "1.5",
|
||||
"Provider": "AWS",
|
||||
"Description": "The CIS Amazon Web Services Foundations Benchmark provides prescriptive guidance for configuring security options for a subset of Amazon Web Services with an emphasis on foundational, testable, and architecture agnostic settings.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "CIS",
|
||||
"Name": "CIS Amazon Web Services Foundations Benchmark v2.0.0",
|
||||
"Version": "2.0",
|
||||
"Provider": "AWS",
|
||||
"Description": "The CIS Amazon Web Services Foundations Benchmark provides prescriptive guidance for configuring security options for a subset of Amazon Web Services with an emphasis on foundational, testable, and architecture agnostic settings.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "CIS",
|
||||
"Name": "CIS Amazon Web Services Foundations Benchmark v3.0.0",
|
||||
"Version": "3.0",
|
||||
"Provider": "AWS",
|
||||
"Description": "The CIS Amazon Web Services Foundations Benchmark provides prescriptive guidance for configuring security options for a subset of Amazon Web Services with an emphasis on foundational, testable, and architecture agnostic settings.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "CIS",
|
||||
"Name": "CIS Amazon Web Services Foundations Benchmark v4.0.1",
|
||||
"Version": "4.0.1",
|
||||
"Provider": "AWS",
|
||||
"Description": "The CIS Amazon Web Services Foundations Benchmark provides prescriptive guidance for configuring security options for a subset of Amazon Web Services with an emphasis on foundational, testable, and architecture agnostic settings.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "CIS",
|
||||
"Name": "CIS Amazon Web Services Foundations Benchmark v5.0.0",
|
||||
"Version": "5.0",
|
||||
"Provider": "AWS",
|
||||
"Description": "The CIS Amazon Web Services Foundations Benchmark provides prescriptive guidance for configuring security options for a subset of Amazon Web Services with an emphasis on foundational, testable, and architecture agnostic settings.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "CISA",
|
||||
"Name": "CISA Cyber Essentials framework",
|
||||
"Version": "",
|
||||
"Provider": "AWS",
|
||||
"Description": "Cybersecurity & Infrastructure Security Agency's (CISA) Cyber Essentials is a guide for leaders of small businesses as well as leaders of small and local government agencies to develop an actionable understanding of where to start implementing organizational cybersecurity practices.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "ENS",
|
||||
"Name": "ENS RD 311/2022",
|
||||
"Version": "RD2022",
|
||||
"Provider": "AWS",
|
||||
"Description": "The accreditation scheme of the ENS (National Security Scheme) has been developed by the Ministry of Finance and Public Administrations and the CCN (National Cryptological Center). This includes the basic principles and minimum requirements necessary for the adequate protection of information.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "FedRAMP-Low-Revision-4",
|
||||
"Name": "FedRAMP Low Revision 4",
|
||||
"Version": "",
|
||||
"Provider": "AWS",
|
||||
"Description": "The Federal Risk and Authorization Management Program (FedRAMP) was established in 2011. It provides a cost-effective, risk-based approach for the adoption and use of cloud services by the U.S. federal government. FedRAMP empowers federal agencies to use modern cloud technologies, with an emphasis on the security and protection of federal information.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "FedRamp-Moderate-Revision-4",
|
||||
"Name": "FedRAMP Moderate Revision 4",
|
||||
"Version": "",
|
||||
"Provider": "AWS",
|
||||
"Description": "The Federal Risk and Authorization Management Program (FedRAMP) was established in 2011. It provides a cost-effective, risk-based approach for the adoption and use of cloud services by the U.S. federal government. FedRAMP empowers federal agencies to use modern cloud technologies, with an emphasis on the security and protection of federal information.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "FFIEC",
|
||||
"Name": "FFIEC Cybersecurity Assessment Tool framework",
|
||||
"Version": "",
|
||||
"Provider": "AWS",
|
||||
"Description": "In light of the increasing volume and sophistication of cyber threats, the Federal Financial Institutions Examination Council (FFIEC) developed the Cybersecurity Assessment Tool (Assessment), on behalf of its members, to help institutions identify their risks and determine their cybersecurity maturity.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "GDPR",
|
||||
"Name": "GDPR compliance framework",
|
||||
"Version": "",
|
||||
"Provider": "AWS",
|
||||
"Description": "The General Data Protection Regulation (GDPR) is a new European privacy law that became enforceable on May 25, 2018. The GDPR replaces the EU Data Protection Directive, also known as Directive 95/46/EC. It's intended to harmonize data protection laws throughout the European Union (EU). It does this by applying a single data protection law that's binding throughout each EU member state.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "GxP-21-CFR-Part-11",
|
||||
"Name": "GxP (Good Practices) 21 CFR Part 11",
|
||||
"Version": "",
|
||||
"Provider": "AWS",
|
||||
"Description": "GxP refers to the regulations and guidelines that are applicable to life sciences organizations that make food and medical products. Medical products that fall under this include medicines, medical devices, and medical software applications. The overall intent of GxP requirements is to ensure that food and medical products are safe for consumers. It's also to ensure the integrity of data that's used to make product-related safety decisions.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "GxP-EU-Annex-11",
|
||||
"Name": "GxP (Good Practices) EU Annex 11",
|
||||
"Version": "",
|
||||
"Provider": "AWS",
|
||||
"Description": "The GxP EU Annex 11 framework is the European equivalent to the FDA 21 CFR part 11 framework in the United States. This annex applies to all forms of computerized systems that are used as part of Good Manufacturing Practices (GMP) regulated activities. A computerized system is a set of software and hardware components that together fulfill certain functionalities. The application should be validated and IT infrastructure should be qualified. Where a computerized system replaces a manual operation, there should be no resultant decrease in product quality, process control, or quality assurance. There should be no increase in the overall risk of the process.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "HIPAA",
|
||||
"Name": "HIPAA compliance framework",
|
||||
"Version": "",
|
||||
"Provider": "AWS",
|
||||
"Description": "The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is legislation that helps US workers to retain health insurance coverage when they change or lose jobs. The legislation also seeks to encourage electronic health records to improve the efficiency and quality of the US healthcare system through improved information sharing.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "ISO27001",
|
||||
"Name": "ISO/IEC 27001 Information Security Management Standard 2013",
|
||||
"Version": "2013",
|
||||
"Provider": "AWS",
|
||||
"Description": "ISO (the International Organization for Standardization) and IEC (the International Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established by the respective organization to deal with particular fields of technical activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "ISO27001",
|
||||
"Name": "ISO/IEC 27001 Information Security Management Standard 2022",
|
||||
"Version": "2022",
|
||||
"Provider": "AWS",
|
||||
"Description": "ISO (the International Organization for Standardization) and IEC (the International Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established by the respective organization to deal with particular fields of technical activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "KISA-ISMS-P",
|
||||
"Name": "KISA ISMS compliance framework 2023",
|
||||
"Version": "2023",
|
||||
"Provider": "AWS",
|
||||
"Description": "The ISMS-P certification, established by KISA (Korea Internet & Security Agency), is a system where an independent certification body evaluates whether a company or organization's information security and privacy protection measures comply with certification standards, and grants certification. This helps organizations improve public trust in their services and respond effectively to increasingly complex cyber threats. The ISMS-P framework also provides comprehensive guidelines for systematically establishing, implementing, and managing information security and privacy protection.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "KISA-ISMS-P",
|
||||
"Name": "KISA ISMS compliance framework 2023 (Korean)",
|
||||
"Version": "2023-korean",
|
||||
"Provider": "AWS",
|
||||
"Description": "ISMS-P 인증은 한국인터넷진흥원(KISA)이 제정한 정보보호 및 개인정보보호 관리체계를 기반으로, 독립적인 심사기관이 기업이나 조직의 보안 및 개인정보 보호 활동이 인증 기준을 충족하는지 평가한 후 인증을 부여하는 제도입니다. 이를 통해 기업과 기관은 제공하는 서비스에 대한 대중의 신뢰를 높이고, 점점 복잡해지는 사이버 위협에 효과적으로 대응할 수 있습니다. 또한, ISMS-P는 정보보호와 개인정보 보호를 체계적으로 수립하고 운영할 수 있는 포괄적인 지침을 제공합니다.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "MITRE-ATTACK",
|
||||
"Name": "MITRE ATT&CK compliance framework",
|
||||
"Version": "",
|
||||
"Provider": "AWS",
|
||||
"Description": "MITRE ATT&CK® is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations. The ATT&CK knowledge base is used as a foundation for the development of specific threat models and methodologies in the private sector, in government, and in the cybersecurity product and service community.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "NIS2",
|
||||
"Name": "Network and Information Security Directive (Directive (EU) 2022/2555)",
|
||||
"Version": "",
|
||||
"Provider": "AWS",
|
||||
"Description": "ANNEX to the Commission Implementing Regulation laying down rules for the application of Directive (EU) 2022/2555 as regards technical and methodological requirements of cybersecurity risk-management measures and further specification of the cases in which an incident is considered to be significant with regard to DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online market places, of online search engines and of social networking services platforms, and trust service providers",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "NIST-800-171-Revision-2",
|
||||
"Name": "National Institute of Standards and Technology (NIST) 800-171 Revision 2",
|
||||
"Version": "",
|
||||
"Provider": "AWS",
|
||||
"Description": "The cybersecurity controls within NIST 800-171 safeguard CUI in the IT networks of government contractors and subcontractors. It defines the practices and procedures that government contractors must adhere to when their networks process or store CUI. NIST 800-171 only applies to those parts of a contractor’s network where CUI is present.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "NIST-800-53-Revision-4",
|
||||
"Name": "National Institute of Standards and Technology (NIST) 800-53 Revision 4",
|
||||
"Version": "",
|
||||
"Provider": "AWS",
|
||||
"Description": "NIST 800-53 is a regulatory standard that defines the minimum baseline of security controls for all U.S. federal information systems except those related to national security. The controls defined in this standard are customizable and address a diverse set of security and privacy requirements.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "NIST-800-53-Revision-5",
