DSPM3 min readWorking notes

References — DSPM Finding Catalog

Sources behind fixtures/findings.json: vendor naming conventions, compliance framework mappings, the Presidio detector import, and per-finding enrichment data.

1. Vendor finding name/description conventions (Orca, Wiz, Cyera)

Basis for finding_name / description / remediation_advice style (Cyera style chosen).

2. Compliance framework sources (compliance_frameworks / sensitivity)

3. Presidio detector import (src/engine/presidio_patterns.py)

4. Per-finding enrichment references (cwe / mitre_attack / validation / sample_value)

All URLs cited in findings.json references fields, with the findings that cite them.

MITRE CWE / ATT&CK

Reference Cited by
CWE-256 Password Pattern
CWE-312 API Key, AWS Access Key, AWS Secret Access Key, Bearer Token, +8 more
CWE-359 AU_ACN, Address, Bank Account, CA_POSTAL_CODE, +53 more
T1552.004 (MITRE ATT&CK) Private Key Header

Standards (IETF RFCs, NIST)

Reference Cited by
NIST SP 800-63B Secret.PasswordHash
RFC 4122 UUID
RFC 5322 Email
RFC 6750 Bearer Token
RFC 7519 JWT Token

Official / vendor documentation

Reference Cited by
AWS IAM — Managing access keys AWS Access Key, AWS Secret Access Key
CMS — Understanding the MBI format (PDF) US_MBI
Google libphonenumber Phone Number

Identifier format specifications