Custom · 7 sections
Choose and order sections
In this report
Choosing and ordering sections is part of the free assessment. The shape travels in the address, so it survives a reload and can be bookmarked; nothing is stored. A link to your own report still needs your session — a report link somebody else can open is not built yet.
1What was assessed
Web application, API, Critical criticality, internet-facing, holds personal data, holds financial data. Built from 11 technologies across 3 environments.
No scanner was connected and no repository was read. Everything below is derived from the answers given in the assessment.
2Across the lifecycle
The same scope cells, grouped by where in the delivery lifecycle they are demanded. A phase with nothing required is not a failing phase.
| Phase | Coverage | Open gaps |
|---|---|---|
| Plan | 0% | 1 |
| Design | 67% | 1 |
| Code | 78% | 10 |
| Build | 89% | 6 |
| Test | 14% | 15 |
| Release | 0% | 12 |
| Deploy | 29% | 21 |
| Operate | 38% | 58 |
| Monitor / Respond | 32% | 7 |
3Coverage by capability
Every capability the profile required, with the share of its scopes that something covers and the maturity of what covers them.
| Capability | Coverage | Maturity | Open gaps |
|---|---|---|---|
| API Security Testing | 0% | 0 | 9 |
| Fuzzing | 0% | 0 | 4 |
| Kubernetes Security | 0% | 0 | 9 |
| Runtime Security | 0% | 0 | 12 |
| Security Requirements | 0% | 0 | 1 |
| DAST | 7% | 0.1 | 8 |
| Vulnerability Scanning | 17% | 0.3 | 25 |
| Penetration Testing | 29% | 0.3 | 7 |
| Admission Control | 33% | 0.7 | 3 |
| Network Security | 33% | 0.7 | 12 |
| Drift Detection | 50% | 1 | 12 |
| IaC Security | 50% | 1 | 6 |
| Threat Modeling | 50% | 0.5 | 1 |
| Secrets Management | 60% | 1.2 | 2 |
| Cloud Configuration Security | 67% | 1.3 | 2 |
| Code Review Security | 67% | 0.7 | 1 |
| Secret Scanning | 67% | 2.7 | 1 |
| SIEM | 67% | 1.3 | 1 |
| Workload Identity | 67% | 1.3 | 6 |
| SCA | 73% | 1.5 | 9 |
| Container Security | 100% | 4 | 0 |
| Incident Response | 100% | 1 | 0 |
| SAST | 100% | 3.2 | 0 |
| Secure Architecture | 100% | 1 | 0 |
| Vulnerability Management | 100% | 2 | 0 |
4Against the frameworks
- NIST SSDF 1.1 — 57%2 satisfied, 6 partial, 2 not satisfied. A further 7 ask for controls your profile did not require — the framework is stricter than your baseline there — and 2 are not addressed by this control catalog at all. Both are excluded from the percentage rather than counted against you.
- OWASP SAMM 2.0 — 51%2 satisfied, 6 partial, 2 not satisfied. A further 3 ask for controls your profile did not require — the framework is stricter than your baseline there — and 2 are not addressed by this control catalog at all. Both are excluded from the percentage rather than counted against you.
5What is in place today
Every control this assessment recorded as being in place — the Ist side of the coverage number, named rather than counted.
| What is in place | Tool | How it runs | Enforcement | Weight carried | Effectiveness | Maturity |
|---|---|---|---|---|---|---|
| Trivy dependency scan on pull requests and in CI | Trivy | automated | a warning | 36 | 75% | 2 |
| Trivy gate on the container build | Trivy | automated | a warning | 27 | 75% | 2 |
| Argo CD reconciliation against Git | Argo CD | continuous | a warning | 24 | 50% | 2 |
| Checkov Terraform scan on pull requests and in CI | Checkov | automated | a warning | 12 | 59% | 2 |
| Entra Workload Identity on AKS | no tool | automated | not enforced | 12 | 25% | 2 |
| Trivy image scan in CI and registry | Trivy | automated | blocking | 12 | 94% | 4 |
| Defender for Cloud vulnerability assessment in production | Microsoft Defender for Cloud | continuous | a warning | 10 | 73% | 2 |
| Renovate dependency update pull requests | Renovate | automated | not enforced | 9 | 25% | 2 |
| Semgrep rules on pull requests | Semgrep | automated | a warning | 9 | 67% | 2 |
| SonarQube pull request gate | SonarQube | automated | blocking | 9 | 94% | 4 |
| Annual third-party penetration test | no tool | manual | not enforced | 6 | 0% | 1 |
| Default-deny NetworkPolicies in the cluster | no tool | automated | blocking | 6 | 63% | 2 |
| DefectDojo as the finding destination | DefectDojo | automated | informational | 6 | 50% | 2 |
| SonarQube analysis of the main branch | SonarQube | automated | a warning | 6 | 75% | 2 |
| Azure Key Vault for application secrets | no tool | automated | not enforced | 3 | 25% | 2 |
| Azure Policy deny assignments on resource deployments | no tool | automated | blocking | 3 | 63% | 2 |
| DefectDojo SLA policy per severity | DefectDojo | automated | informational | 3 | 57% | 2 |
| Kyverno policies in audit mode | Kyverno | continuous | informational | 3 | 40% | 2 |
| Azure Monitor log pipeline | no tool | continuous | informational | 2 | 40% | 2 |
| Gitleaks over the repository and its history | Gitleaks | automated | blocking | 2 | 94% | 4 |
| Architecture board sign-off on major changes | no tool | manual | approval-required | 1 | 29% | 1 |
| Branch protection requiring a second reviewer | GitHub Advanced Security | semi-automated | approval-required | 1 | 41% | 1 |
| CODEOWNERS review on the payment paths | GitHub Advanced Security | semi-automated | approval-required | 1 | 41% | 1 |
| Defender for Cloud posture on the production subscription | Microsoft Defender for Cloud | continuous | a warning | 1 | 73% | 2 |
| Incident response runbook, rehearsed twice a year | no tool | manual | not enforced | 1 | 0% | 1 |
| OWASP ZAP baseline scan against TEST | OWASP ZAP | semi-automated | informational | 1 | 45% | 1 |
| STRIDE workshop held at design time | no tool | manual | not enforced | 1 | 0% | 1 |
Weight, not a count: a scope carries the weight of the requirement level behind it, and the coverage percentage is over those same weights. A control carrying zero weight is in place but covers nothing this profile requires.
6Recommended next improvements
- 1. Introduce Known Vulnerability ScanCoverage impact +7.2 % · risk reduction critical · closes 15 scopes
- 2. Introduce Vulnerable Dependency GateCoverage impact +6.4 % · risk reduction critical · closes 9 scopes
- 3. Extend Infrastructure Drift Detection to the rest of your stackCoverage impact +5.7 % · risk reduction critical · closes 12 scopes
- 3. Introduce Runtime Threat DetectionCoverage impact +5.7 % · risk reduction critical · closes 12 scopes
- 5. Extend Known Vulnerability Scan to every environmentCoverage impact +4.8 % · risk reduction high · closes 10 scopes
At most 5 improvements are ranked here, by what each would move. This is the top of the list, not the whole work list — everything still open is in the CSV export.
7The three numbers
Coverage
47%
Effectiveness
61%
Maturity
1.0 / 5 (Available)
198 covered221 not covered
- Coverage
- 198 of 419 weighted scopes are covered by something. 250 scopes were required in total.
- Effectiveness
- How much those controls actually do. 35% of this score could not be assessed, because evidence collection and ownership are not part of this release; those components were excluded rather than guessed.
- Maturity
- Averaged over everything the profile requires, with uncovered scope counting as level 0. Coverage and maturity move independently: a control can run everywhere and still be an immature process.

