Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Architecture: Security Automation Workflow Enumeration #10

Open
adammontville opened this issue Oct 21, 2020 · 2 comments
Open

Architecture: Security Automation Workflow Enumeration #10

adammontville opened this issue Oct 21, 2020 · 2 comments
Assignees

Comments

@adammontville
Copy link

Provide an example of workflows from an existing project (CIS 7.1 Controls)

@adammontville adammontville self-assigned this Oct 21, 2020
@adammontville
Copy link
Author

Just an update on this effort. I seem to have lost the initial work I did on this, so I'll restart and have something prior to the next meeting. So, still in progress.

@adammontville
Copy link
Author

oca-architecture-wg-controls-workflow-analysis.pdf

That short deck, I hope, describes what I could find in v7.1 of the CIS Controls for cross-functional workflows. I see evidence of workflows in what the Controls call "ERD" diagrams (they're more like system relationship diagrams). These diagrams don't indicate more than the relationship (no protocol or data format information is included). Some sub-control descriptions and "Procedures and Tools" sections will allude to workflows, but don't explicitly talk about them. I combined a number of these diagrams into one view, and believe that any orchestration, interaction, or workflow implementation is being obscured in what is labeled as an "Alerting/Reporting Analytics System".

Then, each of the management areas (asset, configuration, vulnerability, log, etc.) relate to computing/network devices and are connected to the alerting/reporting analytics system, and I presume that the alerting would trigger some other process. that triggering and the process itself appear to be out of scope of the document.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant