INTRO
ERP/1 CM (CXC 138 31 Configuration Management) is an Elixir/OTP security profile management framework, CMDB asset classification registry, and automated compliance document compiler.
Extracted and specialized from the CMDB functionality of synrc/ca, CM provides formal security baseline specifications, regulatory document generation (LaTeX / PDF reports and legal administrative orders), OID registries, and security control mappings compliant with NIST SP 800-53, FIPS 199/200, ISO/IEC 27005, MITRE ATT&CK, and Ukrainian KSZI / НД ТЗІ regulations.
REGULATORY FRAMEWORK
CM operates under a hierarchical regulatory framework combining Ukrainian national legislation, state technical standards (НД ТЗІ), and international frameworks:
- ● Ukrainian National Laws: Law of Ukraine "On Protection of Information in Information and Communication Systems" (No. 80/94-VR), "On Information" (No. 2657-XII), and "On Electronic Trust Services" (No. 2155-VIII).
- ● State Security Profile Orders: Mandatory State Security Profile Orders №409 (Open/Confidential Data) and №419 (Official Data).
- ● НД ТЗІ Technical Standards: НД ТЗІ 1.1-002-99, 2.5-004-99, 2.5-005-99, 2.5-008-02, 2.5-010-03, 1.6-005-22, 2.3-025-24 (Three Volumes of security control descriptions), 2.6-001-11 (Two-stage certification), 3.6-006-24 (Critical state registries), and 3.7-003-23.
- ● National Cryptographic Standards: ДСТУ 4145-2002 (ECDSA digital signature) and ДСТУ 7564-2014 (Kupyna hash function).
- ● International Baselines: NIST SP 800-53 Rev. 5, ISO/IEC 27001:2022, FIPS 140-3, and MITRE ATT&CK Enterprise taxonomy.
SEGREGATION OF DUTIES
According to Ukrainian regulatory frameworks (e.g., НД ТЗІ 2.6-001-11) and global Maker/Checker principles, building and certifying a Comprehensive Information Security System (КСЗІ) is strictly a two-stage procedure involving independent licensed providers:
- ● Stage 1: Developer (Provider 1) — Conducts risk assessment, formulates the Target Security Profile (Technical Specification) in Elixir CMDB structures, configures technical security controls, and delivers the system into trial operation.
- ● Stage 2: Expertise Organizer (Provider 2) — Receives the Technical Specification, designs an independent audit program, performs instrumental testing and live verification, and issues the official Expert Conclusion for SSSCIP (ДССЗЗІ).
DOCUMENTATION-AS-CODE (DaC)
CM eliminates manual documentation drift by generating publication-ready LaTeX specifications, security architecture diagrams, and regulatory administrative orders (накази з ІБ) directly from Elixir source modules:
- ● CA.TeX: Compiles formal TeX specifications using
security-profiles.textemplates. - ● CA.NPA: Generates legal administrative security orders for enterprise SZI establishment and KSZI development.
- ● CA.PRO: Programmatic query interface for real-time inspection of hardware, software, role, network, and risk inventories.