Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New Common Controls policy for Early Access App Access controls #371

Merged
merged 14 commits into from
Sep 17, 2024

Conversation

jkaufman-mitre
Copy link
Collaborator

@jkaufman-mitre jkaufman-mitre commented Aug 29, 2024

🗣 Description

Added Policy Group 18 to Common Controls Baseline for Early Access Apps

Code changes tracked in #402.

💭 Motivation and context

Closes #370

  • Google Product Update

🧪 Testing

N/A, this PR does not add any new code

✅ Pre-approval checklist

  • This PR has an informative and human-readable title.
  • Changes are limited to a single goal - eschew scope creep!
  • If applicable, All future TODOs are captured in issues, which are referenced in the PR description.
  • The relevant issues PR resolves are linked preferably via closing keywords.
  • All relevant type-of-change labels have been added.
  • I have read and agree to the CONTRIBUTING.md document.
  • These code changes follow cisagov code standards.
  • All relevant repo and/or project documentation has been updated to reflect the changes in this PR.

✅ Pre-merge Checklist

  • This PR has been smoke tested to ensure main is in a functional state when this PR is merged.
  • Squash all commits into one PR level commit using the Squash and merge button.

✅ Post-merge Checklist

  • Delete the branch to clean up.
  • Close issues resolved by this PR if the closing keywords did not activate.

@mdueltgen mdueltgen added this to the Driftwood milestone Aug 29, 2024
Copy link
Collaborator

@buidav buidav left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

initial comments

baselines/commoncontrols.md Outdated Show resolved Hide resolved
baselines/commoncontrols.md Outdated Show resolved Hide resolved
baselines/commoncontrols.md Outdated Show resolved Hide resolved
Copy link
Collaborator

@adhilto adhilto left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I agree with David's comments. One more thing to consider:

baselines/commoncontrols.md Outdated Show resolved Hide resolved
baselines/commoncontrols.md Outdated Show resolved Hide resolved
baselines/commoncontrols.md Outdated Show resolved Hide resolved
baselines/commoncontrols.md Outdated Show resolved Hide resolved
baselines/commoncontrols.md Outdated Show resolved Hide resolved
baselines/commoncontrols.md Outdated Show resolved Hide resolved
baselines/commoncontrols.md Outdated Show resolved Hide resolved
baselines/commoncontrols.md Outdated Show resolved Hide resolved
@mdueltgen mdueltgen self-assigned this Sep 12, 2024
@mdueltgen mdueltgen removed their request for review September 12, 2024 17:35
@buidav buidav changed the title 370 early access app access common controls New Common Controls policy for Early Access App Access controls Sep 16, 2024
baselines/commoncontrols.md Outdated Show resolved Hide resolved
@buidav buidav merged commit ea23ae5 into driftwood Sep 17, 2024
2 checks passed
@buidav buidav deleted the 370-early-access-app-access-common-controls branch September 17, 2024 17:08
adhilto added a commit that referenced this pull request Oct 3, 2024
* Added Policy Group 18

* Added Drift Rule for Policy Group 18

* Fixed Table of Contents

* Apply suggestions from code review

Co-authored-by: Alden Hilton <[email protected]>
Co-authored-by: David Bui <[email protected]>

* Fixed Implementation

* Added Policy Under Policy Group 16

* Fixed Policy Group 16 Intro

* Changed Security to Secure in header

* Fixed TOC

* Apply suggestions from code review

Co-authored-by: Alden Hilton <[email protected]>

* Apply suggestions from code review

Co-authored-by: David Bui <[email protected]>

* Fixed drift rule files

* Update baselines/commoncontrols.md

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: Alden Hilton <[email protected]>
Co-authored-by: David Bui <[email protected]>
Co-authored-by: mdueltgen <[email protected]>
adhilto added a commit that referenced this pull request Oct 3, 2024
* Updated Resource Link for DriveDocs 3.1 (#400)

* Fixes Numbering Issue in GMAIL 5.3 Instructions (#399)

* Fixed numbering issue in instruction for 5.3

* Update baselines/gmail.md

End with a period for automation processing reasons.

