Skip to content

Add BSI-TR-03185-2 reference IDs to OSPS-AC.yaml#461

Open
SecurityCRob wants to merge 5 commits intomainfrom
SecurityCRob-patch-10
Open

Add BSI-TR-03185-2 reference IDs to OSPS-AC.yaml#461
SecurityCRob wants to merge 5 commits intomainfrom
SecurityCRob-patch-10

Conversation

@SecurityCRob
Copy link
Contributor

adding mappings for BSI

adding mappings for BSI

Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
@SecurityCRob
Copy link
Contributor Author

SecurityCRob commented Jan 13, 2026

depends on:
#459
#460

related to:
#461
#462
#463
#464
#465
#466
#467

eddie-knight
eddie-knight previously approved these changes Jan 16, 2026
reacting to Eddie's observation.  BSI GV.02 related to our AC-01.  Thanks for catching my transcription error!

Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
Copy link
Contributor

@evankanderson evankanderson left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm wondering if GV.02 ("The project's repository, websites and sensitive data MUST be protected against unauthorized actions") maps more broadly than specified by the PDF; it seems like it would also map to AC-02 and possibly AC-03 here, along with BR-07 and BR-01 in your other PR.

I also agree with Eddie's comment on QA-07 being a better stronger mapping for the BSI's QA.06, but that's in a different file, so I'll comment there.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants