On this page
The operating model
A Company owns the managed inventory. An Application is the business-level Magento system; an Instance is one deployable environment of that Application. Security requirements are configured and evaluated in that context.
Profiles and Company Baselines
A Profile is a system-provided security template, such as Magento Security Best Practices, an OWASP ASVS level, or PCI DSS supporting requirements. These are inputs to one operating model, not separate assessment workflows.
A Baseline is the Company-configured selection of Rules and verification expectations created from a Profile. Required Baselines are assigned manually to Applications. Baseline version history and automatic migration after changes are outside the MVP.
Rules and verification methods
- Requirement
- Source guidance that may inform a Profile; it is not interchangeable with a Magebean Rule.
- Rule
- One testable security requirement in a system Profile or Company Baseline.
- Automated check
- CLI-observable verification used for an automated Assessment Item; it is not the Rule itself.
- Human-required verification
- Testing, review, records, or judgment needed when reliable automation is not sufficient.
MVP Rules use automated or human-required verification. A Rule, its Assessment Item snapshot, a verification result, and a Finding are distinct records.
Instances, Assessments, Items, and Evidence
An Instance is one production, staging, development, or other deployable Application environment. An Assessment is an independent audit and living operational object applied to an Instance.
At creation, the Assessment snapshots the selected Baseline configuration into Assessment Items. Later Baseline changes do not alter existing Assessments, and a new Assessment does not copy verification results, Evidence, Findings, Tickets, Risk Acceptances, or Deferrals from another Assessment.
Evidence is supporting material submitted for review. User-submitted Evidence requires independent approval, and approved remediation Evidence alone does not prove that the Rule now passes.
Findings, remediation, and risk decisions
A Finding is a failed security condition requiring treatment. Completing a Remediation Ticket submits a fix for independent verification; it does not resolve the Finding.
Risk Acceptance requires an independently approved Risk Request and a mandatory review date. Deferral is a temporary postponement with a future date. False Positive and Not Applicable are separate, independently reviewed decisions. None turns a failed condition into a technical pass.
Monitoring and immutable Reports
Monitoring is the continuing state of a completed initial Assessment. The Assessment remains a living object: later scans, stale results, expired verification, overdue reviews, and recurring failures can create new work and Findings.
A Report is an immutable export snapshot of that Assessment at a specific time. Exporting a Report does not freeze or replace the live Assessment.