Skip to content

Latest commit

 

History

History
36 lines (21 loc) · 1.6 KB

README.md

File metadata and controls

36 lines (21 loc) · 1.6 KB

security-stories-nist800-53

A collection of security related user stories compatible with NIST Special Publication 800-53

Motivation

It's hard to bake-in security and compliance into software projects when security and compliance are not part of the day to day agile work of software developers.

Now you can start every project with vetted, security-related user stories to make sure your IT system is built to be compliant.

Add these some or all of these stories to your agile backlog. Then add two or three to each sprint. As you build your system you will be making it secure, compliant, and your acceptance criteria will be evidence for your assessor!

You're security team will love you for treating them as a customer!

User Stories

As of March 2017, the list of user stories is still under development.

User stories are grouped by NIST SP 800-53 control family, system impact, and priority rating.

Contributing

To contribute, fork the repository and make pull requests.

See template.yaml file for format and existing YAML files for reference examples.