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: David Bui <[email protected]>

* Updating Classroom 1.2 Instructions (#407)

* New Common Controls policy for Early Access App Access controls (#371)

* Added Policy Group 18

* Added Drift Rule for Policy Group 18

* Fixed Table of Contents

* Apply suggestions from code review

Co-authored-by: Alden Hilton <[email protected]>
Co-authored-by: David Bui <[email protected]>

* Fixed Implementation

* Added Policy Under Policy Group 16

* Fixed Policy Group 16 Intro

* Changed Security to Secure in header

* Fixed TOC

* Apply suggestions from code review

Co-authored-by: Alden Hilton <[email protected]>

* Apply suggestions from code review

Co-authored-by: David Bui <[email protected]>

* Fixed drift rule files

* Update baselines/commoncontrols.md

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: Alden Hilton <[email protected]>
Co-authored-by: David Bui <[email protected]>
Co-authored-by: mdueltgen <[email protected]>

* Updated Location of Setting in DriveDocs 6.1 Instructions (#404)

* Updated location of setting in instructions and fixed bolding

* Update baselines/drive.md

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: David Bui <[email protected]>

* Updating Common Controls 11.2 Implementation Instructions #375 (#411)

* updated location of setting in implementation instructions

* adding in periods

* Update baselines/commoncontrols.md

Co-authored-by: David Bui <[email protected]>

* Update baselines/commoncontrols.md

removed extra period

Co-authored-by: David Bui <[email protected]>

* Remove double period in overview

---------

Co-authored-by: David Bui <[email protected]>

* Updating Common Controls 12.1 Implementation Steps (#414)

* Updated location for takeout admin control based on update to data tab in admin console

* Update baselines/commoncontrols.md

Fixes capitalization of import/export per admin console

Co-authored-by: Alden Hilton <[email protected]>

* removing unnecessary save step

---------

Co-authored-by: Alden Hilton <[email protected]>

* Update location of rules setting in admin console in implementation steps. (#418)

* Updating Common Controls 15.1 Implementation Steps (#420)

* udpated location of setting for data regions in instructions

* Update baselines/commoncontrols.md

removed S in compliances

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: David Bui <[email protected]>

* Fixed backslashes/forwardslashes bug in Common Controls Baseline (#426)

* Changed Early Access to Early Access Apps (#428)

* Add Data at Rest processing policy to Common Controls baseline (#434)

* Added Policy 15.2 and renamed previous 15.2 to 15.3

* adding drift rule for 15.2

* Added TTP Mappings

* Apply suggestions from code review

Co-authored-by: Alden Hilton <[email protected]>

* Update drift-rules/GWS Drift Monitoring Rules - Common Controls as of 11-14-23.csv

Co-authored-by: Alden Hilton <[email protected]>

* Apply suggestions from code review

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: mdueltgen <[email protected]>
Co-authored-by: Alden Hilton <[email protected]>
Co-authored-by: David Bui <[email protected]>

* updating implementation steps for 13.1 to clarify editting rules

* fixed numbering and removed old language about having to click show more which doesn't exist anymore in the admin consle.

* Apply suggestions from code review

Co-authored-by: Alden Hilton <[email protected]>

* Update baselines/commoncontrols.md

Co-authored-by: Alden Hilton <[email protected]>

---------

Co-authored-by: David Bui <[email protected]>
Co-authored-by: jkaufman-mitre <[email protected]>
Co-authored-by: Alden Hilton <[email protected]>
adhilto added a commit that referenced this pull request Oct 15, 2024
* Added Policy Group 18

* Added Drift Rule for Policy Group 18

* Fixed Table of Contents

* Apply suggestions from code review

Co-authored-by: Alden Hilton <[email protected]>
Co-authored-by: David Bui <[email protected]>

* Fixed Implementation

* Added Policy Under Policy Group 16

* Fixed Policy Group 16 Intro

* Changed Security to Secure in header

* Fixed TOC

* Apply suggestions from code review

Co-authored-by: Alden Hilton <[email protected]>

* Apply suggestions from code review

Co-authored-by: David Bui <[email protected]>

* Fixed drift rule files

* Update baselines/commoncontrols.md

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: Alden Hilton <[email protected]>
Co-authored-by: David Bui <[email protected]>
Co-authored-by: mdueltgen <[email protected]>
adhilto added a commit that referenced this pull request Oct 15, 2024
* Updated Resource Link for DriveDocs 3.1 (#400)

* Fixes Numbering Issue in GMAIL 5.3 Instructions (#399)

* Fixed numbering issue in instruction for 5.3

* Update baselines/gmail.md

End with a period for automation processing reasons.