|
||||
"Name": "National Institute of Standards and Technology (NIST) 800-53 Revision 5",
|
||||
"Version": "",
|
||||
"Provider": "AWS",
|
||||
"Description": "The NIST 800-53 (Rev. 5) Low-Moderate-High framework represents the security controls and the associated assessment procedures that are defined in NIST SP 800-53 Revision 5 Recommended Security Controls for Federal Information Systems and Organizations. For any discrepancies that are noted in the content between this NIST SP 800-53 framework and the latest published NIST Special Publication SP 800-53 Revision 5, refer to the official published documents that are available at the NIST Computer Security Resource Center.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "NIST-CSF",
|
||||
"Name": "National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) v1.1",
|
||||
"Version": "1.1",
|
||||
"Provider": "AWS",
|
||||
"Description": "The NIST Cybersecurity Framework (CSF) is supported by governments and industries worldwide as a recommended baseline for use by any organization, regardless of sector or size. The NIST Cybersecurity Framework consists of three primary components: the framework core, the profiles, and the implementation tiers. The framework core contains desired cybersecurity activities and outcomes organized into 23 categories that cover the breadth of cybersecurity objectives for an organization. The profiles contain an organization's unique alignment of their organizational requirements and objectives, risk appetite, and resources using the desired outcomes of the framework core. The implementation tiers describe the degree to which an organization’s cybersecurity risk management practices exhibit the characteristics defined in the framework core.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "PCI",
|
||||
"Name": "Payment Card Industry Data Security Standard (PCI DSS) v3.2.1",
|
||||
"Version": "3.2.1",
|
||||
"Provider": "AWS",
|
||||
"Description": "The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security standard. It's administered by the PCI Security Standards Council, which was founded by American Express, Discover Financial Services, JCB International, MasterCard Worldwide, and Visa Inc. PCI DSS applies to entities that store, process, or transmit cardholder data (CHD) or sensitive authentication data (SAD). This includes, but isn't limited to, merchants, processors, acquirers, issuers, and service providers. The PCI DSS is mandated by the card brands and administered by the Payment Card Industry Security Standards Council.",
|
||||
@@ -2710,4 +2711,4 @@
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "PCI",
|
||||
"Name": "Payment Card Industry Data Security Standard (PCI DSS) v4.0",
|
||||
"Version": "4.0",
|
||||
"Provider": "AWS",
|
||||
"Description": "The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security standard. It's administered by the PCI Security Standards Council, which was founded by American Express, Discover Financial Services, JCB International, MasterCard Worldwide, and Visa Inc. PCI DSS applies to entities that store, process, or transmit cardholder data (CHD) or sensitive authentication data (SAD). This includes, but isn't limited to, merchants, processors, acquirers, issuers, and service providers. The PCI DSS is mandated by the card brands and administered by the Payment Card Industry Security Standards Council.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "ProwlerThreatScore",
|
||||
"Name": "Prowler ThreatScore Compliance Framework for AWS",
|
||||
"Version": "1.0",
|
||||
"Provider": "AWS",
|
||||
"Description": "Prowler ThreatScore Compliance Framework for AWS ensures that the AWS account is compliant taking into account four main pillars: Identity and Access Management, Attack Surface, Forensic Readiness and Encryption",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "RBI-Cyber-Security-Framework",
|
||||
"Name": "Reserve Bank of India (RBI) Cyber Security Framework",
|
||||
"Version": "",
|
||||
"Provider": "AWS",
|
||||
"Description": "The Reserve Bank had prescribed a set of baseline cyber security controls for primary (Urban) cooperative banks (UCBs) in October 2018. On further examination, it has been decided to prescribe a comprehensive cyber security framework for the UCBs, as a graded approach, based on their digital depth and interconnectedness with the payment systems landscape, digital products offered by them and assessment of cyber security risk. The framework would mandate implementation of progressively stronger security measures based on the nature, variety and scale of digital product offerings of banks.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "SOC2",
|
||||
"Name": "System and Organization Controls 2 (SOC2)",
|
||||
"Version": "",
|
||||
"Provider": "AWS",
|
||||
"Description": "System and Organization Controls (SOC), defined by the American Institute of Certified Public Accountants (AICPA), is the name of a set of reports that's produced during an audit. It's intended for use by service organizations (organizations that provide information systems as a service to other organizations) to issue validated reports of internal controls over those information systems to the users of those services. The reports focus on controls grouped into five categories known as Trust Service Principles.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "CIS",
|
||||
"Name": "CIS Microsoft Azure Foundations Benchmark v2.0.0",
|
||||
"Version": "2.0",
|
||||
"Provider": "Azure",
|
||||
