owaspsamm / core

Core model including reused documentation
Creative Commons Attribution Share Alike 4.0 International
76 stars 35 forks source link

Probably mistake in rating calculation for Google spreadsheet v2.0.6 #153

Open amedvedchuk opened 3 months ago

amedvedchuk commented 3 months ago

Hi there! It seems to be a mistake in google spreadsheet version for SAMM assessment v2.0.6 on the Interview tab. Link to file: https://docs.google.com/spreadsheets/d/1jmLVltRhuG19AX5cLUcWH1Qox2Uic17rD29gMVG5zDE/view#gid=1649885013

There are three places where calculation differs from others and from those in Microsoft excel version v2.0.8 (https://github.com/owaspsamm/core/releases/download/v2.0.8/SAMM_spreadsheet.xlsx)

Actual calculations: https://docs.google.com/spreadsheets/d/1jmLVltRhuG19AX5cLUcWH1Qox2Uic17rD29gMVG5zDE/view#gid=1649885013&range=H25:H30 https://docs.google.com/spreadsheets/d/1jmLVltRhuG19AX5cLUcWH1Qox2Uic17rD29gMVG5zDE/view#gid=1649885013&range=H39:H44 https://docs.google.com/spreadsheets/d/1jmLVltRhuG19AX5cLUcWH1Qox2Uic17rD29gMVG5zDE/view#gid=1649885013&range=H53:H58

As I understand these sells need to be empty otherwise answers from one security practice For example "Policy & Compliance" affects "Strategy & Metrics" and so on.