Skip to content

docs(proposal): create reusable artifact contribution guide #8

Description

@hbraswelrh

Description

The Gemara schemas are already used to express Control Catalogs, Threat Catalogs, and Guidance Catalogs across the FINOS CCC & OSPS Baseline projects. The procedure for proposing reusable catalogs is not documented. Therefore, it's difficult for contributors to essentially "donate" catalogs to the ecosystem because there isn't a centralized place for finding reusable catalogs.

Expected Solution

Create a guide and set of criteria for contributors to share reusable catalogs to the Gemara ecosystem.

Things to Consider

  1. What makes a Catalog within the 7-layer architecture "reusable?"
  2. What level of review must be completed to ensure the proposed Catalog(s) are accurate apart from schema-validation?
  3. What is the maintenance cycle for the Catalog(s)?

Supporting Resources

  • Discussion in the community looking to donate catalogs

Metadata

Metadata

Assignees

Labels

documentationImprovements or additions to documentationenhancementNew feature or request

Type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions