441 lines
12 KiB
JSON
441 lines
12 KiB
JSON
{
|
|
"version": "1.0",
|
|
"framework": "cra",
|
|
"controls": [
|
|
{
|
|
"control": "cra-ai-1",
|
|
"title": "Secure-by-Default-Konfiguration",
|
|
"scans": [
|
|
{
|
|
"tool": "semgrep",
|
|
"scan_type": "sast",
|
|
"cwe": [],
|
|
"rules": [
|
|
"cra-ai-1-flask-debug-enabled",
|
|
"cra-ai-1-django-debug-true",
|
|
"cra-ai-1-tls-verify-disabled",
|
|
"cra-ai-1-cors-wildcard"
|
|
]
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-2",
|
|
"title": "Minimale Angriffsflaeche",
|
|
"scans": [],
|
|
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-3",
|
|
"title": "Sichere Systemarchitektur",
|
|
"scans": [],
|
|
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-4",
|
|
"title": "Least-Privilege-Prinzip",
|
|
"scans": [],
|
|
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-5",
|
|
"title": "Manipulationsschutz",
|
|
"scans": [],
|
|
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-6",
|
|
"title": "Integritaetspruefung",
|
|
"scans": [],
|
|
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-7",
|
|
"title": "Starke Authentifizierung",
|
|
"scans": [
|
|
{
|
|
"tool": "semgrep",
|
|
"scan_type": "sast",
|
|
"cwe": [],
|
|
"rules": [
|
|
"cra-ai-7-weak-password-hash"
|
|
]
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-8",
|
|
"title": "Keine Default-Passwoerter",
|
|
"scans": [
|
|
{
|
|
"tool": "gitleaks",
|
|
"scan_type": "secret_detection",
|
|
"cwe": [],
|
|
"rules": []
|
|
},
|
|
{
|
|
"tool": "semgrep",
|
|
"scan_type": "sast",
|
|
"cwe": [
|
|
"CWE-798",
|
|
"CWE-259"
|
|
],
|
|
"rules": []
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-9",
|
|
"title": "Sicheres Credential-Management",
|
|
"scans": [
|
|
{
|
|
"tool": "gitleaks",
|
|
"scan_type": "secret_detection",
|
|
"cwe": [],
|
|
"rules": []
|
|
},
|
|
{
|
|
"tool": "semgrep",
|
|
"scan_type": "sast",
|
|
"cwe": [
|
|
"CWE-798",
|
|
"CWE-522"
|
|
],
|
|
"rules": []
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-10",
|
|
"title": "Sitzungsmanagement",
|
|
"scans": [
|
|
{
|
|
"tool": "semgrep",
|
|
"scan_type": "sast",
|
|
"cwe": [],
|
|
"rules": [
|
|
"cra-ai-10-session-cookie-insecure",
|
|
"cra-ai-10-express-cookie-insecure"
|
|
]
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-11",
|
|
"title": "Brute-Force-Schutz",
|
|
"scans": [],
|
|
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-12",
|
|
"title": "Rollenbasierte Autorisierung",
|
|
"scans": [],
|
|
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-13",
|
|
"title": "Verschluesselung sensibler Daten",
|
|
"scans": [
|
|
{
|
|
"tool": "semgrep",
|
|
"scan_type": "sast",
|
|
"cwe": [
|
|
"CWE-327",
|
|
"CWE-326"
|
|
],
|
|
"rules": []
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-14",
|
|
"title": "Speicher-Schutz (Data at Rest)",
|
|
"scans": [
|
|
{
|
|
"tool": "semgrep",
|
|
"scan_type": "sast",
|
|
"cwe": [],
|
|
"rules": [
|
|
"cra-ai-14-python-weak-cipher",
|
|
"cra-ai-14-node-weak-cipher"
|
|
]
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-15",
|
|
"title": "Transport-Schutz (Data in Transit)",
|
|
"scans": [
|
|
{
|
|
"tool": "semgrep",
|
|
"scan_type": "sast",
|
|
"cwe": [
|
|
"CWE-319",
|
|
"CWE-311"
|
|
],
|
|
"rules": []
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-16",
|
|
"title": "Sicheres Schluesselmanagement",
|
|
"scans": [
|
|
{
|
|
"tool": "gitleaks",
|
|
"scan_type": "secret_detection",
|
|
"cwe": [],
|
|
"rules": []
|
|
},
|
|
{
|
|
"tool": "semgrep",
|
|
"scan_type": "sast",
|
|
"cwe": [
|
|
"CWE-798",
|
|
