Skip to content

Improve SIEM suppression governance gates#2181

Open
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/siem-suppression-governance-fixtures-1491
Open

Improve SIEM suppression governance gates#2181
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/siem-suppression-governance-fixtures-1491

Conversation

@DENGXUELIN

Copy link
Copy Markdown

/claim #1491

Summary

  • Adds suppression and exception governance gates to siem-rules.
  • Requires owner/ticket/scope/expiry, true-positive replay, before/after counts, residual coverage, lookup or macro review, and stale high-value-asset suppression escalation.
  • Adds benign and vulnerable JSON fixtures for governed suppression versus permanent allowlist removal of true positives.

Validation

  • git diff --check origin/main...HEAD
  • JSON parse check for both fixtures
  • Markdown fence-balance and required-marker checks
  • Added-line sensitive-pattern scan
  • git merge-tree --write-tree origin/main HEAD matched HEAD^{tree}

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant