OWASP / OWASP/quantum-security-project

Proposal: Extend the OWASP Quantum Security Top 10 Entry Template to improve Consistency, Actionability and Verifiability

Open
#15 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

documentation
Dominant language
No language data
Stars
99
Forks
32
PR merge metrics
No merged PRs in 30d

Description

After reviewing both the sprint plan and the current Top 10 entry template, I think there is an opportunity to further strengthen the consistency and practical value of the project through a small evolution of the template.

The current template provides a solid foundation, but several objectives described in the sprint plan, such as actionable guidance, consistency, evidence and being practical, are not yet explicitly reflected in the template.

Hence, the following sections are proposed.

I see this as an initial proposal rather than a finished design, and I'd be very interested in feedback from the community.
If there is general agreement, I'd be happy to prepare a pull request implementing the agreed changes.

Proposed Template Extensions

Scope

Clearly define what the entry covers and, equally importantly, what it does not cover.
This helps distinguish related entries and reduces overlap such as QS04, QS05 and QS06.

Detection

Describe how organisations can determine whether they are exposed to the risk as a practical starting point.

Examples include:

  • architecture reviews
  • cryptographic inventories
  • configuration analysis
  • software composition analysis
  • runtime monitoring
  • infrastructure assessments

Mitigations

Rather than listing high-level recommendations, mitigation guidance should be written as concrete engineering activities.

Ideally every mitigation should satisfy three principles:

  • Actionable: mitigation clearly describes what should be implemented.
  • Measurable: mitigation provides objective criteria for determining whether implementation has been completed.
  • Verifiable: mitigation be independently validated through testing, automation, configuration review or audit.

Related Risks

Where appropriate, reference other Top 10 entries that address adjacent or complementary risks.
This improves navigation and helps contributors maintain clear scope boundaries.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the sprint plan and the current Top 10 entry template referenced in the issue. Compare the proposed Scope, Detection, Mitigations, and Related Risks sections with the project's existing structure and read the discussion before proposing implementation details. Done means the community agrees on the template design and the agreed changes are reflected consistently.

Written by the indexing model from the issue text.

Assessment

Domain
content, documentation
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.