Skip to content

Commit 1d15f0b

Browse files
authored
Merge pull request #256 from devsecopsmaturitymodel/wurstbrot-patch-1
feat: Activity Contexualized Encoding
2 parents 08c46d4 + f81d3cf commit 1d15f0b

File tree

1 file changed

+27
-3
lines changed

1 file changed

+27
-3
lines changed

src/assets/YAML/default/Implementation/ApplicationHardening.yaml

Lines changed: 27 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -50,8 +50,34 @@ Implementation:
5050
- Hardening is not explicitly covered by ISO 27001 - too specific
5151
- 8.22
5252
isImplemented: false
53-
evidence: ""
5453
comments: ""
54+
Contextualized Encoding:
55+
identifier: e1f37abb-d848-4a3a-b3df-65e91a89dcb7
56+
hazard:
57+
The generation of interpreter directives from user-provided data poses difficulties and can introduce vulnerabilities to injection attacks.
58+
remediation: |
59+
Implementing contextualized encoding, such as employing object-relational mapping tools or utilizing prepared statements, nearly removes the threat of injection vulnerabilities.
60+
difficultyOfImplementation:
61+
knowledge: 2
62+
time: 2
63+
resources: 1
64+
usefulness: 3
65+
level: 1
66+
description: |
67+
Bear in mind that utilizing frameworks is a recommended approach; however, they can develop known security weaknesses over time. Diligent and regular patching is crucial.
68+
implementation:
69+
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-asvs
70+
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-masvs
71+
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/apimaturity
72+
references:
73+
samm2:
74+
- D-SR-1-A
75+
iso27001-2017:
76+
- Hardening is not explicitly covered by ISO 27001 - too specific
77+
- 13.1.3
78+
iso27001-2022:
79+
- Hardening is not explicitly covered by ISO 27001 - too specific
80+
- 8.22
5581
App. Hardening Level 1:
5682
uuid: cf819225-30cb-4702-8e32-60225eedc33d
5783
risk:
@@ -101,8 +127,6 @@ Implementation:
101127
iso27001-2022:
102128
- Hardening is not explicitly covered by ISO 27001 - too specific
103129
- 8.22
104-
isImplemented: false
105-
evidence: ""
106130
comments: ""
107131
App. Hardening Level 2 (75%):
108132
uuid: 03643ca2-03c2-472b-8e19-956bf02fe9b7

0 commit comments

Comments
 (0)