Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Export to Checklist populates too many CCIs based on NIST Tag #6359

Open
ejaronne opened this issue Nov 4, 2024 · 2 comments
Open

Export to Checklist populates too many CCIs based on NIST Tag #6359

ejaronne opened this issue Nov 4, 2024 · 2 comments
Assignees
Labels
bug Something isn't working

Comments

@ejaronne
Copy link
Contributor

ejaronne commented Nov 4, 2024

To re-create:

On https://heimdall-lite.mitre.org/ load OWASP ZAP Webgoat sample. Export to checklist. Load that file also into Heimdall:

image

The Export takes SC-8 and instead of looking up only SC-8 or SC-8 a, b, c partials, inadvertently and incorrectly grabs control enhancements such as SC-8 (1), SC-8 (2), etc.

We need to enhance the algorithm to be more precise. Adding so many controls will confuse and stress users.

@ejaronne ejaronne added the bug Something isn't working label Nov 4, 2024
@aaronlippold
Copy link
Member

And why doesn't the control above it? Have a CCI as well

@aaronlippold
Copy link
Member

The number of CCI should never exceeded the number of 853 controls

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

4 participants