"Description": "The CIS Azure Foundations Benchmark provides prescriptive guidance for configuring security options for a subset of Azure with an emphasis on foundational, testable, and architecture agnostic settings.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "CIS",
|
||||
"Name": "CIS Microsoft Azure Foundations Benchmark v2.1.0",
|
||||
"Version": "2.1",
|
||||
"Provider": "Azure",
|
||||
"Description": "The CIS Azure Foundations Benchmark provides prescriptive guidance for configuring security options for a subset of Azure with an emphasis on foundational, testable, and architecture agnostic settings.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "CIS",
|
||||
"Name": "CIS Microsoft Azure Foundations Benchmark v3.0.0",
|
||||
"Version": "3.0",
|
||||
"Provider": "Azure",
|
||||
"Description": "The CIS Azure Foundations Benchmark provides prescriptive guidance for configuring security options for a subset of Azure with an emphasis on foundational, testable, and architecture agnostic settings.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "CIS",
|
||||
"Name": "CIS Microsoft Azure Foundations Benchmark v4.0.0",
|
||||
"Version": "4.0",
|
||||
"Provider": "Azure",
|
||||
"Description": "The CIS Azure Foundations Benchmark provides prescriptive guidance for configuring security options for a subset of Azure with an emphasis on foundational, testable, and architecture agnostic settings.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "ENS",
|
||||
"Name": "ENS RD 311/2022",
|
||||
"Version": "RD2022",
|
||||
"Provider": "AZURE",
|
||||
"Description": "The accreditation scheme of the ENS (National Security Scheme) has been developed by the Ministry of Finance and Public Administrations and the CCN (National Cryptological Center). This includes the basic principles and minimum requirements necessary for the adequate protection of information.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "ISO27001",
|
||||
"Name": "ISO/IEC 27001 Information Security Management Standard 2022",
|
||||
"Version": "2022",
|
||||
"Provider": "Azure",
|
||||
"Description": "ISO (the International Organization for Standardization) and IEC (the International Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established by the respective organization to deal with particular fields of technical activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "MITRE-ATTACK",
|
||||
"Name": "MITRE ATT&CK compliance framework",
|
||||
"Version": "",
|
||||
"Provider": "Azure",
|
||||
"Description": "MITRE ATT&CK® is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations. The ATT&CK knowledge base is used as a foundation for the development of specific threat models and methodologies in the private sector, in government, and in the cybersecurity product and service community.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "NIS2",
|
||||
"Name": "Network and Information Security Directive (Directive (EU) 2022/2555)",
|
||||
"Version": "",
|
||||
"Provider": "Azure",
|
||||
"Description": "ANNEX to the Commission Implementing Regulation laying down rules for the application of Directive (EU) 2022/2555 as regards technical and methodological requirements of cybersecurity risk-management measures and further specification of the cases in which an incident is considered to be significant with regard to DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online market places, of online search engines and of social networking services platforms, and trust service providers",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "PCI",
|
||||
"Name": "Payment Card Industry Data Security Standard (PCI DSS) v4.0",
|
||||
"Version": "4.0",
|
||||
"Provider": "Azure",
|
||||
"Description": "The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security standard. It's administered by the PCI Security Standards Council, which was founded by American Express, Discover Financial Services, JCB International, MasterCard Worldwide, and Visa Inc. PCI DSS applies to entities that store, process, or transmit cardholder data (CHD) or sensitive authentication data (SAD). This includes, but isn't limited to, merchants, processors, acquirers, issuers, and service providers. The PCI DSS is mandated by the card brands and administered by the Payment Card Industry Security Standards Council.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "ProwlerThreatScore",
|
||||
"Name": "Prowler ThreatScore Compliance Framework for Azure",
|
||||
"Version": "1.0",
|
||||
"Provider": "Azure",
|
||||
"Description": "Prowler ThreatScore Compliance Framework for Azure ensures that the Azure subscription is compliant taking into account four main pillars: Identity and Access Management, Attack Surface, Forensic Readiness and Encryption",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "SOC2",
|
||||
"Name": "System and Organization Controls 2 (SOC2)",
|
||||
"Version": "",
|
||||
"Provider": "Azure",
|
||||
"Description": "System and Organization Controls (SOC), defined by the American Institute of Certified Public Accountants (AICPA), is the name of a set of reports that's produced during an audit. It's intended for use by service organizations (organizations that provide information systems as a service to other organizations) to issue validated reports of internal controls over those information systems to the users of those services. The reports focus on controls grouped into five categories known as Trust Service Principles.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "CIS",
|
||||
"Name": "CIS Google Cloud Platform Foundation Benchmark v2.0.0",
|
||||
"Version": "2.0",
|
||||
"Provider": "GCP",
|
||||
