Assessment boundaries
- Authorized assets
- allowed test classes
- rate and concurrency
- credentials
- sensitive paths
- data handling
- stop conditions
- reporting contact
Evidence handling
- Collect the minimum needed
- avoid sensitive payload retention
- restrict access
- record provenance
- protect exports
- delete according to policy
Remediation safety
- Qualified review
- change approval
- test environment
- backup or rollback
- deployment record
- verification
- incident escalation
Evidence standard
- State the authorization, scope, exclusions, environment, timing, and methodology version for security assessment.
- Reproducible evidence that avoids collecting unnecessary secrets or personal information.
- Distinguish direct observation, calculated result, heuristic, inference, and manual judgment.
- Preserve failed, incomplete, blocked, and uncertain checks instead of silently dropping them.
Interpretation and decision record
A methodology should help reviewers reach the same bounded conclusion from the same evidence. It should not imply certainty beyond the assessed scope. Record the finding, limitation, owner, decision, remediation, and the verification required to reduce avoidable exposure while preserving authorization, evidence quality, and change control.
Decision and verification record
Scope
Name the website, environment, URLs, entities, templates, or user journeys included in the security assessment decision.
Decision
Record the chosen action, owner, priority, dependencies, approval, and the evidence that justified it.
Verification
Repeat the relevant check from an authorized context, confirm the original evidence is no longer reproducible, and retain a dated result.
Turn security assessment into an accountable record.
A reproducible security assessment assessment record with scope, evidence, limitations, and verification rules.