-
Notifications
You must be signed in to change notification settings - Fork 1
Inclusion of validation scripts #5
Description
Author Use Case: As a product vendor, service provider or 3rd party, I want to provide product/service consumers with validation scripts and other resources that enable automated verification that a component was deployed with configuration settings that align with the relevant requirements of a specific framework.
Consumer Use Case: As a system ISSO that needs to ensure deployed components comply with a specific framework, I want to consume pre-existing validation scripts and other resources that enable me to verify framework requirements remain satisfied at any point in time.
Example: Whether engineers are leveraging a database product from a vendor or a database service from a cloud service provider, I want to use automation to verify the product or service was initially deployed to satisfy the requirements of a target framework, and then periodically re-verify the product/service remains in compliance.
This is a critical building block for system-wide automated continuous assessment/compliance validation.