"Description": "This CIS Benchmark is the product of a community consensus process and consists of secure configuration guidelines developed for Google Cloud Computing Platform",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "CIS",
|
||||
"Name": "CIS Google Cloud Platform Foundation Benchmark v3.0.0",
|
||||
"Version": "3.0",
|
||||
"Provider": "GCP",
|
||||
"Description": "The CIS Google Cloud Platform Foundations Benchmark provides prescriptive guidance for configuring security options for a subset of GCP with an emphasis on foundational, testable, and architecture agnostic settings.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "CIS",
|
||||
"Name": "CIS Google Cloud Platform Foundation Benchmark v4.0.0",
|
||||
"Version": "4.0",
|
||||
"Provider": "GCP",
|
||||
"Description": "The CIS Google Cloud Platform Foundations Benchmark provides prescriptive guidance for configuring security options for a subset of GCP with an emphasis on foundational, testable, and architecture agnostic settings.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "ENS",
|
||||
"Name": "ENS RD 311/2022",
|
||||
"Version": "RD2022",
|
||||
"Provider": "GCP",
|
||||
"Description": "The accreditation scheme of the ENS (National Security Scheme) has been developed by the Ministry of Finance and Public Administrations and the CCN (National Cryptological Center). This includes the basic principles and minimum requirements necessary for the adequate protection of information.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "ISO27001",
|
||||
"Name": "ISO/IEC 27001 Information Security Management Standard 2022",
|
||||
"Version": "2022",
|
||||
"Provider": "GCP",
|
||||
"Description": "ISO (the International Organization for Standardization) and IEC (the International Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established by the respective organization to deal with particular fields of technical activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "MITRE-ATTACK",
|
||||
"Name": "MITRE ATT&CK compliance framework",
|
||||
"Version": "",
|
||||
"Provider": "GCP",
|
||||
"Description": "MITRE ATT&CK® is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations. The ATT&CK knowledge base is used as a foundation for the development of specific threat models and methodologies in the private sector, in government, and in the cybersecurity product and service community.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "NIS2",
|
||||
"Name": "Network and Information Security Directive (Directive (EU) 2022/2555)",
|
||||
"Version": "",
|
||||
"Provider": "GCP",
|
||||
"Description": "ANNEX to the Commission Implementing Regulation laying down rules for the application of Directive (EU) 2022/2555 as regards technical and methodological requirements of cybersecurity risk-management measures and further specification of the cases in which an incident is considered to be significant with regard to DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online market places, of online search engines and of social networking services platforms, and trust service providers",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "PCI",
|
||||
"Name": "Payment Card Industry Data Security Standard (PCI DSS) v4.0",
|
||||
"Version": "4.0",
|
||||
"Provider": "GCP",
|
||||
"Description": "The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security standard. It's administered by the PCI Security Standards Council, which was founded by American Express, Discover Financial Services, JCB International, MasterCard Worldwide, and Visa Inc. PCI DSS applies to entities that store, process, or transmit cardholder data (CHD) or sensitive authentication data (SAD). This includes, but isn't limited to, merchants, processors, acquirers, issuers, and service providers. The PCI DSS is mandated by the card brands and administered by the Payment Card Industry Security Standards Council.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "ProwlerThreatScore",
|
||||
"Name": "Prowler ThreatScore Compliance Framework for GCP",
|
||||
"Version": "1.0",
|
||||
"Provider": "GCP",
|
||||
"Description": "Prowler ThreatScore Compliance Framework for GCP ensures that the GCP project is compliant taking into account four main pillars: Identity and Access Management, Attack Surface, Forensic Readiness and Encryption",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "SOC2",
|
||||
"Name": "System and Organization Controls 2 (SOC2)",
|
||||
"Version": "",
|
||||
"Provider": "GCP",
|
||||
"Description": "System and Organization Controls (SOC), defined by the American Institute of Certified Public Accountants (AICPA), is the name of a set of reports that's produced during an audit. It's intended for use by service organizations (organizations that provide information systems as a service to other organizations) to issue validated reports of internal controls over those information systems to the users of those services. The reports focus on controls grouped into five categories known as Trust Service Principles.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "CIS",
|
||||
"Name": "CIS GitHub Benchmark v1.0.0",
|
||||
"Version": "1.0",
|
||||
"Provider": "GitHub",
|
||||
"Description": "This document provides prescriptive guidance for establishing a secure configuration posture for securing GitHub.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "CIS",
|
||||
"Name": "CIS Kubernetes Benchmark v1.10.0",
|
||||
"Version": "1.10",
|
||||
"Provider": "Kubernetes",
|
||||
"Description": "This CIS Kubernetes Benchmark provides prescriptive guidance for establishing a secure configuration posture for Kubernetes v1.28 - v1.31",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "CIS",
|
||||
"Name": "CIS Kubernetes Benchmark v1.11.0",
|
||||
"Version": "1.11.1",
|
||||
"Provider": "Kubernetes",
|
||||
"Description": "This CIS Kubernetes Benchmark provides prescriptive guidance for establishing a secure configuration posture for Kubernetes v1.28 - v1.31",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "CIS",
|
||||
"Name": "CIS Kubernetes Benchmark v1.8.0",
|
||||
"Version": "1.8",
|
||||
"Provider": "Kubernetes",
|
||||
"Description": "This CIS Kubernetes Benchmark provides prescriptive guidance for establishing a secure configuration posture for Kubernetes v1.27",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "ISO27001",
|
||||
"Name": "ISO/IEC 27001 Information Security Management Standard 2022",
|
||||
"Version": "2022",
|
||||
"Provider": "Kubernetes",
|
||||
"Description": "ISO (the International Organization for Standardization) and IEC (the International Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established by the respective organization to deal with particular fields of technical activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "PCI",
|
||||
"Name": "Payment Card Industry Data Security Standard (PCI DSS) v4.0",
|
||||
"Version": "4.0",
|
||||
"Provider": "Kubernetes",
|
||||
"Description": "The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security standard. It's administered by the PCI Security Standards Council, which was founded by American Express, Discover Financial Services, JCB International, MasterCard Worldwide, and Visa Inc. PCI DSS applies to entities that store, process, or transmit cardholder data (CHD) or sensitive authentication data (SAD). This includes, but isn't limited to, merchants, processors, acquirers, issuers, and service providers. The PCI DSS is mandated by the card brands and administered by the Payment Card Industry Security Standards Council.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "CIS",
|
||||
"Name": "CIS Microsoft 365 Foundations Benchmark v4.0.0",
|
||||
"Version": "4.0",
|
||||
"Provider": "M365",
|
||||
"Description": "The CIS Microsoft 365 Foundations Benchmark provides prescriptive guidance for establishing a secure configuration posture for Microsoft 365 Cloud offerings running on any OS.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "ISO27001",
|
||||
"Name": "ISO/IEC 27001 Information Security Management Standard 2022",
|
||||
"Version": "2022",
|
||||
"Provider": "M365",
|
||||
"Description": "ISO (the International Organization for Standardization) and IEC (the International Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established by the respective organization to deal with particular fields of technical activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "ProwlerThreatScore",
|
||||
"Name": "Prowler ThreatScore Compliance Framework for Microsoft 365",
|
||||
"Version": "1.0",
|
||||
"Provider": "M365",
|
||||
"Description": "Prowler ThreatScore Compliance Framework for Microsoft 365 ensures that the Microsoft 365 tenant is compliant taking into account four main pillars: Identity and Access Management, Attack Surface, Forensic Readiness and Encryption",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
"Framework": "ISO27001",
|
||||
"Name": "ISO/IEC 27001 Information Security Management Standard 2022",
|
||||
"Version": "2022",
|
||||
"Provider": "NHN",
|
||||
"Description": "ISO (the International Organization for Standardization) and IEC (the International Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established by the respective organization to deal with particular fields of technical activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.",
|
||||
|
||||
@@ -29,6 +29,7 @@ def update_checks_metadata_with_compliance(
|
||||
# Create the Compliance
|
||||
compliance = Compliance(
|
||||
Framework=framework.Framework,
|
||||
Name=framework.Name,
|
||||
Provider=framework.Provider,
|
||||
Version=framework.Version,
|
||||
Description=framework.Description,
|
||||
|
||||
@@ -227,6 +227,7 @@ class Compliance(BaseModel):
|
||||
"""Compliance holds the base model for every compliance framework"""
|
||||
|
||||
Framework: str
|
||||
Name: str
|
||||
Provider: str
|
||||
Version: Optional[str] = None
|
||||
Description: str
|
||||
@@ -240,12 +241,13 @@ class Compliance(BaseModel):
|
||||
@root_validator(pre=True)
|
||||
# noqa: F841 - since vulture raises unused variable 'cls'
|
||||
def framework_and_provider_must_not_be_empty(cls, values): # noqa: F841
|
||||
framework, provider = (
|
||||
framework, provider, name = (
|
||||
values.get("Framework"),
|
||||
values.get("Provider"),
|
||||
values.get("Name"),
|
||||
)
|
||||
if framework == "" or provider == "":
|
||||
raise ValueError("Framework or Provider must not be empty")
|
||||
if framework == "" or provider == "" or name == "":
|
||||
raise ValueError("Framework, Provider or Name must not be empty")
|
||||
return values
|
||||
|
||||
@staticmethod
|
||||
|
||||
@@ -65,6 +65,8 @@ class AWSWellArchitected(ComplianceOutput):
|
||||
ResourceName=finding.resource_name,
|
||||
CheckId=finding.check_id,
|
||||
Muted=finding.muted,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
# Add manual requirements to the compliance output
|
||||
@@ -94,5 +96,7 @@ class AWSWellArchitected(ComplianceOutput):
|
||||
ResourceName="Manual check",
|
||||
CheckId="manual",
|
||||
Muted=False,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
|
||||
@@ -30,3 +30,5 @@ class AWSWellArchitectedModel(BaseModel):
|
||||
CheckId: str
|
||||
Muted: bool
|
||||
ResourceName: str
|
||||
Framework: str
|
||||
Name: str
|
||||
|
||||
@@ -66,6 +66,8 @@ class AWSCIS(ComplianceOutput):
|
||||
ResourceName=finding.resource_name,
|
||||
CheckId=finding.check_id,
|
||||
Muted=finding.muted,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
