Custom · 7 sections
Choose and order sections
In this report
Choosing and ordering sections is part of the free assessment. The shape travels in the address, so it survives a reload and can be bookmarked; nothing is stored. A link to your own report still needs your session — a report link somebody else can open is not built yet.
1What is in place today
Every control this assessment recorded as being in place — the Ist side of the coverage number, named rather than counted.
| What is in place | Tool | How it runs | Enforcement | Weight carried | Effectiveness | Maturity |
|---|---|---|---|---|---|---|
| Trivy dependency scan on pull requests and in CI | Trivy | automated | a warning | 36 | 75% | 2 |
| Trivy gate on the container build | Trivy | automated | a warning | 27 | 75% | 2 |
| Argo CD reconciliation against Git | Argo CD | continuous | a warning | 24 | 50% | 2 |
| Checkov Terraform scan on pull requests and in CI | Checkov | automated | a warning | 12 | 59% | 2 |
| Entra Workload Identity on AKS | no tool | automated | not enforced | 12 | 25% | 2 |
| Trivy image scan in CI and registry | Trivy | automated | blocking | 12 | 94% | 4 |
| Defender for Cloud vulnerability assessment in production | Microsoft Defender for Cloud | continuous | a warning | 10 | 73% | 2 |
| Renovate dependency update pull requests | Renovate | automated | not enforced | 9 | 25% | 2 |
| Semgrep rules on pull requests | Semgrep | automated | a warning | 9 | 67% | 2 |
| SonarQube pull request gate | SonarQube | automated | blocking | 9 | 94% | 4 |
| Annual third-party penetration test | no tool | manual | not enforced | 6 | 0% | 1 |
| Default-deny NetworkPolicies in the cluster | no tool | automated | blocking | 6 | 63% | 2 |
| DefectDojo as the finding destination | DefectDojo | automated | informational | 6 | 50% | 2 |
| SonarQube analysis of the main branch | SonarQube | automated | a warning | 6 | 75% | 2 |
| Azure Key Vault for application secrets | no tool | automated | not enforced | 3 | 25% | 2 |
| Azure Policy deny assignments on resource deployments | no tool | automated | blocking | 3 | 63% | 2 |
| DefectDojo SLA policy per severity | DefectDojo | automated | informational | 3 | 57% | 2 |
| Kyverno policies in audit mode | Kyverno | continuous | informational | 3 | 40% | 2 |
| Azure Monitor log pipeline | no tool | continuous | informational | 2 | 40% | 2 |
| Gitleaks over the repository and its history | Gitleaks | automated | blocking | 2 | 94% | 4 |
| Architecture board sign-off on major changes | no tool | manual | approval-required | 1 | 29% | 1 |
| Branch protection requiring a second reviewer | GitHub Advanced Security | semi-automated | approval-required | 1 | 41% | 1 |
| CODEOWNERS review on the payment paths | GitHub Advanced Security | semi-automated | approval-required | 1 | 41% | 1 |
| Defender for Cloud posture on the production subscription | Microsoft Defender for Cloud | continuous | a warning | 1 | 73% | 2 |
| Incident response runbook, rehearsed twice a year | no tool | manual | not enforced | 1 | 0% | 1 |
| OWASP ZAP baseline scan against TEST | OWASP ZAP | semi-automated | informational | 1 | 45% | 1 |
| STRIDE workshop held at design time | no tool | manual | not enforced | 1 | 0% | 1 |
Weight, not a count: a scope carries the weight of the requirement level behind it, and the coverage percentage is over those same weights. A control carrying zero weight is in place but covers nothing this profile requires.