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: David Bui <[email protected]>

* Updating Classroom 1.2 Instructions (#407)

* New Common Controls policy for Early Access App Access controls (#371)

* Added Policy Group 18

* Added Drift Rule for Policy Group 18

* Fixed Table of Contents

* Apply suggestions from code review

Co-authored-by: Alden Hilton <[email protected]>
Co-authored-by: David Bui <[email protected]>

* Fixed Implementation

* Added Policy Under Policy Group 16

* Fixed Policy Group 16 Intro

* Changed Security to Secure in header

* Fixed TOC

* Apply suggestions from code review

Co-authored-by: Alden Hilton <[email protected]>

* Apply suggestions from code review

Co-authored-by: David Bui <[email protected]>

* Fixed drift rule files

* Update baselines/commoncontrols.md

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: Alden Hilton <[email protected]>
Co-authored-by: David Bui <[email protected]>
Co-authored-by: mdueltgen <[email protected]>

* Updated Location of Setting in DriveDocs 6.1 Instructions (#404)

* Updated location of setting in instructions and fixed bolding

* Update baselines/drive.md

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: David Bui <[email protected]>

* Updating Common Controls 11.2 Implementation Instructions #375 (#411)

* updated location of setting in implementation instructions

* adding in periods

* Update baselines/commoncontrols.md

Co-authored-by: David Bui <[email protected]>

* Update baselines/commoncontrols.md

removed extra period

Co-authored-by: David Bui <[email protected]>

* Remove double period in overview

---------

Co-authored-by: David Bui <[email protected]>

* Updating Common Controls 12.1 Implementation Steps (#414)

* Updated location for takeout admin control based on update to data tab in admin console

* Update baselines/commoncontrols.md

Fixes capitalization of import/export per admin console

Co-authored-by: Alden Hilton <[email protected]>

* removing unnecessary save step

---------

Co-authored-by: Alden Hilton <[email protected]>

* Update location of rules setting in admin console in implementation steps. (#418)

* Updating Common Controls 15.1 Implementation Steps (#420)

* udpated location of setting for data regions in instructions

* Update baselines/commoncontrols.md

removed S in compliances

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: David Bui <[email protected]>

* Fixed backslashes/forwardslashes bug in Common Controls Baseline (#426)

* Changed Early Access to Early Access Apps (#428)

* Add Data at Rest processing policy to Common Controls baseline (#434)

* Added Policy 15.2 and renamed previous 15.2 to 15.3

* adding drift rule for 15.2

* Added TTP Mappings

* Apply suggestions from code review

Co-authored-by: Alden Hilton <[email protected]>

* Update drift-rules/GWS Drift Monitoring Rules - Common Controls as of 11-14-23.csv

Co-authored-by: Alden Hilton <[email protected]>

* Apply suggestions from code review

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: mdueltgen <[email protected]>
Co-authored-by: Alden Hilton <[email protected]>
Co-authored-by: David Bui <[email protected]>

* updating implementation steps for 13.1 to clarify editting rules

* fixed numbering and removed old language about having to click show more which doesn't exist anymore in the admin consle.

* Apply suggestions from code review

Co-authored-by: Alden Hilton <[email protected]>

* Update baselines/commoncontrols.md

Co-authored-by: Alden Hilton <[email protected]>

---------

Co-authored-by: David Bui <[email protected]>
Co-authored-by: jkaufman-mitre <[email protected]>
Co-authored-by: Alden Hilton <[email protected]>
buidav added a commit that referenced this pull request Oct 29, 2024
* Updated Resource Link for DriveDocs 3.1 (#400)

* Fixes Numbering Issue in GMAIL 5.3 Instructions (#399)

* Fixed numbering issue in instruction for 5.3

* Update baselines/gmail.md

End with a period for automation processing reasons.

