Originally created by: olafz
When trying to load the OWASP-SAMM-2.0 bundle, OpenGRC shows
The bundle JSON uses OWASP SAMM values:
But the app stores these fields as enum-backed Control fields. ControlType only allows Administrative, Technical, Physical, Operational, and Other: https://github.com/LeeMangold/OpenGRC/blob/d69895aed199ecb397ff92e7bc782c7c16e6ca98/app/Enums/ControlType.php#L10-L14
So Governance is valid SAMM data, but invalid for this app’s ControlType enum. After fixing that, this same bundle would also fail on category and enforcement for the same reason.
OpenGRC should normalize unsupported bundle values during import, probably mapping unknown type, category, and enforcement to Other or Unknown. Another, more flexible, model fix would store SAMM domain/practice/level separately instead of forcing them into these enum-backed columns.
Originally posted by: olafz
When trying to load "OWASP-Top10-2021":