Skip to content

QS01: apply proposed Top 10 template (Scope, Evidence, Detection, Related Risks) - #50

Open
akanthed wants to merge 2 commits into
OWASP:mainfrom
akanthed:apply-template-qs01
Open

akanthed wants to merge 2 commits into
OWASP:mainfrom
akanthed:apply-template-qs01

Conversation

@akanthed

Copy link
Copy Markdown
Contributor

Summary

PR #40 (implementing the proposal in #15) formalizes new Scope, Evidence, Detection, and Related Risks sections for the Top 10 entry template, but its stated non-goal is that it does not rewrite existing entries. This PR demonstrates what that retroactive application looks like by applying the proposed template to QS01: Harvest-Now-Decrypt-Later Exposure.

Changes

  • Scope: explicitly separates QS01 (the capture-now exposure) from QS02, QS04, QS05, and QS06, which were previously distinguishable only by reading all entries side by side.
  • Evidence: classifies QS01 as Demonstrated, with justification tied to the existing NSM-10/OMB M-23-02/NCSC references already cited in the entry.
  • Detection: adds four practical, concrete checks (CBOM sweep, TLS/VPN configuration analysis, data classification review, network boundary review).
  • Related Risks: reuses the QS01 example relationships already drafted in PR Formalize Quantum Top 10 entry template #40's description (QS04, QS05, QS06) and adds QS02, since QS01/QS02 are the pair most likely to be conflated.
  • Reorders Standards & Regulatory Mapping and Reference Links to match the section order in the proposed template, and removes the stale TODO note questioning whether the Standards & Regulatory Mapping section should be kept.

No existing content (Description, Common Examples, How to Prevent, Example Attack Scenarios, Reference Links text) was rewritten — only reformatted into list form for Standards & Regulatory Mapping and reordered.

Notes

Related: #15, #40

akanthed and others added 2 commits September 21, 2026 11:18
…ated Risks)

Demonstrates retroactive application of the template extensions
proposed in OWASP#15 and drafted in PR OWASP#40, which intentionally left
existing entries unchanged. Adds Scope, Evidence classification,
Detection, and Related Risks sections to QS01 and reorders Standards
& Regulatory Mapping / Reference Links to match the proposed template
order, removing the stale TODO note on that section.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Rewrites the new sections in plainer language so the entry is
accessible to non-specialist readers, without changing technical
meaning or citations.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant