• Joined on 2026-04-12
Hartmut commented on issue Hartmut/CapaKraken#32 2026-04-16 10:06:37 +02:00
CDP 35948520/Checkliste Cloud: 7 Web App Security Checks

Review-Ergebnis

Detail-Analyse aller 7 Checks aus samples/CDP/checklists/cloud.xlsx gegen CapaKraken-Code und [docs/acn-security-compliance-status.md](../blob/main/docs/acn-security-complia…

Hartmut commented on issue Hartmut/CapaKraken#31 2026-04-16 10:06:36 +02:00
CDP 35948520/Checkliste General: 35 Web App Security Checks

Review-Ergebnis

Detail-Analyse aller 35 Checks aus samples/CDP/checklists/general.xlsx gegen CapaKraken-Code und [docs/acn-security-compliance-status.md](../blob/main/docs/acn-security-comp…

Hartmut commented on issue Hartmut/CapaKraken#30 2026-04-16 10:02:30 +02:00
CDP 35948516: NodeJS

CapaKraken Compliance-Status

EAPPS-Mapping: Node.js Security
Status: 🟡 PARTIAL / TODO — konkrete Schritte unten

Zusammenfassung

Next.js Runtime + API-Package basieren…

Hartmut commented on issue Hartmut/CapaKraken#29 2026-04-16 10:02:30 +02:00
CDP 35948518: Cloud

CapaKraken Compliance-Status

EAPPS-Mapping: SaaS/PaaS Cloud Standard
Status: 🟡 PARTIAL / TODO — konkrete Schritte unten

Zusammenfassung

⚠️ CapaKraken läuft aktuell…

Hartmut commented on issue Hartmut/CapaKraken#27 2026-04-16 10:02:29 +02:00
CDP 35948515: HTML5

CapaKraken Compliance-Status

EAPPS-Mapping: 3.3.1.x
Status: 🟡 PARTIAL / TODO — konkrete Schritte unten

Zusammenfassung

HTML5-spezifische Security-Checks (CORS,…

Hartmut commented on issue Hartmut/CapaKraken#28 2026-04-16 10:02:29 +02:00
CDP 35948519: Utilize a Secure DevOps environment supporting code scanning services

CapaKraken Compliance-Status

EAPPS-Mapping: DevSecOps Standard
Status: 🟡 PARTIAL / TODO — konkrete Schritte unten

Zusammenfassung

CI/CD-Pipeline auf Gitea Actions mit…

Hartmut commented on issue Hartmut/CapaKraken#25 2026-04-16 10:02:29 +02:00
CDP 35948520: Web Application

CapaKraken Compliance-Status

EAPPS-Mapping: 3.3.1.x (Web Application Standard)
Status: 🟡 PARTIAL / TODO — konkrete Schritte unten

Zusammenfassung

Web-App-Sicherheit ist…

Hartmut commented on issue Hartmut/CapaKraken#26 2026-04-16 10:02:29 +02:00
CDP 35948517: ReactJs

CapaKraken Compliance-Status

EAPPS-Mapping: 3.3.1.x
Status: 🟡 PARTIAL / TODO — konkrete Schritte unten

Zusammenfassung

CapaKraken nutzt React 19 via Next.js 15. Die 8…

Hartmut commented on issue Hartmut/CapaKraken#6 2026-04-16 10:02:28 +02:00
CDP 35948473: Implement Patching Process (app/AI)

CapaKraken Compliance-Status

EAPPS-Mapping: Patch Management Standard
Status: 🟡 PARTIAL / TODO — konkrete Schritte unten

Zusammenfassung

Dependabot + pnpm audit in CI…

Hartmut commented on issue Hartmut/CapaKraken#24 2026-04-16 10:02:28 +02:00
CDP 35948469: Designate SPOC for Sharing Information (app/AI)

CapaKraken Compliance-Status

EAPPS-Mapping: Prozess
Status: 🟡 PARTIAL / TODO — konkrete Schritte unten

Zusammenfassung

SPOC (Single Point of Contact) für Security-/Compl…

Hartmut commented on issue Hartmut/CapaKraken#7 2026-04-16 10:02:28 +02:00
CDP 35948472: Maintain current application inventory (dev)

CapaKraken Compliance-Status

EAPPS-Mapping: 3.1.1.01 (AIR Registration)
Status: 🟡 PARTIAL / TODO — konkrete Schritte unten

Zusammenfassung

AIR-Eintrag (Accenture…

Hartmut commented on issue Hartmut/CapaKraken#10 2026-04-16 10:02:28 +02:00
CDP 35948471: Deliver project specific CDP training (app/AI)

CapaKraken Compliance-Status

EAPPS-Mapping: Prozess
Status: 🟡 PARTIAL / TODO — konkrete Schritte unten

Zusammenfassung

Organisatorische Kontrolle — technisch nicht…

Hartmut commented on issue Hartmut/CapaKraken#17 2026-04-16 10:02:28 +02:00
CDP 35948464: General

CapaKraken Compliance-Status

EAPPS-Mapping: 3.2.2.3.x / Web Application Security Standard
Status: 🟡 PARTIAL / TODO — konkrete Schritte unten

Zusammenfassung

Secure-Codin…

Hartmut commented on issue Hartmut/CapaKraken#19 2026-04-16 10:02:27 +02:00
CDP 35948466: Enable Logging (app)

CapaKraken Compliance-Status

EAPPS-Mapping: 3.2.7.01
Status: OK (laut docs/acn-security-compliance-status.md)

Zusammenfassung

Strukturiertes Logging (Pino) für…

Hartmut closed issue Hartmut/CapaKraken#15 2026-04-16 10:02:27 +02:00
CDP 35948454: Maintain System Administrator Log (app)
Hartmut closed issue Hartmut/CapaKraken#19 2026-04-16 10:02:27 +02:00
CDP 35948466: Enable Logging (app)
Hartmut commented on issue Hartmut/CapaKraken#3 2026-04-16 10:02:27 +02:00
CDP 35948468: Provide Written Notification (app)

CapaKraken Compliance-Status

EAPPS-Mapping: Access Control Standard (Prozess)
Status: 🟡 PARTIAL / TODO — konkrete Schritte unten

Zusammenfassung

Prozess-Kontrolle:…

Hartmut commented on issue Hartmut/CapaKraken#15 2026-04-16 10:02:27 +02:00
CDP 35948454: Maintain System Administrator Log (app)

CapaKraken Compliance-Status

EAPPS-Mapping: 3.2.7.01 / 3.2.7.03
Status: OK (laut docs/acn-security-compliance-status.md)

Zusammenfassung

Alle relevanten System-Admin-…

Hartmut commented on issue Hartmut/CapaKraken#14 2026-04-16 10:02:26 +02:00
CDP 35948458: Require Multi-Factor Authentication

CapaKraken Compliance-Status

EAPPS-Mapping: 3.2.2.2.01
Status: OK (laut docs/acn-security-compliance-status.md)

Zusammenfassung

TOTP-basierte MFA ist implementiert…

Hartmut closed issue Hartmut/CapaKraken#13 2026-04-16 10:02:26 +02:00
CDP 35948455: Provide Role Related Access (app)