MONARC - Method for an Optimised aNAlysis of Risks by @CASES-LU
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
Cédric Bonhomme 92d131e461
updated zm-client
1 week ago
.github chg: [ci-releases] Do not install dev packages. 4 months ago
INSTALL new: [deployment] Updated installation instructions with the bundle generated by GitHub Actions. 3 months ago
config new: [2FA] added instanceName config for the label of 2fa QRCode 4 months ago
db-bootstrap updated structure dump. 3 years ago
deliveries/cases Added new tag for soa scale in 5th deliverable 5 months ago
public Reverted the unwanted changes. 1 year ago
scripts chg: [scripts] replaced zendframework by Laminas. !minor 4 months ago
tests Reverted the unwanted changes. 1 year ago
vagrant Add romanian language in install scripts 7 months ago
wsl Add romanian language in install scripts 7 months ago
.gitignore Ignore cache result file from phpunit. 2 years ago
AUTHORS chg: updated README !minor 6 months ago
CHANGELOG.md chg: [dependencies] Updated zm-core to 2.12.1. 3 months ago
LICENSE Added license file. 5 years ago
README.md chg: [CSS] updated path of the flags. 4 months ago
SECURITY.md Added SECURITY.md 3 years ago
VERSION.json chg: [dependencies] Updated zm-core to 2.12.1. 3 months ago
composer.json chg: [dependencies] Added new QRCode backend endroid/qr-code. 3 months ago
composer.lock updated zm-client 1 week ago
package.json chg: [dependencies] Updated ng-client to 2.12.2 (related to CVE-2022-31129). 3 months ago
phpunit.xml Added the commit with the tests introduction. 2 years ago

README.md

MONARC - Method for an Optimised aNAlysis of Risks by CASES

Latest Release License Contributors Stars Workflow Twitter

Introduction

Depending on its size and its security needs, organisations must react in the most appropriate manner. Adopting good practices, taking the necessary measures and adjusting them proportionally: all this is part of the process to ensure information security. Most of all, it depends on performing a risk analysis on a regular basis.

Although the profitability of the risk analysis approach is guaranteed, the investment represented by this approach in terms of the required cost and expertise is a barrier for many companies, especially SMEs.

To remedy this situation and allow all organisations, both large and small, to benefit from the advantages that a risk analysis offers, CASES has developed an optimised risk analysis method: MONARC (Optimised Risk Analysis Method), allowing precise and repeatable risk management.

The advantage of MONARC lies in the capitalisation of risk analyses already performed in similar business contexts: the same vulnerabilities regularly appear in many businesses, as they face the same threats and generate similar risks. Most companies have servers, printers, a fleet of smartphones, Wi-Fi antennas, etc. therefore the vulnerabilities and threats are the same. It is therefore sufficient to generalise risk scenarios for these assets (also called objects) by context and/or business.

Documentation

You will find a user guide and a technical guide on the MONARC website.

For installation instructions see INSTALL.

You can also use the provided Virtual Machine.

Contributing

If you are interested to contribute to the MONARC project, review our community page. There are many ways to contribute and participate to the project.

Feel free to fork the code, play with it, make some patches and send us the pull requests.

There is one main branch: what we consider as stable with frequent updates as hot-fixes.

Features are developed in separated branches and then regularly merged into the master stable branch.

Please, do not open directly a GitHub issue if you think you have found a security vulnerability. See our vulnerability disclosure page.

License

This software is licensed under GNU Affero General Public License version 3

For more information, the list of authors and contributors is available.

Data provided with MONARC (threats, assets, vulnerabilities, referentials, etc.) are licensed under CC0 1.0 Universal (CC0 1.0) - Public Domain Dedication. These objects are available through the MONARC Objects Sharing Plarform. If a specific author wants to license an object under a different license, a pull request can be requested.
You can find more information about MOSP on the dedicated repository.