Giter Club home page Giter Club logo

oxomium's Introduction

Pylint Error Django CI Dependency Review

Quality Gate Status Security Rating Maintainability Rating Reliability Rating Technical Debt Duplicated Lines (%) Coverage

Oxomium Project

Oxomium is an opensource project build to help company to manage the cybersecurity compliance of organisations.

It provides help to CISO or other security people to follow conformity to a Policy.

More information on Oxomium Website.

An online demonstration in available with user demo and password 6NLYm6F4PBBQBjc: Oxomium Demo

A wiki page detail the process of installation.

oxomium's People

Contributors

pep-un avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar

oxomium's Issues

Update of data model

The Organization - Policy - Mesure indirection append to be painfull.
We probably need to get ride of the Policy class and represent Policy as a bunch of Mesure

Email notification for action

Create a planed report to receive daily / weekly / monthly status.
Create an email notification for action near to expiration date.

Add a planning of control

Add a new menu to see the plan of controls my year/months/weeks and be able to planifie unplaned control or replanifie the existing one.

Security reveiw

Review the OWASP TOP 10, an describe in Security.md how we handle each risque.

Refactor classes name

Classes names are not coherant with the wording used in ISO27000 framwork.

To have a more clear code and interface it's importante to clarify the wording and to update the classes names and display accordingly.

Implement direct link between Actions, Conformities and Findings

Add link to creat Actions from Conformiy and Finding.
Add the visibility on the number of action listed to a Conformity or a Finding.
Add direct link to the list of action related to a Conformity or an Finding

Had link to open Finding or Conformity from Action. (Detail View or in the form ?)

Implement Cybersecurity Continuous Improvement Plan

CCIP should allow to have an hoverview of all Actions with teh followinf information :

  • the phase : Plan Do Check Act (or something else ? PCAS / DMAIC / A3 / 8D / PSP ?)
  • Planification date, estimated and effective start date and end date
  • the status (0% to 100%) with update date
  • the owner,
  • the priority,
  • the associated Policy/Measure,
  • the Organization,
  • the formal Check by who and when
  • Comment
  • others ?

Add a "my actions" page

This page must provide an overview off all item affected to the user (compliance, audit, CAPA, ...)

Upgrade forms

Upgrade forms tom implemente logics and restrictions.
For exemple, if a Conformity is not applicable, all other field should be disabled.

Conformity evaluation methode

The conformity is actualy evaluat an a scal from 0 to 100.

Other system may be more pertinant :

  • CMMI Maturity level
  • Conform / parcialy conforme / unconforme
  • Scan from 1 to 5

What is the best choice ?

Extend User model

Extend User Model to implement Organization attachement and Organization based restriction

Add background job to update control status

Status must be change automatically at the start of a period from "Scheduled" to "To Be Evaluated".

Additionally, at the end of the period, they must be changed to Missed, if they ave not been evaluated.

Implement the Mesure/Conformity logic

When we affect a Policy to an Organization, we need te create automaticaly all Conformity item.
At the revers, we need to delete them when the Policy is unassociate.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.