Skip to content

Add BSI TR-03185-2 mapping reference#460

Open
SecurityCRob wants to merge 1 commit intomainfrom
SecurityCRob-patch-8
Open

Add BSI TR-03185-2 mapping reference#460
SecurityCRob wants to merge 1 commit intomainfrom
SecurityCRob-patch-8

Conversation

@SecurityCRob
Copy link
Contributor

Added mapping reference for BSI TR-03185-2 including title, version, URL, and description.

Added mapping reference for BSI TR-03185-2 including title, version, URL, and description.

Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
@SecurityCRob
Copy link
Contributor Author

SecurityCRob commented Jan 13, 2026

depends on:
#459
#460

related to:
#461
#462
#463
#464
#465
#466
#467

@eddie-knight
Copy link
Contributor

@funnelfiasco this is also just metadata, should be a quick merge

Copy link
Contributor

@evankanderson evankanderson left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(I don't see changes needed, but I wanted to point out a relation with earlier mapping challenges.)

Comment on lines +26 to +30
Secure software is essential for the use of IT products in governments,
businesses and societies. The German Federal Office for Information
Security (BSI) appeals to all relevant stakeholders to consider information
security from the outset and to ease estimating a software component’s
security posture as far as possible in order to enable its secure use.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks to be the first paragraph from the regulation, which is fine.

In the larger context of these mappings, BSI TR-03185-2 is specifically focused on open source projects, and BSI TR-03185-1 provides equivalent guidance for proprietary software. This is in contrast to unlike the UK SSCOP, which does not differentiate the two, and produced more difficulty in the mappings.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i agree with your assessment. Any suggested action?

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mostly, I was pointing this out as a guideline for future framework mappings. It might also be worth an aside somewhere about differences between proprietary and open source software security (e.g. security by obscurity really doesn't exist, things like build pipelines are generally much more exposed, and it's much easier for malicious actors to propose changes / fork code).

@evankanderson
Copy link
Contributor

One interesting note which I only realized when I was almost done with these reviews is that the BSI TR-03185-2 guidance is based on the 2025-02-25 version of baseline, and we have added and changed controls for the October release and the in-development release (these mappings should be applied to the in-development version, not the "current version").

@eddie-knight
Copy link
Contributor

eddie-knight commented Jan 30, 2026

Agreed @evankanderson — this is another reason that I'd argue in favor of only maintaining outgoing mappings. The mappings we add here are going into a future version of our catalog, which the BSI work did not consider when they mapped to the feb25 release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants