References — DSPM Finding Catalog
Sources behind fixtures/findings.json: vendor naming conventions, compliance
framework mappings, the Presidio detector import, and per-finding enrichment data.
1. Vendor finding name/description conventions (Orca, Wiz, Cyera)
Basis for finding_name / description / remediation_advice style (Cyera style chosen).
- Orca Cloud Risk Encyclopedia — Sensitive Data in File
- Orca alert — Database with Potentially Personal Identifying Information found – Credit Card Numbers
- Orca alert — Potentially Personal Identifying Information found – Email Addresses
- Cyera integration for Elastic — issue/classification field reference
- Cyera sample payloads in elastic/integrations — issue name “Credit card number in plain text”, PCI DSS description,
remediation_advice - Sekoia — Wiz Issues integration, example payloads
2. Compliance framework sources (compliance_frameworks / sensitivity)
- HIPAA Safe Harbor 18 identifiers, 45 CFR 164.514(b)(2) — explained
- Network for Public Health Law — HIPAA Safe Harbor De-Identification reference (PDF)
- CPRA full text — Cal. Civ. Code 1798.140(ae) sensitive personal information, 1798.140(v) personal information
- India SPDI Rules 2011, Rule 3 — sensitive personal data list
- India SPDI Rules 2011 — official text (WIPO mirror, PDF)
- CMS — Understanding the Medicare Beneficiary Identifier (MBI) format (PDF)
3. Presidio detector import (src/engine/presidio_patterns.py)
- data-privacy-stack/presidio fork — source of the 71 imported regex detectors (commit
760d6c8, presidio_analyzer v2.2.364)
4. Per-finding enrichment references (cwe / mitre_attack / validation / sample_value)
All URLs cited in findings.json references fields, with the findings that cite them.
MITRE CWE / ATT&CK
| Reference | Cited by |
|---|---|
| CWE-256 | Password Pattern |
| CWE-312 | API Key, AWS Access Key, AWS Secret Access Key, Bearer Token, +8 more |
| CWE-359 | AU_ACN, Address, Bank Account, CA_POSTAL_CODE, +53 more |
| T1552.004 (MITRE ATT&CK) | Private Key Header |
Standards (IETF RFCs, NIST)
| Reference | Cited by |
|---|---|
| NIST SP 800-63B | Secret.PasswordHash |
| RFC 4122 | UUID |
| RFC 5322 | Email |
| RFC 6750 | Bearer Token |
| RFC 7519 | JWT Token |
Official / vendor documentation
| Reference | Cited by |
|---|---|
| AWS IAM — Managing access keys | AWS Access Key, AWS Secret Access Key |
| CMS — Understanding the MBI format (PDF) | US_MBI |
| Google libphonenumber | Phone Number |