OWASP / OpenCRE

Home Page:https://opencre.org

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

gap analysis: better reserve a special category for 0-links, and more

robvanderveer opened this issue · comments

0-links are by definition direct links and it would be good to highlight them with a color and name. One way to do this is to reserve 'Strong' for 0. And relabel it to 'Direct for clarity. This would also solve many situations where 'strong' is not a suitable qualification for the link. Like for example SAMM secret management linking strong (3) to 'follow secure coding practices'. The downside of this is that 'average' is a too weak qualification for (1) and (2) scores. Therefore I suggest to relabel that to 'medium', since the word average has a too negative connotation.
So: reserve 'strong' for 0. Relabel 'strong' to 'direct'. Relabel 'Average' to 'Medium'.
And while we are at it, relabel 'weak' to 'low' because of the negative connotation.
Also: adopt the descriptions.
Makes sense?