Skip to content

Rough draft of example / audit vs assessment...#2

Open
JustinCappos wants to merge 2 commits intomainfrom
JustinCappos-audit-vs-assessment
Open

Rough draft of example / audit vs assessment...#2
JustinCappos wants to merge 2 commits intomainfrom
JustinCappos-audit-vs-assessment

Conversation

@JustinCappos
Copy link
Copy Markdown
Contributor

I think this is a really contrived example. I'd welcome a different example that doesn't sound so silly.

I think this is a really contrived example.   I'd welcome a different example that doesn't sound so silly.

Signed-off-by: Justin Cappos <justincappos@gmail.com>
Co-authored-by: Andrew Martin <sublimino@gmail.com>
Signed-off-by: Justin Cappos <justincappos@gmail.com>
Copy link
Copy Markdown
Contributor

@trumant trumant left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This paragraph doesn't seem to naturally follow from the discussion above about a "tiered model".

Perhaps this content is better placed following the ##Approach heading or further down in the document.


## What is an assessment and how does it relate to an audit

Both a security assessment and a security audit help to understand the security of a system and play different, but overlapping, roles. A security audit focuses primarily at looking for security defects in a project's implementation or a deviation from established best practices. In contrast, an assessment focuses on thinking about what a reasonable project of this type might be expected to provide in terms of security properties and potential gotchas for users.
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

NIt: you are using 2 spaces following a period, whereas all other text here uses a single space following a period.

@eddie-knight
Copy link
Copy Markdown
Contributor

Apologies that this sat un-merged for so long. I think it's been made obsolete by #21

@JustinCappos is there anything new in this PR that you want me to move over to the Audits vs Assessments page?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants