Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

epic(OS_Scan): Conduct Design Sessions for Implementation of OpenStack Compliance Scan #223

Closed
10 tasks
lolaapenna opened this issue Sep 17, 2024 · 0 comments
Closed
10 tasks

Comments

@lolaapenna
Copy link
Collaborator

lolaapenna commented Sep 17, 2024

Description

This epic focuses on conducting design sessions to plan and strategize the implementation of OpenStack Compliance Scans.

Objective

To develop a comprehensive and effective approach to ensure that the OpenStack environment meets all compliance requirements as outlined in the SAP Converged Cloud - Security Hardening policy. These sessions will involve key stakeholders and subject matter experts to design the Heureka compliance scan framework collaboratively.

Tasks

  • Review Compliance Requirements:
  • Decide on Tooling for Scanners
  • Decide on the first scanner scope

Scanners (Assets)?

  • VM Scanner
  • Virtual Network Scanner
  • Security Group Scanner
  • VM Image Scanner

Scanners (Policy)?

  • Invalid Security Group configuration ?!

Future Decision to be made

  • Design RBAC Implementation:
    • Define roles, permissions, and access levels.
  • Decide how to handle Nested Resources:
    • Develop strategies for handling nested resources, including project IDs, embedded services, user attributes, and support groups.
@lolaapenna lolaapenna added the jira For JIRA Syncer label Oct 17, 2024
@github-actions github-actions bot added OWS2-241 and removed jira For JIRA Syncer labels Oct 17, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant