-
Notifications
You must be signed in to change notification settings - Fork 38
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Dedupe NIST tags for 2inspec tools #93
Comments
@ejaronne Do you have any input on this? I believe I mentioned this to you at one point and you suggested leaving the duplicates for conversion back to xccdf but I could be misremembering the conversation. |
However, the other thing I would not hear is that since we don’t actually
keep the relationship intact There really isn’t any need to have multiple
data elements in the array. We ever needed to find the association we could
look at the XML and the CCI to find out which 853 control it belongs to
On Tue, Nov 23, 2021 at 6:41 PM Eugene Aronne ***@***.***> wrote:
This is intended to emulate exactly the related controls from the DISA
STIG itself. It is not a duplication. In this case, multiple CCI's support
different aspects of AC-2(4), as shown in the DISA STIG Viewer:
[image: image]
<https://user-images.githubusercontent.com/34140975/143145961-8bfdbe59-6305-493d-8a4f-1488db0b9246.png>
—
You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub
<mitre/saf#93>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/AALK42FSQDYJXWM4HAP5IX3UNQRCZANCNFSM5FTYIMZA>
.
--
--------
Aaron Lippold
***@***.***
260-255-4779
twitter/aim/yahoo,etc.
'aaronlippold'
|
Just wanted to bring this back up. I believe it still is a duplication of data. STIG Viewer displays this data differently as it shows each CCI and it's corresponding NIST control family where as in InSpec these are separate lists with no relation of CCI to NIST and should be deduped. The NIST data isn't even in the XCCDF so converting back and forth should not be a concern. STIG Viewer is adding that data based on CCI and so are all of the MITRE tools. |
Yes, I think we can and a |
STIG controls with multiple SRG IDs and therefore multiple CCIs often reference the same NIST control family. When running for example xccdf2inspec and this scenario occurs there will be multiple NIST tags that are the same.
For example:
The text was updated successfully, but these errors were encountered: