Skip to main content

Security Engineering Rubric

DimensionRepeatPassStrong
Threat modelGeneric checklistAssets, actors, boundaries, abuse casesRisk changes are traced through design and tests
VerificationScanner dumpReproducible manual and automated evidenceNegative tests and exploit reproduction verify controls
Supply chainDependencies merely listedSBOM, signing, and provenance verifyHardened builder and policy controls are demonstrated
ResponseNo operational pathDetection and incident exercise workExercise findings drive measurable remediation
DefenseCannot explain residual riskDefends controls, gaps, and prioritiesIndependent review is answered with evidence

Passing requires at least Pass in every row and no unresolved unaccepted critical risk.