Files
msd-core/gsd-core/references/security-asvs-levels.md
Tom Boucher f9d9dfb4bc fix(#1627): scale security rigor by ASVS level (planner disposition + auditor depth) (#1636)
workflow.security_asvs_level was display-only — the planner hardcoded
'mitigate if ASVS L1 requires it' and the auditor only echoed the level,
so L2/L3 behaved identically to L1.

- New reference gsd-core/references/security-asvs-levels.md defines L1
  (opportunistic), L2 (standard), L3 (comprehensive) for both planner
  threat disposition and auditor verification depth (higher = superset).
- planner: disposition now scales with the configured ASVS level (no
  hardcoded L1) + @-pointer to the reference.
- auditor: verification depth scales with asvs_level (L1 grep-presence,
  L2 boundary/vector check, L3 end-to-end trace + bypass check).
- planning-config.md + INVENTORY updated; planner kept under its 48K cap
  by extracting the goal-backward worked example to planner-guidance.md.

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-23 18:48:58 -04:00

1.8 KiB
Raw Blame History

Security ASVS Levels

GSD threat modeling maps OWASP ASVS levels to planner disposition rigor and auditor verification depth. Higher levels are supersets of lower — L3 includes all L2 and L1 requirements.

L1 — Opportunistic (default)

Scope: Cover threats on primary trust boundaries and high-impact components.

Planner disposition: mitigate critical/high-severity threats. mitigate medium-severity threats if they occur on a primary trust boundary; otherwise accept with documented rationale explaining the specific risk tolerance. accept low-risk threats with a rationale statement. transfer when threat is third-party responsibility.

Auditor verification depth: Verify each declared mitigation is PRESENT in the cited file (grep-level check — find the pattern, confirm the call exists).

L2 — Standard

Scope: Map ALL applicable STRIDE categories for every in-scope component.

Planner disposition: mitigate medium-severity-and-above threats. Every accept MUST have explicit documented rationale explaining why the risk is tolerable for this specific context.

Auditor verification depth: Verify the mitigation ACTUALLY ADDRESSES the threat vector (not just that some pattern is present) and is placed at the correct trust boundary. A login check in the wrong layer does not close the threat.

L3 — Comprehensive

Scope: Exhaustive STRIDE × all components; defense-in-depth for critical threats.

Planner disposition: mitigate all threats except those explicitly accepted with documented sign-off. Defense-in-depth layers required for critical threats (multiple independent controls).

Auditor verification depth: Deep verification — trace data flow end-to-end, check edge cases and ordering, confirm the mitigation cannot be bypassed via alternate code paths or parameter manipulation.