After reviewing both the sprint plan and the current Top 10 entry template, I think there is an opportunity to further strengthen the consistency and practical value of the project through a small evolution of the template.
The current template provides a solid foundation, but several objectives described in the sprint plan, such as actionable guidance, consistency, evidence and being practical, are not yet explicitly reflected in the template.
Hence, the following sections are proposed.
I see this as an initial proposal rather than a finished design, and I'd be very interested in feedback from the community.
If there is general agreement, I'd be happy to prepare a pull request implementing the agreed changes.
Proposed Template Extensions
Scope
Clearly define what the entry covers and, equally importantly, what it does not cover.
This helps distinguish related entries and reduces overlap such as QS04, QS05 and QS06.
Detection
Describe how organisations can determine whether they are exposed to the risk as a practical starting point.
Examples include:
- architecture reviews
- cryptographic inventories
- configuration analysis
- software composition analysis
- runtime monitoring
- infrastructure assessments
Mitigations
Rather than listing high-level recommendations, mitigation guidance should be written as concrete engineering activities.
Ideally every mitigation should satisfy three principles:
- Actionable: mitigation clearly describes what should be implemented.
- Measurable: mitigation provides objective criteria for determining whether implementation has been completed.
- Verifiable: mitigation be independently validated through testing, automation, configuration review or audit.
Related Risks
Where appropriate, reference other Top 10 entries that address adjacent or complementary risks.
This improves navigation and helps contributors maintain clear scope boundaries.
After reviewing both the sprint plan and the current Top 10 entry template, I think there is an opportunity to further strengthen the consistency and practical value of the project through a small evolution of the template.
The current template provides a solid foundation, but several objectives described in the sprint plan, such as actionable guidance, consistency, evidence and being practical, are not yet explicitly reflected in the template.
Hence, the following sections are proposed.
I see this as an initial proposal rather than a finished design, and I'd be very interested in feedback from the community.
If there is general agreement, I'd be happy to prepare a pull request implementing the agreed changes.
Proposed Template Extensions
Scope
Clearly define what the entry covers and, equally importantly, what it does not cover.
This helps distinguish related entries and reduces overlap such as QS04, QS05 and QS06.
Detection
Describe how organisations can determine whether they are exposed to the risk as a practical starting point.
Examples include:
Mitigations
Rather than listing high-level recommendations, mitigation guidance should be written as concrete engineering activities.
Ideally every mitigation should satisfy three principles:
Related Risks
Where appropriate, reference other Top 10 entries that address adjacent or complementary risks.
This improves navigation and helps contributors maintain clear scope boundaries.