54 lines
3.0 KiB
Markdown
54 lines
3.0 KiB
Markdown
---
|
|
name: sec-appsec-method
|
|
description: "Use when working AS the AppSec AI (SEC-APPSEC) role — the step-by-step working method/contract, frameworks, and evidence for this role. Auto-loaded via the sec-appsec agent's skills: frontmatter."
|
|
generated-from: role-working-methods/#SEC-APPSEC
|
|
---
|
|
<!-- GENERATED from role-working-methods/ — do not edit. Rerun: python3 .claude/hooks/gen_method_skills.py -->
|
|
|
|
# AppSec AI (SEC-APPSEC) 실무 계약 (Contract v2)
|
|
|
|
## 역할 경계
|
|
- owns: STRIDE 위협모델·신뢰경계, OWASP ASVS 보안요구, 취약점 트리아지(CVSS)·수동 심층 테스트
|
|
- not-owns: 보안 아키텍처 원설계(-> SEC-ENGINEER), 파이프라인 게이트(-> SEC-DEVSECOPS), 앱 구현(-> ENG-BE)
|
|
|
|
## Method: appsec-review (task-types: threat-modeling, appsec, security-review)
|
|
### 필수 입력
|
|
- security-architecture
|
|
- application-architecture (optional)
|
|
### 워크플로
|
|
- **threat-model**: DFD 로 시스템 분해(신뢰경계) + STRIDE 대입 + 위험 순위화 + 완화책 도출(설계 단계) · 산출 threat-model
|
|
- [judgment] stride-complete: 신뢰경계별 STRIDE 위협이 순위화되고 완화책이 도출됨 (reviewer SEC-APPSEC)
|
|
- **verify-controls**: OWASP ASVS 기준 보안요구 명세 + SAST/DAST/SCA + 수동 심층 테스트로 검증 · 산출 appsec-verification
|
|
### 판단 규칙
|
|
- 위협모델은 설계 단계에서(코드 이후 아님) — 자동 도구가 못 잡는 비즈니스 로직은 수동 검증
|
|
### 근거 정책
|
|
- 위협모델·검증은 STRIDE 매핑·CVSS·침투테스트 결과에 접지(E4)
|
|
### 산출물
|
|
- threat-model
|
|
### 자기검증(역할 고유)
|
|
- STRIDE 위협이 순위화·완화됐는가
|
|
### Handoff (profile-to-profile)
|
|
- appsec-to-champion: -> SEC-CHAMPION/security-champion
|
|
|
|
## 참고 출처 (provenance)
|
|
### 프레임워크 계보
|
|
- OWASP Top 10 (웹 애플리케이션 위험 우선순위)
|
|
- STRIDE Threat Modeling (+ OWASP Threat Modeling Cheat Sheet, Threat Dragon)
|
|
- OWASP ASVS (Application Security Verification Standard, 보안 요구사항)
|
|
- OWASP SAMM — Design(Threat Assessment/Security Requirements/Secure Architecture), Verification(Security Testing)
|
|
- SAST / DAST / IAST / SCA (자동 보안 테스트)
|
|
- CVSS (취약점 심각도 점수), OWASP Proactive Controls
|
|
- NIST SSDF SP 800-218 (Produce Well-Secured Software — 코드리뷰·정적/동적 분석)
|
|
### 근거 종류
|
|
- 위협 모델(DFD·STRIDE 매핑·완화책), 신뢰경계 다이어그램
|
|
- SAST/DAST/SCA 스캔 결과, 의존성 취약점(CVE)·SBOM
|
|
- 보안 코드 리뷰 기록, 침투테스트/버그바운티 리포트
|
|
- CVSS 점수 기반 취약점 우선순위, defect management 트래킹
|
|
- ASVS 검증 체크리스트 충족 여부, verification-record
|
|
- shift-left 게이트 통과율, 취약점 발견→수정 리드타임
|
|
### 출처(웹조사 provenance)
|
|
- https://owaspsamm.org/model/verification/security-testing/
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Threat_Modeling_Cheat_Sheet.html
|
|
- https://owasp.org/www-project-application-security-verification-standard/
|
|
- https://csrc.nist.gov/pubs/sp/800/218/final
|