Interim Findings: How Well Does Federal Guidance Cover the OWASP CI/CD Top 10?
700 mapping cells later: interim results from my SANS research mapping federal cybersecurity guidance against the OWASP Top 10 CI/CD Security Risks, and the four gap areas every pipeline owner should check.
Interim Findings: How Well Does Federal Guidance Cover the OWASP CI/CD Top 10?
Last month I introduced my SANS research project: a structured mapping of federal cybersecurity guidance against the risks that actually show up in CI/CD pipelines. The control-extraction and mapping phase is now done, and the interim numbers are worth sharing.
The usual caveat applies, and I mean it: these are interim results from a single coder. An independent reliability audit is pending, and no final calls get made until it has run. I flag this not as fine print but because reporting what the evidence says, before you know whether you like it, is the whole job. It is the same discipline I bring to security audits.










