{"assessment-plan":{"assessment-assets":{"assessment-platforms":[{"props":[{"name":"tool-type","value":"scanner"},{"name":"tool-version","value":"1.3.x"}],"title":"OpenSCAP Scanner","uuid":"30ac9e00-6cbf-4243-8264-a5d55a6f0f7e"},{"props":[{"name":"tool-type","value":"analysis"},{"name":"tool-version","value":"1.0"}],"title":"Evidence Review Toolkit","uuid":"55abb1c7-4cea-46cc-a898-4d5cf88592ae"}]},"assessment-subjects":[{"description":"System inventory items","include-subjects":[{"subject-uuid":"ad62a733-21c6-4666-aec7-364384bb1692","type":"inventory-item"},{"subject-uuid":"349e63d5-63e6-4b8a-8238-5b41d9facf0f","type":"inventory-item"},{"subject-uuid":"8070df67-4610-4c77-95fb-76a15269e17a","type":"inventory-item"},{"subject-uuid":"d8b7541c-8d57-4680-9012-6983c3c9da9e","type":"inventory-item"}],"type":"inventory-item"}],"import-ssp":{"href":"../system-security-plans/Kubernetes-System-ssp-dora/system-security-plan.json"},"local-definitions":{"activities":[{"description":"Automated vulnerability scanning and configuration compliance checks using OSCAP","props":[{"name":"method","value":"TEST"},{"name":"assessment-type","value":"automated"}],"steps":[{"description":"Execute security compliance scan against the inventory items","title":"Run Security Compliance Scan","uuid":"ce5581a9-669c-4f8a-9a59-0a1d3ea67b7e"},{"description":"Review scan results and identify non-compliant controls","title":"Analyze Results","uuid":"ded44a7e-7155-42f1-8514-e7a9f8725545"}],"title":"Automated Security Scanning","uuid":"989250be-b725-4835-803d-d46ece800bbb"},{"description":"Manual review and testing of security controls that cannot be automated","props":[{"name":"method","value":"EXAMINE"},{"name":"assessment-type","value":"manual"}],"steps":[{"description":"Review security policies, procedures, configurations, and evidence artifacts","title":"Document Review","uuid":"17d05306-0271-435e-8099-6f7e1bcc9b72"},{"description":"Interview system administrators and security personnel","title":"Interview Personnel","uuid":"17ccfb35-cfe7-4b7d-acac-89408f8cc5a1"}],"title":"Manual Control Testing","uuid":"82fac3cd-ae96-4bd9-bf26-476ea4bea6bd"},{"description":"Validate operational resilience, response, and recovery capabilities across the Ubuntu fleet","props":[{"name":"method","value":"TEST"},{"name":"assessment-type","value":"scenario-based"}],"steps":[{"description":"Review incident, disruption, and recovery scenarios applicable to the system","title":"Scenario Walkthrough","uuid":"809b6c87-c7cf-437c-9055-4b5618624673"},{"description":"Correlate technical evidence with implemented controls and procedures","title":"Evidence Correlation","uuid":"e6d212ab-1fda-4521-86e1-aeed8f38c587"}],"title":"Resilience and Response Validation","uuid":"2c3c6147-d463-43e6-b5f0-19119120cfac"}]},"metadata":{"last-modified":"2026-05-09T08:08:27.739305","oscal-version":"1.2.1","props":[{"name":"assessment-type","value":"security-assessment"},{"name":"assessment-scope","value":"host-assessment"},{"name":"assessment-frequency","value":"annual"},{"name":"regulation","value":"EU DORA"},{"name":"platform","value":"Kubernetes 1.28"},{"name":"subject-count","value":"4"}],"published":"2026-05-09T08:08:27.739305","title":"Kubernetes System Assessment Plan - DORA","version":"1.0"},"reviewed-controls":{"control-selections":[{"description":"All controls imported by the referenced SSP will be assessed","include-all":{}}],"description":"Assessment of controls for the EU DORA baseline","props":[{"name":"assessment-baseline","value":"EU DORA"},{"name":"control-selection","value":"all-imported-controls"}]},"tasks":[{"description":"Schedule and conduct the assessment kickoff meeting","timing":{"on-date":{"date":"2026-05-16T08:08:27.739305"}},"title":"Assessment Kickoff","type":"action","uuid":"a017fc1f-480d-431e-8a5d-e52516593464"},{"description":"Perform automated scans, document review, interviews, and validation activities","timing":{"within-date-range":{"end":"2026-06-13T08:08:27.739305","start":"2026-05-23T08:08:27.739305"}},"title":"Execute Automated and Manual Assessment Activities","type":"action","uuid":"7570963f-16aa-409a-985d-bbd4342be1cc"},{"description":"Complete evidence review and prepare assessment results","timing":{"on-date":{"date":"2026-06-23T08:08:27.739305"}},"title":"Assessment Results Ready","type":"milestone","uuid":"b2c33963-8db0-4662-845b-728e9ececb1d"}],"uuid":"1ed3b300-b518-4021-b470-90bd319c16ef"}}
