[Docs] Downgrade MIAUW-conforming, and name the methodology provenance #604

Closed
opened 2026-07-22 16:19:51 +00:00 by brenno · 1 comment
Owner

Found in the pre-publication legal review.

Evidence: README.md:28 — an optional module "for authoring MIAUW-conforming penetration-test reports"; docs/USER_GUIDE.md:2471 and :2540 — "It scaffolds a complete, MIAUW-conforming report in one step."

The project own overview says the opposite: docs/USER_GUIDE.md:2718-2719 — "Every requirement is waivable with a mandatory reason — it is a gap analysis, never a hard gate."

Separately, the methodology is not the foundation own: docs/LICENSE_COMPLIANCE.md:125 points at github.com/brennodewinter/Informatiebeveiligingsonderzoek, the initiator personal repository. That overlap appears nowhere in the public text, and lib/services/miauw_eis_catalog.dart is the only bundled dataset missing the THIRD-PARTY CONTENT header that CWE, WSTG, MASTG and MASWE all carry.

Why this matters now: "conforming" is a conformity statement about someone else methodology, made by a tool that lets every requirement be waived. The penetration tester client reads it as a statement about the delivered report. That the author of MIAUW and the initiator of OciDeck are the same person does not make the claim wrong, but it is something you name yourself before somebody else does.

Proposal: change "MIAUW-conforming" to "reports structured to the MIAUW methodology", and add a row to THIRD_PARTY_NOTICES.md under Trademarks: MIAUW, its owner and origin, with one sentence noting that the initiator of OciDeck is also the author of that methodology. Add the missing THIRD-PARTY CONTENT header to miauw_eis_catalog.dart.

Found in the pre-publication legal review. **Evidence:** `README.md:28` — an optional module "for authoring **MIAUW-conforming** penetration-test reports"; `docs/USER_GUIDE.md:2471` and `:2540` — "It scaffolds a complete, **MIAUW-conforming** report in one step." The project own overview says the opposite: `docs/USER_GUIDE.md:2718-2719` — "**Every requirement is waivable** with a mandatory reason — it is a gap analysis, **never a hard gate**." Separately, the methodology is not the foundation own: `docs/LICENSE_COMPLIANCE.md:125` points at `github.com/brennodewinter/Informatiebeveiligingsonderzoek`, the initiator personal repository. That overlap appears nowhere in the public text, and `lib/services/miauw_eis_catalog.dart` is the only bundled dataset missing the `THIRD-PARTY CONTENT` header that CWE, WSTG, MASTG and MASWE all carry. **Why this matters now:** "conforming" is a conformity statement about someone else methodology, made by a tool that lets every requirement be waived. The penetration tester client reads it as a statement about the delivered report. That the author of MIAUW and the initiator of OciDeck are the same person does not make the claim wrong, but it is something you name yourself before somebody else does. **Proposal:** change "MIAUW-conforming" to "reports structured to the MIAUW methodology", and add a row to `THIRD_PARTY_NOTICES.md` under *Trademarks*: MIAUW, its owner and origin, with one sentence noting that the initiator of OciDeck is also the author of that methodology. Add the missing `THIRD-PARTY CONTENT` header to `miauw_eis_catalog.dart`.
Author
Owner

Opgelost in #656 (gemerged). make check groen op de gerebasede kop.

Opgelost in #656 (gemerged). `make check` groen op de gerebasede kop.
brenno 2026-07-22 17:30:07 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
LibreKAT/Ocideck#604
No description provided.