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: David Bui <[email protected]>

* New Common Controls policy for Early Access App Access controls (#371)

* Added Policy Group 18

* Added Drift Rule for Policy Group 18

* Fixed Table of Contents

* Apply suggestions from code review

Co-authored-by: Alden Hilton <[email protected]>
Co-authored-by: David Bui <[email protected]>

* Fixed Implementation

* Added Policy Under Policy Group 16

* Fixed Policy Group 16 Intro

* Changed Security to Secure in header

* Fixed TOC

* Apply suggestions from code review

Co-authored-by: Alden Hilton <[email protected]>

* Apply suggestions from code review

Co-authored-by: David Bui <[email protected]>

* Fixed drift rule files

* Update baselines/commoncontrols.md

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: Alden Hilton <[email protected]>
Co-authored-by: David Bui <[email protected]>
Co-authored-by: mdueltgen <[email protected]>

* Updated Location of Setting in DriveDocs 6.1 Instructions (#404)

* Updated location of setting in instructions and fixed bolding

* Update baselines/drive.md

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: David Bui <[email protected]>

* Updating Common Controls 11.2 Implementation Instructions #375 (#411)

* updated location of setting in implementation instructions

* adding in periods

* Update baselines/commoncontrols.md

Co-authored-by: David Bui <[email protected]>

* Update baselines/commoncontrols.md

removed extra period

Co-authored-by: David Bui <[email protected]>

* Remove double period in overview

---------

Co-authored-by: David Bui <[email protected]>

* Updating Common Controls 12.1 Implementation Steps (#414)

* Updated location for takeout admin control based on update to data tab in admin console

* Update baselines/commoncontrols.md

Fixes capitalization of import/export per admin console

Co-authored-by: Alden Hilton <[email protected]>

* removing unnecessary save step

---------

Co-authored-by: Alden Hilton <[email protected]>

* Update location of rules setting in admin console in implementation steps. (#418)

* Updating Common Controls 15.1 Implementation Steps (#420)

* udpated location of setting for data regions in instructions

* Update baselines/commoncontrols.md

removed S in compliances

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: David Bui <[email protected]>

* Fixed backslashes/forwardslashes bug in Common Controls Baseline (#426)

* Changed Early Access to Early Access Apps (#428)

* Add Data at Rest processing policy to Common Controls baseline (#434)

* Added Policy 15.2 and renamed previous 15.2 to 15.3

* adding drift rule for 15.2

* Added TTP Mappings

* Apply suggestions from code review

Co-authored-by: Alden Hilton <[email protected]>

* Update drift-rules/GWS Drift Monitoring Rules - Common Controls as of 11-14-23.csv

Co-authored-by: Alden Hilton <[email protected]>

* Apply suggestions from code review

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: mdueltgen <[email protected]>
Co-authored-by: Alden Hilton <[email protected]>
Co-authored-by: David Bui <[email protected]>

* Clarifying Implementation Steps of CommonControls13.1 (#445)

* Updated Resource Link for DriveDocs 3.1 (#400)

* Fixes Numbering Issue in GMAIL 5.3 Instructions (#399)

* Fixed numbering issue in instruction for 5.3

* Update baselines/gmail.md

End with a period for automation processing reasons.

