diff --git a/baseline/OSPS-GV.yaml b/baseline/OSPS-GV.yaml index 03f78b6..ec65fbe 100644 --- a/baseline/OSPS-GV.yaml +++ b/baseline/OSPS-GV.yaml @@ -6,29 +6,7 @@ description: | that the project is well positioned to respond to both threats and opportunities. criteria: - - id: OSPS-GV-01 - maturity_level: 2 - criterion: | - The project documentation MUST include the - Roles and Responsibilities for members of the - project. - rationale: | - Documenting project roles and responsibilities - helps project particpants, potential contributors, - and downstream consumers have an accurate - understand of who is working on the project - and what areas of authority they may have. - implementation: | - Document project participants and their roles - through such artifacts as members.md, governance.md, - maintainers.md, or similar file within the source - code repository of the project. - control_mappings: - BPB: B-S-3, B-S-4 - OCRE: 013-021 - security_insights_value: # TODO - - - id: OSPS-GV-02 + - id: OSPS-GV-101 maturity_level: 1 criterion: | The project MUST have one or more mechanisms @@ -55,7 +33,7 @@ criteria: OCRE: security_insights_value: # TODO - - id: OSPS-GV-03 + - id: OSPS-GV-102 maturity_level: 1 criterion: | The project documentation MUST include an @@ -77,7 +55,29 @@ criteria: SSDF: PW1.2 security_insights_value: # TODO - - id: OSPS-GV-04 + - id: OSPS-GV-201 + maturity_level: 2 + criterion: | + The project documentation MUST include the + Roles and Responsibilities for members of the + project. + rationale: | + Documenting project roles and responsibilities + helps project particpants, potential contributors, + and downstream consumers have an accurate + understand of who is working on the project + and what areas of authority they may have. + implementation: | + Document project participants and their roles + through such artifacts as members.md, governance.md, + maintainers.md, or similar file within the source + code repository of the project. + control_mappings: + BPB: B-S-3, B-S-4 + OCRE: 013-021 + security_insights_value: # TODO + + - id: OSPS-GV-202 maturity_level: 2 criterion: | The project documentation MUST include a @@ -106,7 +106,7 @@ criteria: OC: 4.1.2 security_insights_value: # TODO - - id: OSPS-GV-05 + - id: OSPS-GV-203 maturity_level: 2 criterion: | The project documentation MUST have a policy