"CWE-321"
|
|
],
|
|
"rules": []
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-17",
|
|
"title": "Datenminimierung",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-18",
|
|
"title": "Strukturierter SSDLC",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-19",
|
|
"title": "Systematische Code Reviews",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-20",
|
|
"title": "Automatisierte Sicherheitstests",
|
|
"scans": [
|
|
{
|
|
"tool": "semgrep",
|
|
"scan_type": "sast",
|
|
"cwe": [
|
|
"CWE-89",
|
|
"CWE-78",
|
|
"CWE-79",
|
|
"CWE-22"
|
|
],
|
|
"rules": []
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-21",
|
|
"title": "Supply-Chain-Security",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-22",
|
|
"title": "Dependency-Monitoring",
|
|
"scans": [
|
|
{
|
|
"tool": "osv",
|
|
"scan_type": "cve",
|
|
"cwe": [],
|
|
"rules": []
|
|
},
|
|
{
|
|
"tool": "syft",
|
|
"scan_type": "sbom",
|
|
"cwe": [],
|
|
"rules": []
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-23",
|
|
"title": "Software Bill of Materials (SBOM)",
|
|
"scans": [
|
|
{
|
|
"tool": "syft",
|
|
"scan_type": "sbom",
|
|
"cwe": [],
|
|
"rules": []
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-24",
|
|
"title": "Security-Logging",
|
|
"scans": [],
|
|
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-25",
|
|
"title": "Ereignis-Monitoring",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-26",
|
|
"title": "Anomalie-Erkennung",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-27",
|
|
"title": "Log-Integritaet und -Aufbewahrung",
|
|
"scans": [],
|
|
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-28",
|
|
"title": "Sichere Update-Mechanismen",
|
|
"scans": [],
|
|
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-29",
|
|
"title": "Update-Authentizitaet",
|
|
"scans": [],
|
|
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-30",
|
|
"title": "Update-Integritaet",
|
|
"scans": [],
|
|
"note": "absence-based — no syntactic pattern; covered by the grounded surface check (retrieve surface + LLM judge), gated (BREAKPILOT_GROUNDED_CHECKS) pending live tuning",
|
|
"status": "needs_tooling"
|
|
},
|
|
{
|
|
"control": "cra-ai-31",
|
|
"title": "Lifecycle-Support",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-32",
|
|
"title": "Schwachstellen-Identifikation",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-33",
|
|
"title": "SBOM-Pflege und Analyse",
|
|
"scans": [
|
|
{
|
|
"tool": "syft",
|
|
"scan_type": "sbom",
|
|
"cwe": [],
|
|
"rules": []
|
|
},
|
|
{
|
|
"tool": "osv",
|
|
"scan_type": "cve",
|
|
"cwe": [],
|
|
"rules": []
|
|
}
|
|
],
|
|
"note": null,
|
|
"status": "covered"
|
|
},
|
|
{
|
|
"control": "cra-ai-34",
|
|
"title": "Risikobasierte Priorisierung",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-35",
|
|
"title": "Coordinated Vulnerability Disclosure",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-36",
|
|
"title": "Incident-Response-Prozess",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-37",
|
|
"title": "Fruehwarnung (24h)",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-38",
|
|
"title": "Detaillierter Vorfallsbericht (72h)",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-39",
|
|
"title": "Patch-Bereitstellung",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
},
|
|
{
|
|
"control": "cra-ai-40",
|
|
"title": "Dokumentation und Nachbereitung",
|
|
"scans": [],
|
|
"note": "process / document control — outside static-scan scope",
|
|
"status": "not_code_checkable"
|
|
}
|
|
]
|
|
}
|