Skip to content

Commit 1dd410d

Browse files
authored
add
1 parent 73e3c58 commit 1dd410d

File tree

1 file changed

+20
-0
lines changed

1 file changed

+20
-0
lines changed

data/TestandVerification.yml

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -731,6 +731,26 @@ Static depth for infrastructure:
731731
iso27001-2017:
732732
- 12.6.1
733733
- 14.2.1
734+
Correlate known vulnerabilities in infrastructure with new image versions:
735+
risk: "TODO."
736+
measure: "TODO"
737+
difficultyOfImplementation:
738+
knowledge: 2
739+
time: 5
740+
resources: 4
741+
usefulness: 1
742+
level: 4
743+
dependsOn:
744+
- Usage of a maximum lifetime for images
745+
implementation:
746+
- Anchore.io
747+
- Clair
748+
- OpenSCAP
749+
- <a href='https://github.com/future-architect/vuls'>Vuls</a>
750+
samm2: v-security-testing|A|1
751+
iso27001-2017:
752+
- 12.6.1
753+
- 14.2.1
734754
Test the clould configuration:
735755
risk: Standard hardening practices for cloud environments are not performed leading to vulnerabilities.
736756
measure: With the help of tools the configuration of virtual environments are

0 commit comments

Comments
 (0)