Meza/Enterprise Application Requirements
A list of enterprise environment requirements that Meza satisfies (or are in development). The goal is to publish capabilities while also surveying the needs of the Meza community on missing enterprise features.
Feel free to create a new user column for yourself in the table below (make the column heading your username here) and add "X's" to all of the requirements that your meza application must meet. Also feel free to add new rows for any requirements that aren't currently listed.
Editor's Note: I think this table is supposed to be more comprehensive like this table
In any case, one aspect that I believe was covered in the defunct/deprecated ETADS requirement is "SELinux". SELinux is 'enforcing' by default in RHEL, so it must be too in Meza[1].
| Class | Enterprise Requirement | Enterprise Requirement Text
The application shall... |
ASR[2] | Rationale | revansx | GR |
|---|---|---|---|---|---|---|
| Base | RHEL | be hosted in the organizations existing RHEL infrastructure | X | tbd | X | |
| Base | ETADS Compliant[3] | comply with the Enterprise Technology Assessments and Digital Standards (ETADS)
as found at https://etads.nasa.gov/standards/ |
X | tbd | X | |
| Base | NIST MODERATE | have apply the NIST 800-53 security controls to comply with a security classification of MODERATE
as found at:https://nvd.nist.gov/800-53/Rev4/impact/moderate |
X | tbd | X | |
| Base | CA Policy Agent | utilize the organizations CA Policy Agent | X | tbd | X | |
| Base | AWS | be hosted within clients existing AWS organization account[4] | X | X | ||
| Base | SSAE 16 | have an SSAE 16 compliance certificate [5] for the data center | X | Especially in financial services / accounting industries | X | |
| Base | SOC-2 | have a SOC-2 certificate for the data center[6] | X | Especially in financial services / accounting industries | X | |
| Base | SBU & CUI | be designed to store and display content designated by users as Sensitive But Unclassified or Controlled Unclassified Information. in accordance with the organizations policies for storing and displaying SBU and CUI content. | X | tbd | X | |
| Core | mw-ShortURLS | be con | X | tbd | X | |
| AC | eAuth | tbd | X | tbd | X | |
| AC | auto account creation | tbd | X | tbd | X | |
| AC | auto-login | tbd | X | tbd | X | |
| tbd | SMW | tbd | tbd | X | ||
| tbd | Page Forms | tbd | tbd | X | ||
| tbd | SRF | tbd | tbd | X | ||
| tbd | non-meza html | tbd | X | tbd | X |
Notes:
- ↑ https://github.com/freephile/meza/issues/229
- ↑ ASR = Application Security Related --- This requirement's implementation represents an aspect of security and must be addressed in the application IT security Plan
- ↑ The original link and content on this subject are now defunct. https://etads.nasa.gov/standards/ is NOT found in the InternetArchive (Wayback Machine). It seems the relevant standards may be listed in this historical document since it mentions FIPS and Section 508 However, the document is specifically for desktop systems named "RHEL 7 NASA Core Build" and it does not list SELinux.
- ↑ Besides Amazon Web Services, enterprises may require hosting within their other existing cloud platforms such as Microsoft Azure, or Google Cloud Platform
- ↑ http://www.datacenterknowledge.com/archives/2011/09/27/why-data-centers-need-ssae-16
- ↑ SSAE 16 and SOC-2 are not the same. So, it's possible that a client could require one, and not the other.