Skip to content
This repository has been archived by the owner on Dec 23, 2019. It is now read-only.

When writing controls I need a way to score their importance as not all controls have the same impact on performance indexing and security #93

Open
willeybryan opened this issue May 30, 2019 · 0 comments
Labels
API Features and issues relating to the API used by the tool and it's features Performance-Index Features and issues relating to the risk indexing of controls and systems

Comments

@willeybryan
Copy link
Collaborator

willeybryan commented May 30, 2019

Acceptance Criteria

Notes
"The Logical Condition is any set of logical relations among metric conditions that, when TRUE, mean that this condition provides some evidentiary support for that particular index value (a.k.a. score value). Relevance is a number, or a function that returns a number, on some standard scale of relevance. In the demo below, the relevance scale is -1 to +1, with '+1' meaning fully relevant with positive implications, '-1' meaning fully relevant with negative implications, and '0' meaning not relevant. Significance is the conditional weighting factor, given that both the logical condition are true and relevance is not zero."

Why?
- Professionals consuming the output of the tool need to be able to easily compare the amount of risk a release exposes them too in cases where not all controls are met. To do this we need to assign values to the rules which we can them bubble up into a performance index.

@willeybryan willeybryan added Performance-Index Features and issues relating to the risk indexing of controls and systems API Features and issues relating to the API used by the tool and it's features labels May 30, 2019
@willeybryan willeybryan changed the title When writing controls I need a way to score their importance as not all controls have the same impact on risk and security When writing controls I need a way to score their importance as not all controls have the same impact on performance indexing and security Jun 18, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
API Features and issues relating to the API used by the tool and it's features Performance-Index Features and issues relating to the risk indexing of controls and systems
Projects
None yet
Development

No branches or pull requests

1 participant