Add COR.INF controls

Signed-off-by: gearnode <bryan@frimin.fr>
This commit is contained in:
gearnode
2025-01-14 16:43:15 +01:00
parent c0a45a8c16
commit 3f3bcc48b5
10 changed files with 478 additions and 8 deletions

View File

@@ -0,0 +1,35 @@
---
id: "COR.SRC.002"
category: "core/src"
revision-version: 1
revision-date: "2024-01-07"
estimate-time: "15m"
necessity: "optional"
frameworks:
- name: "soc2"
sections: ["CC4.1", "CC8.1"]
---
# Configure Code Scanning
## Purpose
It ensures that potential security flaws are detected early. This proactive
approach strengthens your security posture and helps maintain high code quality.
## Implementation
### Github
1. Go to the "Security" tab of your repository.
2. Click on "Set up code scanning".
3. Select "Set up this workflow" under "CodeQL Analysis".
4. Review the YAML file and commit it to your repository.
Code scanning will now run every time code is pushed to the repository, and
results will appear in the Security tab.
## Evidence
- Screenshot of code scanning results from Security tab
- Sample of resolved security alerts