Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

https://mvsp.dev/ review #1151

Closed
jmanico opened this issue Dec 14, 2021 · 21 comments
Closed

https://mvsp.dev/ review #1151

jmanico opened this issue Dec 14, 2021 · 21 comments
Assignees
Labels
2) Awaiting response Awaiting a response from the original poster _5.0 - Not blocker This issue does not block 5.0 so if it gets addressed then great, if not then fine.

Comments

@jmanico
Copy link
Member

jmanico commented Dec 14, 2021

Let's review this awesome project at https://mvsp.dev/ and see if we are missing anything before 5.0

@cmlh
Copy link
Contributor

cmlh commented Dec 14, 2021

Any chance of creating a milestone to track @jmanico https://mvsp.dev/ and #1039, #317, PA-DSS and others?

@jmanico jmanico self-assigned this Dec 14, 2021
@jmanico
Copy link
Member Author

jmanico commented Dec 14, 2021

Any chance of creating a milestone to track @jmanico https://mvsp.dev/ and #1039, #317, PA-DSS and others?

For sure Christian. For now, I flagged the issues you cited as 5.0 so at the very least address your comments before the 5.0 release. I'll also assign these issues to myself (and you) as well.

@tghosth tghosth added _5.0 - draft This should be discussed once a 5.0 draft has been prepared. _5.0 - prep This needs to be addressed to prepare 5.0 labels Apr 27, 2022
@tghosth tghosth removed the _5.0 - draft This should be discussed once a 5.0 draft has been prepared. label Dec 7, 2022
@tghosth
Copy link
Collaborator

tghosth commented Dec 7, 2022

@cmlh are #1360, #1361 and #1365 the only things that are missing from ASVS compared to MSVP? If so, can we close this original issue?

@tghosth tghosth added the 2) Awaiting response Awaiting a response from the original poster label Dec 7, 2022
@tghosth tghosth assigned tghosth and cmlh and unassigned jmanico Dec 7, 2022
@tghosth
Copy link
Collaborator

tghosth commented Dec 7, 2022

@set-reminder 2 weeks decide what to do depending on response

@tghosth tghosth closed this as completed Dec 7, 2022
@octo-reminder
Copy link

octo-reminder bot commented Dec 7, 2022

Reminder
Wednesday, December 21, 2022 12:00 AM (GMT+01:00)

decide what to do depending on response

@tghosth tghosth reopened this Dec 7, 2022
@cmlh
Copy link
Contributor

cmlh commented Dec 8, 2022

@tghosth wrote:

@cmlh are #1360, #1361 and #1365 the only things that are missing from ASVS compared to MSVP? If so, can we close this original issue?

Nope, I took a sampling of the major differences so once we've selected what we want to integrate then I can raise the related MSVP Controls as additional GitHub issues.

@tghosth
Copy link
Collaborator

tghosth commented Dec 18, 2022

I am open to suggestions if you feel there are additional gaps

@tghosth
Copy link
Collaborator

tghosth commented Dec 18, 2022

@set-reminder 2 weeks decide what to do depending on response

@octo-reminder
Copy link

octo-reminder bot commented Dec 18, 2022

Reminder
Sunday, January 1, 2023 12:00 AM (GMT+01:00)

decide what to do depending on response

@octo-reminder
Copy link

octo-reminder bot commented Dec 20, 2022

🔔 @tghosth

decide what to do depending on response

@tghosth
Copy link
Collaborator

tghosth commented Dec 21, 2022

@cmlh are you going to go through and suggest items in msvp that do not exist in ASVS?

@set-reminder 4 weeks @tghosth to decide what to do if no response

@octo-reminder
Copy link

octo-reminder bot commented Dec 21, 2022

Reminder
Wednesday, January 18, 2023 12:00 AM (GMT+01:00)

@tghosth to decide what to do if no response

@elarlang
Copy link
Collaborator

I think he did already.

https://github.com/OWASP/ASVS/issues?q=is%3Aissue+mvsp

@octo-reminder
Copy link

octo-reminder bot commented Dec 31, 2022

🔔 @tghosth

decide what to do depending on response

@cmlh
Copy link
Contributor

cmlh commented Jan 7, 2023

Nope, I haven't completed this yet due to lack of availability.

@tghosth
Copy link
Collaborator

tghosth commented Jan 8, 2023

So I am leaving it open for now so let me know

@tghosth tghosth removed their assignment Jan 8, 2023
@octo-reminder
Copy link

octo-reminder bot commented Jan 17, 2023

🔔 @tghosth

@tghosth to decide what to do if no response

@tghosth tghosth added _5.0 - Not blocker This issue does not block 5.0 so if it gets addressed then great, if not then fine. and removed _5.0 - prep This needs to be addressed to prepare 5.0 reminder labels Mar 14, 2023
@tghosth
Copy link
Collaborator

tghosth commented Mar 14, 2023

I have moved this to non-blocker and @cmlh is welcome to revisit this when he gets time

@cmlh
Copy link
Contributor

cmlh commented Apr 5, 2023

Below how I will track the inclusion of MSVP into ASVS as GitHub's Project isn't enabled.

CHANGELOG

5 April 2023 - Initial Draft
6 April 2023 - Insert "1.1 Vulnerability reports"
7 April 2023 - Insert "1.2 Customer testing"
8 April 2023 - Insert "1.3 Self assessment"
9 April 2023 - Insert "1.4 External testing" and "1.5 Training"
11 April 2023 - Insert "1.8 Data handling"
15 April 2023 - Insert "2.1 Single Sign On"
20 April 2023 - Insert "2.2 HTTPS-only:
13 July 2023 - Insert "2.3 Security Headers", "2.5 Security Headers" and "2.6 Dependency Patching"

@jmanico
Copy link
Member Author

jmanico commented Nov 5, 2024

I am closing this out since ASVS 5.0 is too busy as it is. Please open new individual issues for new requirements that we do not cover if you think we missed anything.

@jmanico jmanico closed this as completed Nov 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
2) Awaiting response Awaiting a response from the original poster _5.0 - Not blocker This issue does not block 5.0 so if it gets addressed then great, if not then fine.
Projects
None yet
Development

No branches or pull requests

4 participants