Methodology versus verification standard
A methodology structures test activity; a verification standard supplies agreed requirement-level checks. Neither replaces a defined scope.
A governed reference for testing depth, perspectives, coverage, evidence, mappings, limitations, retesting and framework review.
Damocles publishes the exact reference versions used to structure authorised work and reviews this register on a defined schedule.
A methodology structures test activity; a verification standard supplies agreed requirement-level checks. Neither replaces a defined scope.
Risk taxonomies group common risk themes. CWE classifies underlying weakness types. Taxonomies support consistent reporting but are not complete test procedures.
CVSS 4.0 records technical severity as a reproducible vector. Damocles records customer-specific impact and remediation priority separately.
Mappings connect scoped evidence to objectives. Regulatory applicability and compliance conclusions remain the responsibility of the regulated organisation and its advisers.
Scope records black-, grey- or white-box access, representative roles, locations and evidence access. More access can increase depth without making coverage unlimited.
Directly assessed means the engagement tests the relevant behaviour; supporting evidence means the output helps another assessment; contextual means the reference explains relevance but is not assessed.
Tested, Not Tested, Not Applicable and Unable to Validate distinguish completed work from exclusions, design inapplicability and constraints.
Evidence may include requests, responses, configuration observations and reproducible steps when safe. Reports retain scope, assumptions and remaining limitations.
When included, retesting repeats agreed procedures after remediation and records resolved, reduced or remaining exposure and residual risk.
Technical evidence supports risk, assurance and audit work. It does not certify an organisation, establish complete compliance or assess controls beyond authorised scope.
| Publisher and reference | Exact version | Role | Approved usage and limitations | Verification |
|---|---|---|---|---|
| OWASP: Web Security Testing Guide | 4.2 | methodology | Reference the named version for scoped technical testing, evidence classification or contextual mapping only. Open source; cite rather than reproduce extensive text. | Owner: Technical Assurance Verified: Next review: |
| OWASP: Application Security Verification Standard | 5.0.0 | verification-standard | Reference the named version for scoped technical testing, evidence classification or contextual mapping only. Open source; verify agreed requirements only. | Owner: Technical Assurance Verified: Next review: |
| OWASP: OWASP Top 10 | 2025 | risk-taxonomy | Reference the named version for scoped technical testing, evidence classification or contextual mapping only. Taxonomy only; not a complete testing method. | Owner: Technical Assurance Verified: Next review: |
| OWASP: OWASP API Security Top 10 | 2023 | risk-taxonomy | Reference the named version for scoped technical testing, evidence classification or contextual mapping only. Taxonomy only; applies only to APIs in scope. | Owner: Technical Assurance Verified: Next review: |
| MITRE: Common Weakness Enumeration | 4.20 | weakness-taxonomy | Reference the named version for scoped technical testing, evidence classification or contextual mapping only. Use identifiers and summaries subject to MITRE terms. | Owner: Technical Assurance Verified: Next review: |
| FIRST: Common Vulnerability Scoring System | 4.0 | severity-method | Reference the named version for scoped technical testing, evidence classification or contextual mapping only. Severity is separate from customer-specific business priority. | Owner: Technical Assurance Verified: Next review: |
| OWASP: Mobile Application Security Verification Standard | 2.1.0 | verification-standard | Reference the named version for scoped technical testing, evidence classification or contextual mapping only. Open source; verify only agreed requirements. | Owner: Technical Assurance Verified: Next review: |
| OWASP: Mobile Application Security Testing Guide | 2.0.0 | methodology | Reference the named version for scoped technical testing, evidence classification or contextual mapping only. Open source; platform and access constrain coverage. | Owner: Technical Assurance Verified: Next review: |
| Australian Signals Directorate: Information Security Manual | June 2026 | control-framework | Reference the named version for scoped technical testing, evidence classification or contextual mapping only. Cite official identifiers only; content changes over time. | Owner: Technical Assurance Verified: Next review: |
| Australian Signals Directorate: Guidelines for Software Development | June 2026 | testing-guidance | Reference the named version for scoped technical testing, evidence classification or contextual mapping only. Map only verified and applicable ISM identifiers. | Owner: Technical Assurance Verified: Next review: |
| APRA: Prudential Standard CPS 234 Information Security | effective 1 July 2019 | regulatory-framework | Reference the named version for scoped technical testing, evidence classification or contextual mapping only. Regulated entities determine applicability; mapping is not APRA approval. | Owner: Technical Assurance Verified: Next review: |
| APRA: Prudential Practice Guide CPG 234 Information Security | published June 2019 | prudential-guidance | Reference the named version for scoped technical testing, evidence classification or contextual mapping only. Guidance, not a certification standard. | Owner: Technical Assurance Verified: Next review: |
| NIST: Security and Privacy Controls for Information Systems and Organizations | Release 5.2.0 | control-framework | Reference the named version for scoped technical testing, evidence classification or contextual mapping only. Use official control identifiers; do not imply assessment of every control. | Owner: Technical Assurance Verified: Next review: |
| NIST: Technical Guide to Information Security Testing and Assessment | SP 800-115 | testing-guidance | Reference the named version for scoped technical testing, evidence classification or contextual mapping only. Guidance is tailored to authorised scope. | Owner: Technical Assurance Verified: Next review: |
| NIST: Incident Response Recommendations and Considerations for Cybersecurity Risk Management | Revision 3 | testing-guidance | Reference the named version for scoped technical testing, evidence classification or contextual mapping only. Guidance only; readiness review is not incident certification. | Owner: Technical Assurance Verified: Next review: |
| ISO: ISO/IEC 27001 | 2022 with Amendment 1:2024 | control-framework | Reference the named version for scoped technical testing, evidence classification or contextual mapping only. Licensed standard: name/version only; no unverified identifiers or control text. | Owner: Technical Assurance Verified: Next review: |
| ISO: ISO/IEC 27002 | 2022 | control-framework | Reference the named version for scoped technical testing, evidence classification or contextual mapping only. Licensed standard: name/version only; no unverified identifiers or control text. | Owner: Technical Assurance Verified: Next review: |
| PCI Security Standards Council: Payment Card Industry Data Security Standard | 4.0.1 | control-framework | Reference the named version for scoped technical testing, evidence classification or contextual mapping only. Licensed material: name/version only; exact mappings withheld until source access and applicability are verified. | Owner: Technical Assurance Verified: Next review: |
Publication boundary: MASWE is registered as draft/beta and is excluded from approved rendering. Other draft, expired and overdue references are also excluded. ISO and PCI control wording and unverified exact identifiers are not reproduced.