-
Notifications
You must be signed in to change notification settings - Fork 535
Mapping DNSSI 2023 ↔ ISO/IEC 27001:2022 #2820
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
When writing a custom `get_object` method in a viewset, we must perform call `self.check_object_permissions(request, obj)`. Otherwise, `RBACPermissions.has_object_permission` will **not** be called.
New format is <branch>-<timestamp>-<artifact name>
…-uploaded-artifacts
) Co-authored-by: eric-intuitem <[email protected]>
Update convential_commits.md
fix broken word export when IG name is a number
Update README.md
Fix autocomplete arraysEqual
* starting point * variant with filesystem - experimental * First implementation * checkpoint * checkpoint * checkpoint valkey * sqlite backend for huey, compatible with pg for the rest of the app * compose preperation * Introduce MAIL_DEBUG env variable * checkpoint * logging and error management * wip * target value * slow down the scheduler given the current use cases to save CPU * fixup * back to default worker class for now * Use the global setting and default to false
…em#1430) * small optimizations of library presentation headers * Ajustement du code pour CI Semantics
* Check permissions for each model to import before attempting to create objects * Wrap form return values with withFiles wrapper * Localize domain import permission denied error * Style domain import button * Remove dead code * Tidy import domain functions * Use RoleAsignment.is_access_allowed rather than user.permissions * Enforce RBAC on domain export * chore: Remove duplicate import
Co-authored-by: Mohamed-Hacene <[email protected]>
intuitem#1431) Add files via upload Added so called elementary threats by german BSI in order to assign in risk-management
annotated base query for better perf
…em#1444) * wip * wip * wip * checkpoint * ready for review
…ios (intuitem#1442) * freat: current/residual criticality filters for risk scenarios * fix: created correct filter * fix: minor fix
…item#1445) Expose extra variables for a more flexible infra tuning
* checkpoint * error management * Moving component * counters asynchronously as well * clean up and cleaner syntax
* Align EE settings * Fix languages
* feat: check required libraries after domain creation * feat: improve error handling * chore: format
* Add a progress field on applied controls * changed save model function & regionalize * inverse colors and add a validator on the progress field model
* fix: diffentiate cell's tooltips using matrixName% * fix: typo and code readability
* Increase limit_request_line param for gunicorn Increase limit_request_line param for gunicorn, this allows some IDP (such as GoAuthentik) provider to work as the request line often goes beyond the default value of 4094. * Update startup.sh Forgot backslash...
…1451) * put entityy mendatory with red star UI * changed implementation
|
Warning Rate limit exceeded@Qnadia has exceeded the limit for the number of commits or files that can be reviewed per hour. Please wait 28 minutes and 11 seconds before requesting another review. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ⛔ Files ignored due to path filters (5)
📒 Files selected for processing (107)
✨ Finishing touches
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
nas-tabchiche
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Cette Pull Request ajoute le fichier map-DNSSI_2023-iso27001_2022.yml, qui relie la Directive Nationale de la Sécurité des Systèmes d’Information (DNSSI 2023) aux mesures de sécurité de l’ISO/IEC 27001 : 2022.
Contenu du fichier :
Alignement des règles opérationnelles DNSSI 2023 avec les contrôles ISO 27002 : 2022
Références croisées entre les objectifs marocains (Gouvernance, Risques, SSI) et les domaines ISO
Objectif :
Permettre l’analyse automatique de conformité entre les politiques nationales marocaines (DGSSI) et le cadre ISO 27001 : 2022, pour soutenir la gouvernance de la cybersécurité et la préparation aux audits.