2Where the gaps are
170 gaps in total, 95 of them critical or high.
| Severity | Control | Where | What is wrong |
|---|---|---|---|
| critical | Authenticated Dynamic Scan | Production · CI Pipeline | nothing covers it |
| critical | Periodic Penetration Test | Production · Manual Review | expected runs automatically, actual run by hand |
| critical | Periodic Penetration Test | Production · Manual Review | expected runs automatically, actual run by hand |
| critical | Vulnerable Dependency Gate | Production · Java · CI Pipeline | expected blocking, actual a warning |
| critical | Vulnerable Dependency Gate | Production · Java · Release Gate | nothing covers it |
| critical | Vulnerable Dependency Gate | Production · Spring Boot · CI Pipeline | expected blocking, actual a warning |
| critical | Vulnerable Dependency Gate | Production · Spring Boot · Release Gate | nothing covers it |
| critical | Vulnerable Dependency Gate | Production · React · CI Pipeline | expected blocking, actual a warning |
| critical | Vulnerable Dependency Gate | Production · React · Release Gate | nothing covers it |
| critical | Admission Policy Enforcement | Production · Kubernetes · Admission | nothing covers it |
| critical | IaC Misconfiguration Detection | Production · Helm · Pull Request | it runs elsewhere, but not for this technology |
| critical | IaC Misconfiguration Detection | Production · Helm · CI Pipeline | it runs elsewhere, but not for this technology |
| critical | Infrastructure Drift Detection | Production · Terraform · Continuous Scan | it runs elsewhere, but not for this technology |
| critical | Infrastructure Drift Detection | Production · Terraform · Runtime | it runs elsewhere, but not for this technology |
| critical | Infrastructure Drift Detection | Production · Azure · Continuous Scan | it runs elsewhere, but not for this technology |
The remaining 80 critical or high gaps are in the CSV export.
3What was assessed
Web application, API, Critical criticality, internet-facing, holds personal data, holds financial data. Built from 11 technologies across 3 environments.
No scanner was connected and no repository was read. Everything below is derived from the answers given in the assessment.
4Recommended next improvements
- 1. Introduce Known Vulnerability ScanCoverage impact +7.2 % · risk reduction critical · closes 15 scopes
- 2. Introduce Vulnerable Dependency GateCoverage impact +6.4 % · risk reduction critical · closes 9 scopes
- 3. Extend Infrastructure Drift Detection to the rest of your stackCoverage impact +5.7 % · risk reduction critical · closes 12 scopes
- 3. Introduce Runtime Threat DetectionCoverage impact +5.7 % · risk reduction critical · closes 12 scopes
- 5. Extend Known Vulnerability Scan to every environmentCoverage impact +4.8 % · risk reduction high · closes 10 scopes
At most 5 improvements are ranked here, by what each would move. This is the top of the list, not the whole work list — everything still open is in the CSV export.
5Across the lifecycle
The same scope cells, grouped by where in the delivery lifecycle they are demanded. A phase with nothing required is not a failing phase.
| Phase | Coverage | Open gaps |
|---|---|---|
| Plan | 0% | 1 |
| Design | 67% | 1 |
| Code | 78% | 10 |
| Build | 89% | 6 |
| Test | 14% | 15 |
| Release | 0% | 12 |
| Deploy | 29% | 21 |
| Operate | 38% | 58 |
| Monitor / Respond | 32% | 7 |
6The three numbers
Coverage
47%
Effectiveness
61%
Maturity
1.0 / 5 (Available)
198 covered221 not covered
- Coverage
- 198 of 419 weighted scopes are covered by something. 250 scopes were required in total.
- Effectiveness
- How much those controls actually do. 35% of this score could not be assessed, because evidence collection and ownership are not part of this release; those components were excluded rather than guessed.
- Maturity
- Averaged over everything the profile requires, with uncovered scope counting as level 0. Coverage and maturity move independently: a control can run everywhere and still be an immature process.
7Against the frameworks
- NIST SSDF 1.1 — 57%2 satisfied, 6 partial, 2 not satisfied. A further 7 ask for controls your profile did not require — the framework is stricter than your baseline there — and 2 are not addressed by this control catalog at all. Both are excluded from the percentage rather than counted against you.
- OWASP SAMM 2.0 — 51%2 satisfied, 6 partial, 2 not satisfied. A further 3 ask for controls your profile did not require — the framework is stricter than your baseline there — and 2 are not addressed by this control catalog at all. Both are excluded from the percentage rather than counted against you.