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: David Bui <[email protected]>

* Updating Classroom 1.2 Instructions (#407)

* New Common Controls policy for Early Access App Access controls (#371)

* Added Policy Group 18

* Added Drift Rule for Policy Group 18

* Fixed Table of Contents

* Apply suggestions from code review

Co-authored-by: Alden Hilton <[email protected]>
Co-authored-by: David Bui <[email protected]>

* Fixed Implementation

* Added Policy Under Policy Group 16

* Fixed Policy Group 16 Intro

* Changed Security to Secure in header

* Fixed TOC

* Apply suggestions from code review

Co-authored-by: Alden Hilton <[email protected]>

* Apply suggestions from code review

Co-authored-by: David Bui <[email protected]>

* Fixed drift rule files

* Update baselines/commoncontrols.md

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: Alden Hilton <[email protected]>
Co-authored-by: David Bui <[email protected]>
Co-authored-by: mdueltgen <[email protected]>

* Updated Location of Setting in DriveDocs 6.1 Instructions (#404)

* Updated location of setting in instructions and fixed bolding

* Update baselines/drive.md

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: David Bui <[email protected]>

* Updating Common Controls 11.2 Implementation Instructions #375 (#411)

* updated location of setting in implementation instructions

* adding in periods

* Update baselines/commoncontrols.md

Co-authored-by: David Bui <[email protected]>

* Update baselines/commoncontrols.md

removed extra period

Co-authored-by: David Bui <[email protected]>

* Remove double period in overview

---------

Co-authored-by: David Bui <[email protected]>

* Updating Common Controls 12.1 Implementation Steps (#414)

* Updated location for takeout admin control based on update to data tab in admin console

* Update baselines/commoncontrols.md

Fixes capitalization of import/export per admin console

Co-authored-by: Alden Hilton <[email protected]>

* removing unnecessary save step

---------

Co-authored-by: Alden Hilton <[email protected]>

* Update location of rules setting in admin console in implementation steps. (#418)

* Updating Common Controls 15.1 Implementation Steps (#420)

* udpated location of setting for data regions in instructions

* Update baselines/commoncontrols.md

removed S in compliances

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: David Bui <[email protected]>

* Fixed backslashes/forwardslashes bug in Common Controls Baseline (#426)

* Changed Early Access to Early Access Apps (#428)

* Add Data at Rest processing policy to Common Controls baseline (#434)

* Added Policy 15.2 and renamed previous 15.2 to 15.3

* adding drift rule for 15.2

* Added TTP Mappings

* Apply suggestions from code review

Co-authored-by: Alden Hilton <[email protected]>

* Update drift-rules/GWS Drift Monitoring Rules - Common Controls as of 11-14-23.csv

Co-authored-by: Alden Hilton <[email protected]>

* Apply suggestions from code review

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: mdueltgen <[email protected]>
Co-authored-by: Alden Hilton <[email protected]>
Co-authored-by: David Bui <[email protected]>

* updating implementation steps for 13.1 to clarify editting rules

* fixed numbering and removed old language about having to click show more which doesn't exist anymore in the admin consle.

* Apply suggestions from code review

Co-authored-by: Alden Hilton <[email protected]>

* Update baselines/commoncontrols.md

Co-authored-by: Alden Hilton <[email protected]>

---------

Co-authored-by: David Bui <[email protected]>
Co-authored-by: jkaufman-mitre <[email protected]>
Co-authored-by: Alden Hilton <[email protected]>

* first draft of new DLP changes

* TOC update, group description, clarifying implementation steps

* removing extra spacing

* first draft of new DLP changes

* TOC update, group description, clarifying implementation steps

* removing extra spacing

* updating drift rules

* updating implemetnation steps for actions, adding should block external sharing policy

* draft for condition rules for Credit card/ITIN/SSN

* updated TOC for chat/drive

* adding in drift rules

* Apply suggestions from code review

Co-authored-by: Alden Hilton <[email protected]>

* code changes based on comments

* code changes udpating implementation steps across policy group 18

* Apply suggestions from code review

Co-authored-by: David Bui <[email protected]>
Co-authored-by: Alden Hilton <[email protected]>

* replacing add instead of actions

* Apply suggestions from code review

Parity w/ m365 and scubagear
3rd party DLP options
license info

Co-authored-by: David Bui <[email protected]>

* updating TOC

* Apply suggestions from code review

Co-authored-by: David Bui <[email protected]>

---------

Co-authored-by: David Bui <[email protected]>
Co-authored-by: jkaufman-mitre <[email protected]>
Co-authored-by: Alden Hilton <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants