Fork me on GitHub

Test and Verification -> Consolidation: Reproducible defect tickets

Risk and Opportunity

Risk: Vulnerability descriptions are hard to understand by staff from operations and development.
Opportunity: Vulnerabilities include the test procedure to give the staff from operations and development the ability to reproduce vulnerabilities. This enhances the understanding of vulnerabilities and therefore the fix have a higher quality.

Exploit details

Usefullness: Low
Required knowledge: Medium (two disciplines)
Required time: Low
Required resources (systems): Low

Additional Information

Implementation hints: Mozilla Zest
OWASP SAMM 2 Mapping: i-defect-management|B|2
ISO27001:2017 Controls Mapping: