⚠️ OpenSpec-managed issue — this content is automatically synced
from the openspec/ directory. Manual edits will be overwritten on next sync.
Artifacts
Summary
A CISO wants to classify the applications in their own organisation's overview with a BIO baseline level, and share that knowledge with other municipalities. Stackiq has one BBN level per product, set in the catalogue, the same for every municipality and not split into availability, integrity and confidentiality. This change lets an organisation classify each application it uses on those three aspects, with a reason each, suggests the levels from GEMMA's reference components, derives the overall BBN level, and shows other municipalities how organisations classify an application, as counts that name no one.
Specs
Tasks
Design
See design.md for technical design details.
Synced from openspec/changes/security-baseline-classification by OpenSpec workflow
App: stackiq
Artifacts
Summary
A CISO wants to classify the applications in their own organisation's overview with a BIO baseline level, and share that knowledge with other municipalities. Stackiq has one BBN level per product, set in the catalogue, the same for every municipality and not split into availability, integrity and confidentiality. This change lets an organisation classify each application it uses on those three aspects, with a reason each, suggests the levels from GEMMA's reference components, derives the overall BBN level, and shows other municipalities how organisations classify an application, as counts that name no one.
Specs
Tasks
Design
See design.md for technical design details.
Synced from
openspec/changes/security-baseline-classificationby OpenSpec workflowApp:
stackiq