Search / openssf/osps-baseline-to-psscrm
mapping
OSPS Baseline to P-SSCRM Mapping Mapping Document
openssf/osps-baseline-to-psscrm
Cross-walk from the Open Source Project Security (OSPS) Baseline controls to P-SSCRM. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.
Published by OSPS Baseline Authors
License No license declared
Pull latest (v0.0.0-dev-671f23f)
$grcli unpack --repository openssf/osps-baseline-to-psscrm --version v0.0.0-dev-671f23f Releases
1 live| Version | Manifest digest | Published | License | Status | |
|---|---|---|---|---|---|
| v0.0.0-dev-671f23f | 206888845a1006… | 1mo ago | No license declared | Live unsigned | Details → |
Mapping references
external standards this artifact maps to (v0.0.0-dev-671f23f)-
The Open Source Project Security (OSPS) Baseline is a set of security criteria that projects should meet to demonstrate a strong security posture.
-
The Proactive-Software Supply Chain Risk Management (P-SSCRM) Framework is designed to help you understand and plan a secure software supply chain risk management initiative. P-SSCRM was created through a process of understanding and analyzing real-world data from nine industry-leading software supply chain risk management initiatives as well as through the analysis and unification of ten government and industry documents, frameworks, and standards. Although individual methodologies and standards differ, many initiatives and standards share common ground. P-SSCRM describes this common ground and presents a model for understanding, quantifying, and developing a secure software supply chain risk management program and determining where your organization’s existing efforts stand when contrasted with other real-world software supply chain risk management initiatives.
Builds upon
artifacts this one extends, imports, or shares a lexicon withNo upstream references yet
This artifact doesn't extend, import, or share a lexicon with anything else in the registry.
Extended or imported by
other artifacts that build upon this oneNo dependents yet
Published artifacts that extend or import this one will appear here.