Reference — generated from the toolkit
Source of truth: toolkit/registers/security-debt-register.md. Edit it there; this page is regenerated on build.
Security-debt register
Findings from the security-gap assessment, scored so the live threats outrank the theoretical ones.
Schema
| Field | Notes |
|---|---|
| ID | SD-NNNN |
| Product | which product |
| Category | ASVS control area / dependency CVE / config / secret |
| Evidence | scan / assessment link |
| CVSS | base severity |
| EPSS | exploit likelihood |
| Business exposure | data/impact if realised |
| Fix-by SLA | per severity (days/weeks/cycle) |
| Status | open / accepted (RA-link) / remediated |
Rules
- Scored on CVSS + EPSS + business exposure together — an unreachable "critical" doesn't outrank a live "high".
- Anything not fixed by SLA exits only via a signed risk-acceptance record.
- Feeds the STOP exit gate: zero unremediated critical/high to pass.