Search / finos-ccc/ccc.objstor.th / v2026.06-rc1

Release · v2026.06-rc1

FINOS-CCC/CCC.ObjStor.TH Threat Catalog

FINOS-CCC/CCC.ObjStor.TH

Threats for Object Storage technologies, as defined by the FINOS Common Cloud Controls project.

Published by FINOS Common Cloud Controls

Install

OCI v1.1
$grcli unpack --repository finos-ccc/ccc.objstor.th --tag v2026.06-rc1
Coordinate
oci.grc.store/finos-ccc/ccc.objstor.th:v2026.06-rc1
Manifest digest
sha256:5dcc7e5c5929bb0fd7d7cd721d6087bb32716ded63e774f5d22514ce5a503216

Provenance

1 layer
Digest Media type Size
c5d12b943a0b… application/vnd.gemara.artifact.v1+yaml 2.8 KiB
Bundle config blob
{
  "bundle-version": "1.0",
  "gemara-version": "v1.0.0",
  "metadata": {
    "provenance": {
      "buildDefinition": {
        "buildType": "https://grc.store/grcli/buildtype/v0",
        "externalParameters": {
          "artifact": {
            "id": "CCC.ObjStor.TH",
            "type": "ThreatCatalog"
          },
          "target": {
            "registry": "oci.grc.store",
            "repository": "finos-ccc/ccc.objstor.th",
            "tag": "v2026.06-rc1"
          }
        },
        "internalParameters": {
          "CI": "true",
          "GITHUB_ACTIONS": "true",
          "GITHUB_ACTOR": "eddie-knight",
          "GITHUB_REF": "refs/heads/main",
          "GITHUB_REPOSITORY": "finos/common-cloud-controls",
          "GITHUB_RUN_ATTEMPT": "1",
          "GITHUB_RUN_ID": "26549295026",
          "GITHUB_SHA": "7d4361913495ae08cad809355e37e0be0ad3f1d4",
          "GITHUB_WORKFLOW": "Release Catalog",
          "RUNNER_OS": "Linux"
        },
        "resolvedDependencies": [
          {
            "name": "artifacts/storage/object/threats.yaml",
            "uri": "file://artifacts/storage/object/threats.yaml",
            "digest": {
              "sha256": "c5d12b943a0b950fa1ed21063a0aaa7edf002dbfd16e639a7d47ddfa69df3672"
            }
          },
          {
            "name": "source",
            "uri": "git+https://github.com/finos/common-cloud-controls@7d4361913495ae08cad809355e37e0be0ad3f1d4",
            "digest": {
              "gitCommit": "7d4361913495ae08cad809355e37e0be0ad3f1d4"
            }
          }
        ]
      },
      "runDetails": {
        "builder": {
          "id": "https://github.com/finos/common-cloud-controls/actions/runs/26549295026",
          "version": {
            "go": "go1.25.0",
            "go-arch": "amd64",
            "go-os": "linux",
            "grcli": "v0.1.0"
          }
        },
        "metadata": {
          "invocationId": "26549295026-1",
          "startedOn": "2026-05-28T01:37:55.26359605Z",
          "finishedOn": "2026-05-28T01:37:55.433095471Z"
        },
        "byproducts": [
          {
            "name": "threats.yaml",
            "digest": {
              "sha256": "c5d12b943a0b950fa1ed21063a0aaa7edf002dbfd16e639a7d47ddfa69df3672"
            }
          }
        ]
      }
    }
  },
  "artifacts": [
    {
      "name": "threats.yaml",
      "type": "ThreatCatalog",
      "id": "CCC.ObjStor.TH",
      "role": "artifact"
    }
  ]
}

CCC Object Storage Threats

Threats for Object Storage technologies, as defined by the FINOS Common Cloud Controls project.

ID
CCC.ObjStor.TH
Version
v2026.06-rc1
Gemara version
v1.0.0
Author
FINOS Common Cloud Controls

Data Resilience

The Data Resilience group covers entries related to ensuring data availability, integrity, and sovereignty across its lifecycle. This includes replication, backup, recovery, region restrictions, and protection against data loss or corruption.

  1. CCC.ObjStor.TH01 Data Exfiltration via Insecure Lifecycle Policies

    Misconfigured lifecycle policies may unintentionally allow data to be exfiltrated or destroyed prematurely, resulting in a loss of availability and potential exposure of sensitive data.

    Capabilities
    • CCC.ObjStor.Capabilities
      • CCC.ObjStor.CP08
    • CCC.Core.Capabilities
      • CCC.Core.CP11