Skip to content

QS05: add governance, ownership and measurability controls - #36

Open
goubach wants to merge 1 commit into
OWASP:mainfrom
goubach:qs05-governance-controls
Open

QS05: add governance, ownership and measurability controls#36
goubach wants to merge 1 commit into
OWASP:mainfrom
goubach:qs05-governance-controls

Conversation

@goubach

@goubach goubach commented Aug 6, 2026

Copy link
Copy Markdown

Addresses #35

What changes

  • Description: frames crypto-agility as a governed, owned and measurable capability.
  • How to Prevent: adds two controls (ownership and governing policy; agility measurability), with a one-line pointer to the inventory in QS04.
  • Example Attack Scenarios: adds Scenario 3, a governance failure where agility cannot be exercised in time.

What does not change

  • No edits to Reference Links or the Standards and Regulatory Mapping section (open TODO for the leads).
  • No overlap introduced with QS04 (inventory) or QS06 (hybrid).

Addresses OWASP#35

What changes
- Description: frames crypto-agility as a governed, owned and measurable capability.
- How to Prevent: adds two controls (ownership and governing policy; agility measurability), with a one-line pointer to the inventory in QS04.
- Example Attack Scenarios: adds Scenario OWASP#3, a governance failure where agility cannot be exercised in time.

What does not change
- No edits to Reference Links or the Standards and Regulatory 
- Mapping section (open TODO for the leads).
- No overlap introduced with QS04 (inventory) or QS06 (hybrid).
@nmcitra

nmcitra commented Aug 7, 2026

Copy link
Copy Markdown

As promised in the channel. The substance is right and I support all three additions — the ownership control fills the gap #35 named, the measurability control is what makes it auditable rather than aspirational, and Scenario 3 is the missing failure mode: the technology worked and the organisation couldn't exercise it. Keeping the references and standards mapping untouched for the leads was the right call.

My notes are all at the wording level, five of them:

  1. "it must have named owner, governed by policy, and measurable" — the parallelism breaks. Suggest: "it must have a named owner, a governing policy, and a measurable definition of agility."
  2. "share systems behind the abstraction layer" and "share protocols that negotiate" — both want "of": "share of systems…", "share of protocols…".
  3. "since we can only utilise agile what the inventory (QS04) reveals" — suggest: "since agility can only be exercised over what the inventory (QS04) reveals."
  4. Scenario 3 opens on a fragment ("An organisation that is technically agile, with crypto abstraction layer and negotiable protocols."). Folding it into the next sentence fixes it.
  5. The scenario's close — "yielding the exposure a governance problem rather than a technical concern" — suggest: "leaving the exposure as a governance problem rather than a technical one."

All five are paste-ready if useful. Substance-wise this is ready; happy to re-read after the wording pass.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants