security-methodologylisted
Install: claude install-skill ClaudeRegistry/marketplace
# Security Assessment Methodology
## Purpose
Provide standardized security assessment frameworks, vulnerability classification systems, and compliance evaluation methodology for use during security scanning and auditing. Tech-agnostic, applies to any language or framework.
## OWASP Risk Rating
Calculate risk using these factors:
| Risk Factor | Score (0-9) | What to Evaluate |
|-------------|-------------|------------------|
| Threat Agent | 0-9 | Skill level, motive, opportunity, size of threat group |
| Attack Vector | 0-9 | Ease of exploitation (automated=9, requires physical access=1) |
| Security Weakness | 0-9 | Prevalence × detectability |
| Technical Impact | 0-9 | Loss of confidentiality, integrity, availability |
| Business Impact | 0-9 | Financial, reputation, compliance, privacy damage |
**Overall Risk** = Average of factors, weighted by context.
## Security Debt Calculation
| Severity | Remediation Time per Issue | Priority |
|----------|---------------------------|----------|
| Critical | 4 hours | P0, fix immediately |
| High | 2 hours | P1, fix this sprint |
| Medium | 1 hour | P2, fix this quarter |
| Low | 30 minutes | P3, fix when convenient |
**Total Security Debt** = Sum of (count × remediation time) per severity level.
## Security Maturity Model
| Level | Name | Description |
|-------|------|-------------|
| 0 | None | No security measures |
| 1 | Initial | Ad-hoc, reactive security |
| 2 | Managed | Basic security controls in place |
| 3 | De