The main components are the following:
- a portal with Two-factor authentication and acting as a reverse proxy (Source code);
- the governance platform (Source code);
- incident notification system (Source code);
- a MONARC instance.
The portal provides a way to manage users via an API.
The platform should offer following functionalities to its users:
- Security objectives: the user assesses the performances of his organization for the listed security objectives.
- Sector: Sector is needed for stats as some companies might be participant in multiple sectors. Sector selection could be important for later on for specific assets.
- Dependencies: the user lists the operators his organization depends on.
- Risk Management: the user assesses the risks his organization faces.
- Data submission: the user can submit data (e.g. security objectives; dependencies; risk assessment) to his regulator / competent authority
- Monitoring for users: the user has the possibility to display on graphics, data he has captured.
- Monitoring for regulators/competent authority: the regulator/competent authority
has the possibility to display on graphics:
- Data submitted by each of his users.
- Data submitted by a group of his users (e.g. health sector statistics).
- Incident notification: each user has the possibility to report incidents to his regulator / competent authority.
- Regulator / competent authority functionalities:
- Submitted data management: each regulator/ competent authority can manage and process data submitted by his users.
- User management: each regulator/ competent authority should have the possibility to manage his users.
- Platform configuration: each regulator/ competent authority can configure his platform (e.g. branding; import sectoral library; configure users; export data; etc.).
https://github.com/orgs/monarc-project/projects/3
Features | Component | Already exist | Changes required | Cost estimation |
---|---|---|---|---|
Security objectives | MONARC | YES (Referentials) | content | |
Sector | MONARC | NO | DropDown List | |
Dependencies | MONARC | NO | creation | |
Risk Management | MONARC | YES (evaluation) | content | |
Data submission | MONARC | YES (import/Export) | --- | |
Monitoring for users | MONARC | partially (dashboard) | ||
Monitoring for regulators | MONARC | partially (dashboard) | ||
Regulator | MONARC | temp by MONARC (BO/FO) | TimeStamp ReadOnly trigger | |
Users management | Portal / MONARC | Partially MONARC | single sign on | |
Platform configuration | Portal | NO | Logo & colour | |
Incident notification | NISINP | NO (it seems) |