Skip to content

Restore STRM PDFs to the repository (2026.2 set, mirrored from the official CDN) - #15

Open
thisstillisntreal wants to merge 1 commit into
securecontrolsframework:mainfrom
thisstillisntreal:restore-strm-pdfs-2026-2
Open

Restore STRM PDFs to the repository (2026.2 set, mirrored from the official CDN)#15
thisstillisntreal wants to merge 1 commit into
securecontrolsframework:mainfrom
thisstillisntreal:restore-strm-pdfs-2026-2

Conversation

@thisstillisntreal

@thisstillisntreal thisstillisntreal commented Jul 12, 2026

Copy link
Copy Markdown

This PR restores the Set Theory Relationship Mapping (STRM)/ folder that was removed in the 2026.2 restructure, populated with the complete current 2026.2 STRM set — all 249 PDFs, byte-identical mirrors of the files served at content.securecontrolsframework.com/strm/ as listed in the workbook's Focal Documents tab.

Why restore them in-repo:

  • Version history: the repo previously carried the STRM PDFs, so releases were fully self-contained and diffable; CDN files can change or disappear without a trace.
  • Auditability: compliance tooling (ours included) pins SHA-256 hashes of these PDFs for verification. An in-repo copy gives everyone a canonical, versioned reference.
  • Offline/complete clones: a git clone is once again the entire release.

Notes:

  • scf-strm-scf-dpmp-2025.pdf is included under its actual CDN filename. The 2026.2 workbook's Focal Documents tab lists it with a spurious general- prefix (404) — see the companion issue.
  • A manifest with per-file SHA-256, source URL, and retrieval timestamp is included at Set Theory Relationship Mapping (STRM)/strm_manifest.json.

If you'd prefer not to carry the PDFs in-repo, feel free to close — we also maintain an external mirror with full provenance for the audit use-case.


Bug report: broken STRM URL in the 2026.2 workbook (issues are disabled, so reporting here)

In secure-controls-framework-scf-2026-2.xlsx, the Focal Documents tab lists this STRM URL for "SCF DPMP 2025" (FDI general-scf-dpmp-2025):

https://content.securecontrolsframework.com/strm/scf-strm-general-scf-dpmp-2025.pdf

That URL returns HTTP 404. The PDF is actually served at:

https://content.securecontrolsframework.com/strm/scf-strm-scf-dpmp-2025.pdf

(no general- prefix — verified HTTP 200 application/pdf, 2026-07-12). It is the only broken STRM URL of the 250 listed — everything else resolves. Would be great to fix the cell in the next workbook revision so tooling that consumes the Focal Documents tab doesn't need a special case.

All 249 STRM PDFs listed in the 2026.2 workbook's Focal Documents tab,
byte-identical to the copies served at content.securecontrolsframework.com/strm/.
Includes strm_manifest.json with per-file SHA-256, source URL, and size.

Note: scf-strm-scf-dpmp-2025.pdf is included under its actual CDN filename;
the workbook lists it with a spurious 'general-' prefix (404) — reported separately.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant