Skip to main content
Reference — generated from the toolkit

Source of truth: toolkit/registers/security-debt-register.md. Edit it there; this page is regenerated on build.

Security-debt register

Findings from the security-gap assessment, scored so the live threats outrank the theoretical ones.

Schema

FieldNotes
IDSD-NNNN
Productwhich product
CategoryASVS control area / dependency CVE / config / secret
Evidencescan / assessment link
CVSSbase severity
EPSSexploit likelihood
Business exposuredata/impact if realised
Fix-by SLAper severity (days/weeks/cycle)
Statusopen / accepted (RA-link) / remediated

Rules

  • Scored on CVSS + EPSS + business exposure together — an unreachable "critical" doesn't outrank a live "high".
  • Anything not fixed by SLA exits only via a signed risk-acceptance record.
  • Feeds the STOP exit gate: zero unremediated critical/high to pass.