# Add manual requirements to the compliance output
|
||||
@@ -74,6 +76,8 @@ class AWSCIS(ComplianceOutput):
|
||||
for attribute in requirement.Attributes:
|
||||
compliance_row = AWSCISModel(
|
||||
Provider=compliance.Provider.lower(),
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
Description=compliance.Description,
|
||||
AccountId="",
|
||||
Region="",
|
||||
|
||||
@@ -66,6 +66,8 @@ class AzureCIS(ComplianceOutput):
|
||||
ResourceName=finding.resource_name,
|
||||
CheckId=finding.check_id,
|
||||
Muted=finding.muted,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
# Add manual requirements to the compliance output
|
||||
@@ -98,5 +100,7 @@ class AzureCIS(ComplianceOutput):
|
||||
ResourceName="Manual check",
|
||||
CheckId="manual",
|
||||
Muted=False,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
|
||||
@@ -65,6 +65,8 @@ class GCPCIS(ComplianceOutput):
|
||||
ResourceName=finding.resource_name,
|
||||
CheckId=finding.check_id,
|
||||
Muted=finding.muted,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
# Add manual requirements to the compliance output
|
||||
@@ -96,5 +98,7 @@ class GCPCIS(ComplianceOutput):
|
||||
ResourceName="Manual check",
|
||||
CheckId="manual",
|
||||
Muted=False,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
|
||||
@@ -65,6 +65,8 @@ class GithubCIS(ComplianceOutput):
|
||||
ResourceName=finding.resource_name,
|
||||
CheckId=finding.check_id,
|
||||
Muted=finding.muted,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
# Add manual requirements to the compliance output
|
||||
@@ -96,5 +98,7 @@ class GithubCIS(ComplianceOutput):
|
||||
ResourceName="Manual check",
|
||||
CheckId="manual",
|
||||
Muted=False,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
|
||||
@@ -66,6 +66,8 @@ class KubernetesCIS(ComplianceOutput):
|
||||
ResourceName=finding.resource_name,
|
||||
CheckId=finding.check_id,
|
||||
Muted=finding.muted,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
# Add manual requirements to the compliance output
|
||||
@@ -98,5 +100,7 @@ class KubernetesCIS(ComplianceOutput):
|
||||
ResourceName="Manual check",
|
||||
CheckId="manual",
|
||||
Muted=False,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
|
||||
@@ -66,6 +66,8 @@ class M365CIS(ComplianceOutput):
|
||||
ResourceName=finding.resource_name,
|
||||
CheckId=finding.check_id,
|
||||
Muted=finding.muted,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
# Add manual requirements to the compliance output
|
||||
@@ -98,5 +100,7 @@ class M365CIS(ComplianceOutput):
|
||||
ResourceName="Manual check",
|
||||
CheckId="manual",
|
||||
Muted=False,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
|
||||
@@ -35,6 +35,8 @@ class AWSCISModel(BaseModel):
|
||||
ResourceName: str
|
||||
CheckId: str
|
||||
Muted: bool
|
||||
Framework: str
|
||||
Name: str
|
||||
|
||||
|
||||
class AzureCISModel(BaseModel):
|
||||
@@ -67,6 +69,8 @@ class AzureCISModel(BaseModel):
|
||||
ResourceName: str
|
||||
CheckId: str
|
||||
Muted: bool
|
||||
Framework: str
|
||||
Name: str
|
||||
|
||||
|
||||
class M365CISModel(BaseModel):
|
||||
@@ -99,6 +103,8 @@ class M365CISModel(BaseModel):
|
||||
ResourceName: str
|
||||
CheckId: str
|
||||
Muted: bool
|
||||
Framework: str
|
||||
Name: str
|
||||
|
||||
|
||||
class GCPCISModel(BaseModel):
|
||||
@@ -130,6 +136,8 @@ class GCPCISModel(BaseModel):
|
||||
ResourceName: str
|
||||
CheckId: str
|
||||
Muted: bool
|
||||
Framework: str
|
||||
Name: str
|
||||
|
||||
|
||||
class KubernetesCISModel(BaseModel):
|
||||
@@ -162,6 +170,8 @@ class KubernetesCISModel(BaseModel):
|
||||
ResourceName: str
|
||||
CheckId: str
|
||||
Muted: bool
|
||||
Framework: str
|
||||
Name: str
|
||||
|
||||
|
||||
class GithubCISModel(BaseModel):
|
||||
@@ -193,6 +203,8 @@ class GithubCISModel(BaseModel):
|
||||
ResourceName: str
|
||||
CheckId: str
|
||||
Muted: bool
|
||||
Framework: str
|
||||
Name: str
|
||||
|
||||
|
||||
# TODO: Create a parent class for the common fields of CIS and have the specific classes from each provider to inherit from it.
|
||||
|
||||
@@ -67,6 +67,8 @@ class AWSENS(ComplianceOutput):
|
||||
ResourceName=finding.resource_name,
|
||||
CheckId=finding.check_id,
|
||||
Muted=finding.muted,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
# Add manual requirements to the compliance output
|
||||
@@ -100,5 +102,7 @@ class AWSENS(ComplianceOutput):
|
||||
ResourceName="Manual check",
|
||||
CheckId="manual",
|
||||
Muted=False,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
|
||||
@@ -67,6 +67,8 @@ class AzureENS(ComplianceOutput):
|
||||
ResourceName=finding.resource_name,
|
||||
CheckId=finding.check_id,
|
||||
Muted=finding.muted,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
# Add manual requirements to the compliance output
|
||||
@@ -100,5 +102,7 @@ class AzureENS(ComplianceOutput):
|
||||
ResourceName="Manual check",
|
||||
CheckId="manual",
|
||||
Muted=False,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
|
||||
@@ -67,6 +67,8 @@ class GCPENS(ComplianceOutput):
|
||||
ResourceName=finding.resource_name,
|
||||
CheckId=finding.check_id,
|
||||
Muted=finding.muted,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
# Add manual requirements to the compliance output
|
||||
@@ -100,5 +102,7 @@ class GCPENS(ComplianceOutput):
|
||||
ResourceName="Manual check",
|
||||
CheckId="manual",
|
||||
Muted=False,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
|
||||
@@ -28,6 +28,8 @@ class AWSENSModel(BaseModel):
|
||||
CheckId: str
|
||||
Muted: bool
|
||||
ResourceName: str
|
||||
Framework: str
|
||||
Name: str
|
||||
|
||||
|
||||
class AzureENSModel(BaseModel):
|
||||
@@ -57,6 +59,8 @@ class AzureENSModel(BaseModel):
|
||||
CheckId: str
|
||||
Muted: bool
|
||||
