workflow.security_asvs_level was display-only — the planner hardcoded 'mitigate if ASVS L1 requires it' and the auditor only echoed the level, so L2/L3 behaved identically to L1. - New reference gsd-core/references/security-asvs-levels.md defines L1 (opportunistic), L2 (standard), L3 (comprehensive) for both planner threat disposition and auditor verification depth (higher = superset). - planner: disposition now scales with the configured ASVS level (no hardcoded L1) + @-pointer to the reference. - auditor: verification depth scales with asvs_level (L1 grep-presence, L2 boundary/vector check, L3 end-to-end trace + bypass check). - planning-config.md + INVENTORY updated; planner kept under its 48K cap by extracting the goal-backward worked example to planner-guidance.md. Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
1.8 KiB
Security ASVS Levels
GSD threat modeling maps OWASP ASVS levels to planner disposition rigor and auditor verification depth. Higher levels are supersets of lower — L3 includes all L2 and L1 requirements.
L1 — Opportunistic (default)
Scope: Cover threats on primary trust boundaries and high-impact components.
Planner disposition: mitigate critical/high-severity threats. mitigate medium-severity threats if they occur on a primary trust boundary; otherwise accept with documented rationale explaining the specific risk tolerance. accept low-risk threats with a rationale statement. transfer when threat is third-party responsibility.
Auditor verification depth: Verify each declared mitigation is PRESENT in the cited file (grep-level check — find the pattern, confirm the call exists).
L2 — Standard
Scope: Map ALL applicable STRIDE categories for every in-scope component.
Planner disposition: mitigate medium-severity-and-above threats. Every accept MUST have explicit documented rationale explaining why the risk is tolerable for this specific context.
Auditor verification depth: Verify the mitigation ACTUALLY ADDRESSES the threat vector (not just that some pattern is present) and is placed at the correct trust boundary. A login check in the wrong layer does not close the threat.
L3 — Comprehensive
Scope: Exhaustive STRIDE × all components; defense-in-depth for critical threats.
Planner disposition: mitigate all threats except those explicitly accepted with documented sign-off. Defense-in-depth layers required for critical threats (multiple independent controls).
Auditor verification depth: Deep verification — trace data flow end-to-end, check edge cases and ordering, confirm the mitigation cannot be bypassed via alternate code paths or parameter manipulation.