Files
msd-core/gsd-core/templates/SECURITY.md
Tom Boucher 207d8f1697 fix(#1626): make the security gate severity-aware via per-threat severity (#1635)
workflow.security_block_on was documented as the minimum threat severity
that blocks advancement, but threats carried no severity and the auditor's
threats_open count (the SECURITY.md gate field) counted every open threat
regardless of severity — so the threshold had no effect, and the auditor's
block_on vocabulary (open/unregistered/none) did not even match the config
enum (critical/high/medium/low/none).

- planner: add a Severity column to the STRIDE threat register; assign
  severity per threat.
- auditor: read severity; reconcile the <config> block_on domain to the
  severity enum; redefine threats_open as the count of OPEN threats whose
  severity is at or above block_on (none => 0). Below-threshold opens are
  reported as non-blocking and excluded from threats_open.
- SECURITY.md template + planning-config.md reconciled.

No gate-check site changed: threats_open == 0 stays the gate everywhere;
only its computation is now severity-filtered.

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-23 19:04:13 -04:00

1.8 KiB

phase, slug, status, threats_open, asvs_level, created
phase slug status threats_open asvs_level created
N
phase-slug
draft 0 1
date

Phase {N} — Security

Per-phase security contract: threat register, accepted risks, and audit trail.


Trust Boundaries

Boundary Description Data Crossing
{boundary} {description} {data type / sensitivity}

Threat Register

Threat ID Category Component Severity Disposition Mitigation Status
T-{N}-01 {STRIDE category} {component} {critical / high / medium / low} {mitigate / accept / transfer} {control or reference} open

Status: open · closed · open — below {block_on} threshold (non-blocking) Severity: critical > high > medium > low — only open threats at or above workflow.security_block_on count toward threats_open Disposition: mitigate (implementation required) · accept (documented risk) · transfer (third-party)


Accepted Risks Log

Risk ID Threat Ref Rationale Accepted By Date

Accepted risks do not resurface in future audit runs.

If none: "No accepted risks."


Security Audit Trail

Audit Date Threats Total Closed Open Run By
{YYYY-MM-DD} {N} {N} {N} {name / agent}

Sign-Off

  • All threats have a disposition (mitigate / accept / transfer)
  • Accepted risks documented in Accepted Risks Log
  • threats_open: 0 confirmed
  • status: verified set in frontmatter

Approval: {pending / verified YYYY-MM-DD}