QS05: add governance, ownership and measurability controls - #36
Conversation
Addresses OWASP#35 What changes - Description: frames crypto-agility as a governed, owned and measurable capability. - How to Prevent: adds two controls (ownership and governing policy; agility measurability), with a one-line pointer to the inventory in QS04. - Example Attack Scenarios: adds Scenario OWASP#3, a governance failure where agility cannot be exercised in time. What does not change - No edits to Reference Links or the Standards and Regulatory - Mapping section (open TODO for the leads). - No overlap introduced with QS04 (inventory) or QS06 (hybrid).
|
As promised in the channel. The substance is right and I support all three additions — the ownership control fills the gap #35 named, the measurability control is what makes it auditable rather than aspirational, and Scenario 3 is the missing failure mode: the technology worked and the organisation couldn't exercise it. Keeping the references and standards mapping untouched for the leads was the right call. My notes are all at the wording level, five of them:
All five are paste-ready if useful. Substance-wise this is ready; happy to re-read after the wording pass. |
Revising the wording based on nmcitra's feedback
|
Grateful for the feedback. All wording fixes applied. Commit pushed. |
|
Scenario 3 has been updated. It now focuses on the trigger-detection gap rather than the execution gap alone, following the point raised in #35. The failure now begins with no one assigned to watch the triggers, which is usually what starts in practice. The rewrite also resolves the opening fragment you've flagged in note 4. |
Addresses #35
What changes
What changed after review