Security Engineering Rubric
| Dimension | Repeat | Pass | Strong |
|---|---|---|---|
| Threat model | Generic checklist | Assets, actors, boundaries, abuse cases | Risk changes are traced through design and tests |
| Verification | Scanner dump | Reproducible manual and automated evidence | Negative tests and exploit reproduction verify controls |
| Supply chain | Dependencies merely listed | SBOM, signing, and provenance verify | Hardened builder and policy controls are demonstrated |
| Response | No operational path | Detection and incident exercise work | Exercise findings drive measurable remediation |
| Defense | Cannot explain residual risk | Defends controls, gaps, and priorities | Independent review is answered with evidence |
Passing requires at least Pass in every row and no unresolved unaccepted critical risk.