Someone else's data
A worked example, so you can see the shape before answering anything.
Start
Coverage map
Workspace
Continuous assurance
A worked example. Nothing here belongs to you — start your own assessment to see yours.
198 weight covered221 weight not covered
Do we have the necessary security controls everywhere we need them?
Are those controls actually effective, or do scanners just run alongside?
Has this become a governable, measurable, continuously improved process?
NIST SSDF and OWASP SAMM as views over the same controls — nothing here is recomputed.
10 requirements were assessed of 15. The percentage is over those and nothing else.
OWASP · version 2.0