ResourceName: str
|
||||
Framework: str
|
||||
Name: str
|
||||
|
||||
|
||||
class GCPENSModel(BaseModel):
|
||||
@@ -86,3 +90,5 @@ class GCPENSModel(BaseModel):
|
||||
CheckId: str
|
||||
Muted: bool
|
||||
ResourceName: str
|
||||
Framework: str
|
||||
Name: str
|
||||
|
||||
@@ -59,6 +59,8 @@ class GenericCompliance(ComplianceOutput):
|
||||
ResourceName=finding.resource_name,
|
||||
CheckId=finding.check_id,
|
||||
Muted=finding.muted,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
# Add manual requirements to the compliance output
|
||||
@@ -84,5 +86,7 @@ class GenericCompliance(ComplianceOutput):
|
||||
ResourceName="Manual check",
|
||||
CheckId="manual",
|
||||
Muted=False,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
|
||||
@@ -26,3 +26,5 @@ class GenericComplianceModel(BaseModel):
|
||||
CheckId: str
|
||||
Muted: bool
|
||||
ResourceName: str
|
||||
Framework: str
|
||||
Name: str
|
||||
|
||||
@@ -59,6 +59,8 @@ class AWSISO27001(ComplianceOutput):
|
||||
CheckId=finding.check_id,
|
||||
Muted=finding.muted,
|
||||
ResourceName=finding.resource_name,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
# Add manual requirements to the compliance output
|
||||
@@ -84,5 +86,7 @@ class AWSISO27001(ComplianceOutput):
|
||||
ResourceName="Manual check",
|
||||
CheckId="manual",
|
||||
Muted=False,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
|
||||
@@ -59,6 +59,8 @@ class AzureISO27001(ComplianceOutput):
|
||||
CheckId=finding.check_id,
|
||||
Muted=finding.muted,
|
||||
ResourceName=finding.resource_name,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
# Add manual requirements to the compliance output
|
||||
@@ -84,5 +86,7 @@ class AzureISO27001(ComplianceOutput):
|
||||
ResourceName="Manual check",
|
||||
CheckId="manual",
|
||||
Muted=False,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
|
||||
@@ -59,6 +59,8 @@ class GCPISO27001(ComplianceOutput):
|
||||
CheckId=finding.check_id,
|
||||
Muted=finding.muted,
|
||||
ResourceName=finding.resource_name,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
# Add manual requirements to the compliance output
|
||||
@@ -84,5 +86,7 @@ class GCPISO27001(ComplianceOutput):
|
||||
ResourceName="Manual check",
|
||||
CheckId="manual",
|
||||
Muted=False,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
|
||||
@@ -59,6 +59,8 @@ class KubernetesISO27001(ComplianceOutput):
|
||||
CheckId=finding.check_id,
|
||||
Muted=finding.muted,
|
||||
ResourceName=finding.resource_name,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
# Add manual requirements to the compliance output
|
||||
@@ -84,5 +86,7 @@ class KubernetesISO27001(ComplianceOutput):
|
||||
ResourceName="Manual check",
|
||||
CheckId="manual",
|
||||
Muted=False,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
|
||||
@@ -58,6 +58,8 @@ class NHNISO27001(ComplianceOutput):
|
||||
CheckId=finding.check_id,
|
||||
Muted=finding.muted,
|
||||
ResourceName=finding.resource_name,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
|
||||
@@ -84,5 +86,7 @@ class NHNISO27001(ComplianceOutput):
|
||||
ResourceName="Manual check",
|
||||
CheckId="manual",
|
||||
Muted=False,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
|
||||
@@ -24,6 +24,8 @@ class AWSISO27001Model(BaseModel):
|
||||
CheckId: str
|
||||
Muted: bool
|
||||
ResourceName: str
|
||||
Framework: str
|
||||
Name: str
|
||||
|
||||
|
||||
class AzureISO27001Model(BaseModel):
|
||||
@@ -49,6 +51,8 @@ class AzureISO27001Model(BaseModel):
|
||||
CheckId: str
|
||||
Muted: bool
|
||||
ResourceName: str
|
||||
Framework: str
|
||||
Name: str
|
||||
|
||||
|
||||
class GCPISO27001Model(BaseModel):
|
||||
@@ -74,6 +78,8 @@ class GCPISO27001Model(BaseModel):
|
||||
CheckId: str
|
||||
Muted: bool
|
||||
ResourceName: str
|
||||
Framework: str
|
||||
Name: str
|
||||
|
||||
|
||||
class KubernetesISO27001Model(BaseModel):
|
||||
@@ -99,6 +105,8 @@ class KubernetesISO27001Model(BaseModel):
|
||||
CheckId: str
|
||||
Muted: bool
|
||||
ResourceName: str
|
||||
Framework: str
|
||||
Name: str
|
||||
|
||||
|
||||
class NHNISO27001Model(BaseModel):
|
||||
@@ -124,6 +132,8 @@ class NHNISO27001Model(BaseModel):
|
||||
CheckId: str
|
||||
Muted: bool
|
||||
ResourceName: str
|
||||
Framework: str
|
||||
Name: str
|
||||
|
||||
|
||||
class M365ISO27001Model(BaseModel):
|
||||
@@ -149,3 +159,5 @@ class M365ISO27001Model(BaseModel):
|
||||
CheckId: str
|
||||
Muted: bool
|
||||
ResourceName: str
|
||||
Framework: str
|
||||
Name: str
|
||||
|
||||
@@ -62,6 +62,8 @@ class AWSKISAISMSP(ComplianceOutput):
|
||||
ResourceName=finding.resource_name,
|
||||
CheckId=finding.check_id,
|
||||
Muted=finding.muted,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
# Add manual requirements to the compliance output
|
||||
@@ -90,5 +92,7 @@ class AWSKISAISMSP(ComplianceOutput):
|
||||
ResourceName="Manual check",
|
||||
CheckId="manual",
|
||||
Muted=False,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
|
||||
@@ -29,3 +29,5 @@ class AWSKISAISMSPModel(BaseModel):
|
||||
ResourceName: str
|
||||
CheckId: str
|
||||
Muted: bool
|
||||
Framework: str
|
||||
Name: str
|
||||
|
||||
@@ -73,6 +73,8 @@ class AWSMitreAttack(ComplianceOutput):
|
||||
ResourceName=finding.resource_name,
|
||||
CheckId=finding.check_id,
|
||||
Muted=finding.muted,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
# Add manual requirements to the compliance output
|
||||
@@ -112,5 +114,7 @@ class AWSMitreAttack(ComplianceOutput):
|
||||
ResourceName="Manual check",
|
||||
CheckId="manual",
|
||||
Muted=False,
|
||||
Framework=compliance.Framework,
|
||||
Name=compliance.Name,
|
||||
)
|
||||
self._data.append(compliance_row)
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user