Comments (1)
Hey @CalCof thanks for your feedback! We have evaluated the usage of the Microsoft Assessments platform to replace this framework, but unfortunately at this point in time it would be very difficult:
- Our checklists' primary goal is to serve as guidance for our engineers, our partners and our customers in FastTrack engagements. The current format of the assessment makes it very difficult to serve for this purpose. For example, in the Excel-formatted checklist you can assign owners to the resulting actions, add comments, merge input coming from Azure Resource Graph queries, filter items according to severity, and many other features that the Assessments platform is lacking today
- The secondary goal of the checklists in their current form is to be easily kept up-to-date. This is another problem of the Assessments, where the JSON file for each assessment has to be manually crafted and uploaded to the platform (there are no APIs). We have had similar approaches in the past (where our checklists were static), and the result was that the assessments/checklists got out-of-date very quickly.
Another area of alignment is CAF/ESLZ (much closer to the level of detail that these checklists bring than WAF), where we do try to follow ESLZ recommendations.
A Github issue is probably not the best forum to discuss this, happy to chat over a call.
from review-checklists.
Related Issues (20)
- Include WAF Pillar in AVS checklist
- [DOCS] Fix grammatical errors in the README file HOT 1
- ARO checklist - having incorrect reference URL & remove default access HOT 1
- Proposal for Adding Azure Policies to check list and converting Azure Resource Graph Queries to Azure Policies HOT 4
- Graph query missing from AKV check for soft-delete and purge-protection
- Feature: Adding contributors section to the README.md file. HOT 3
- Individual WAF checklists disappeared from spreadsheet HOT 3
- Azure Lighthouse missing HOT 2
- Duplicate GUIDs HOT 2
- checklist_graph.sh uses a static tree ID
- Import WAF checklists - support for non-English versions HOT 2
- Dashboard metrics misalignment.
- JSON files should be validated according to the schema file automatically on every PR
- Add severity field to the cost checklist
- Resource Organization CheckList Item Error HOT 4
- IoT checklist consolidation? HOT 2
- WAF creation script erroring out
- Duplicate ID (Network Topology and Connectivity) HOT 5
- D09.04 - Link to incorrect data HOT 3
- unable to use checklist_graph HOT 2
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from review-checklists.