Skip to content

[OpenSpec] security-baseline-classification #1131

Description

@github-actions

⚠️ OpenSpec-managed issue — this content is automatically synced
from the openspec/ directory. Manual edits will be overwritten on next sync.

Artifacts

Summary

A CISO wants to classify the applications in their own organisation's overview with a BIO baseline level, and share that knowledge with other municipalities. Stackiq has one BBN level per product, set in the catalogue, the same for every municipality and not split into availability, integrity and confidentiality. This change lets an organisation classify each application it uses on those three aspects, with a reason each, suggests the levels from GEMMA's reference components, derives the overall BBN level, and shows other municipalities how organisations classify an application, as counts that name no one.

Specs

Tasks

  • Implement
  • Test (PHPUnit tests/Unit/Settings/BaselineClassificationDeclarationTest.php)
  • Implement
  • Test (PHPUnit tests/Unit/EventListener/UsageClassificationSubscriberTest.php, constructing the real OpenRegister event classes)
  • Implement
  • Test (PHPUnit tests/Unit/Service/UsageClassificationServiceTest.php and tests/Unit/Controller/UsageClassificationControllerTest.php)
  • Implement
  • Test (vitest tests/vitest/usageClassificationPanel.spec.js and Playwright tests/e2e/spec-coverage/baseline-classification.spec.ts)
  • Implement
  • Test (Playwright tests/e2e/spec-coverage/baseline-classification.spec.ts against the demo data)

Design

See design.md for technical design details.


Synced from openspec/changes/security-baseline-classification by OpenSpec workflow
App: stackiq

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions