The ATO process for this project is documented here.
Here are major components, with links to the resulting artifacts:
- Set up monitoring
- Downtime alerts - Set to go to [email protected]
- Error alerts
- Add an
.about.yml
for the main repository - Security scans
- Set up static analysis service - Code Climate | Gemnasium
- Add service badges to the README
- Perform dynamic vulnerability scanning
- Resolve any visible security issues, re-running the scan as needed
- Add the issue-free scan report or documentation about false positives to the
ATOs
folder in Google Drive
- Set up static analysis service - Code Climate | Gemnasium
- Update relevant documentation, primarily the README
- Add a System Security Plan to the repository
- Set up Compliance Masonry documentation
- Implement the controls