Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Evaluate alignment with CNCF Compliance efforts #199

Closed
eddie-knight opened this issue Jun 12, 2024 · 3 comments · Fixed by #302
Closed

Evaluate alignment with CNCF Compliance efforts #199

eddie-knight opened this issue Jun 12, 2024 · 3 comments · Fixed by #302
Assignees

Comments

@eddie-knight
Copy link
Contributor

Within the CNCF Security Technical Advisory Group, there have been efforts in the past to map NIST 800-53r5 controls to the recommendations in their publications.

Will these mappings help accelerate any of the work we're doing?

Separately... Considering our efforts to define regulatory compliance for cloud services, is there any opportunity for overlap with the CNCF STAG Compliance Working Group?

@mlysaght2017
Copy link
Contributor

@eddie-knight @jared-lambert - I spoke to Jon Zeolla about the CNCF cloud native control catalog and also looked at some of their best practices you've pointed to here. The CNCF catalog is K8s focused, and from I can see, does not have a focus on CSP cloud services. I believe the codified templates being proposed for the CCC control go beyond what's detailed in the CNCF catalog so far and I'm happy with the progress we're making on that front.

@mlysaght2017 mlysaght2017 moved this from Prioritised to In Progress in FINOS Common Cloud Controls - Project Kanban Jul 25, 2024
@mlysaght2017 mlysaght2017 moved this from In Progress to Ready for Review in FINOS Common Cloud Controls - Project Kanban Jul 25, 2024
@jared-lambert
Copy link
Contributor

jared-lambert commented Jul 25, 2024

For: CNCF cloud native control catalog

Michael to write a considerations article / para that outlines this call, and put it in the resources folder for later discovery if needed.

@jared-lambert
Copy link
Contributor

For the STAG area, we created a new item here:
#278

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Development

Successfully merging a pull request may close this issue.

3 participants