Damocles methodology resource

Understand how technical assurance is structured and evidenced.

A governed reference for testing depth, perspectives, coverage, evidence, mappings, limitations, retesting and framework review.

Governed technical assurance

How to read our methods, coverage and mappings

Damocles publishes the exact reference versions used to structure authorised work and reviews this register on a defined schedule.

Methodology versus verification standard

A methodology structures test activity; a verification standard supplies agreed requirement-level checks. Neither replaces a defined scope.

Risk and weakness taxonomies

Risk taxonomies group common risk themes. CWE classifies underlying weakness types. Taxonomies support consistent reporting but are not complete test procedures.

Severity and business impact

CVSS 4.0 records technical severity as a reproducible vector. Damocles records customer-specific impact and remediation priority separately.

Control frameworks and regulatory guidance

Mappings connect scoped evidence to objectives. Regulatory applicability and compliance conclusions remain the responsibility of the regulated organisation and its advisers.

Testing depth and perspectives

Scope records black-, grey- or white-box access, representative roles, locations and evidence access. More access can increase depth without making coverage unlimited.

Mapping types

Directly assessed means the engagement tests the relevant behaviour; supporting evidence means the output helps another assessment; contextual means the reference explains relevance but is not assessed.

Coverage statuses

Tested, Not Tested, Not Applicable and Unable to Validate distinguish completed work from exclusions, design inapplicability and constraints.

Evidence and limitations

Evidence may include requests, responses, configuration observations and reproducible steps when safe. Reports retain scope, assumptions and remaining limitations.

Retesting

When included, retesting repeats agreed procedures after remediation and records resolved, reduced or remaining exposure and residual risk.

Why mapping is not certification

Technical evidence supports risk, assurance and audit work. It does not certify an organisation, establish complete compliance or assess controls beyond authorised scope.

Approved framework versions

Approved technical-assurance references, versions, roles, usage limitations and review dates.
Publisher and referenceExact versionRoleApproved usage and limitationsVerification
OWASP: Web Security Testing Guide4.2methodologyReference the named version for scoped technical testing, evidence classification or contextual mapping only. Open source; cite rather than reproduce extensive text.Owner: Technical Assurance
Verified:
Next review:
OWASP: Application Security Verification Standard5.0.0verification-standardReference the named version for scoped technical testing, evidence classification or contextual mapping only. Open source; verify agreed requirements only.Owner: Technical Assurance
Verified:
Next review:
OWASP: OWASP Top 102025risk-taxonomyReference the named version for scoped technical testing, evidence classification or contextual mapping only. Taxonomy only; not a complete testing method.Owner: Technical Assurance
Verified:
Next review:
OWASP: OWASP API Security Top 102023risk-taxonomyReference the named version for scoped technical testing, evidence classification or contextual mapping only. Taxonomy only; applies only to APIs in scope.Owner: Technical Assurance
Verified:
Next review:
MITRE: Common Weakness Enumeration4.20weakness-taxonomyReference the named version for scoped technical testing, evidence classification or contextual mapping only. Use identifiers and summaries subject to MITRE terms.Owner: Technical Assurance
Verified:
Next review:
FIRST: Common Vulnerability Scoring System4.0severity-methodReference the named version for scoped technical testing, evidence classification or contextual mapping only. Severity is separate from customer-specific business priority.Owner: Technical Assurance
Verified:
Next review:
OWASP: Mobile Application Security Verification Standard2.1.0verification-standardReference the named version for scoped technical testing, evidence classification or contextual mapping only. Open source; verify only agreed requirements.Owner: Technical Assurance
Verified:
Next review:
OWASP: Mobile Application Security Testing Guide2.0.0methodologyReference the named version for scoped technical testing, evidence classification or contextual mapping only. Open source; platform and access constrain coverage.Owner: Technical Assurance
Verified:
Next review:
Australian Signals Directorate: Information Security ManualJune 2026control-frameworkReference the named version for scoped technical testing, evidence classification or contextual mapping only. Cite official identifiers only; content changes over time.Owner: Technical Assurance
Verified:
Next review:
Australian Signals Directorate: Guidelines for Software DevelopmentJune 2026testing-guidanceReference the named version for scoped technical testing, evidence classification or contextual mapping only. Map only verified and applicable ISM identifiers.Owner: Technical Assurance
Verified:
Next review:
APRA: Prudential Standard CPS 234 Information Securityeffective 1 July 2019regulatory-frameworkReference the named version for scoped technical testing, evidence classification or contextual mapping only. Regulated entities determine applicability; mapping is not APRA approval.Owner: Technical Assurance
Verified:
Next review:
APRA: Prudential Practice Guide CPG 234 Information Securitypublished June 2019prudential-guidanceReference the named version for scoped technical testing, evidence classification or contextual mapping only. Guidance, not a certification standard.Owner: Technical Assurance
Verified:
Next review:
NIST: Security and Privacy Controls for Information Systems and OrganizationsRelease 5.2.0control-frameworkReference the named version for scoped technical testing, evidence classification or contextual mapping only. Use official control identifiers; do not imply assessment of every control.Owner: Technical Assurance
Verified:
Next review:
NIST: Technical Guide to Information Security Testing and AssessmentSP 800-115testing-guidanceReference the named version for scoped technical testing, evidence classification or contextual mapping only. Guidance is tailored to authorised scope.Owner: Technical Assurance
Verified:
Next review:
NIST: Incident Response Recommendations and Considerations for Cybersecurity Risk ManagementRevision 3testing-guidanceReference the named version for scoped technical testing, evidence classification or contextual mapping only. Guidance only; readiness review is not incident certification.Owner: Technical Assurance
Verified:
Next review:
ISO: ISO/IEC 270012022 with Amendment 1:2024control-frameworkReference the named version for scoped technical testing, evidence classification or contextual mapping only. Licensed standard: name/version only; no unverified identifiers or control text.Owner: Technical Assurance
Verified:
Next review:
ISO: ISO/IEC 270022022control-frameworkReference the named version for scoped technical testing, evidence classification or contextual mapping only. Licensed standard: name/version only; no unverified identifiers or control text.Owner: Technical Assurance
Verified:
Next review:
PCI Security Standards Council: Payment Card Industry Data Security Standard4.0.1control-frameworkReference the named version for scoped technical testing, evidence classification or contextual mapping only. Licensed material: name/version only; exact mappings withheld until source access and applicability are verified.Owner: Technical Assurance
Verified:
Next review:

Publication boundary: MASWE is registered as draft/beta and is excluded from approved rendering. Other draft, expired and overdue references are also excluded. ISO and PCI control wording and unverified exact identifiers are not reproduced.