HomeIntelligenceBrief
BREACH BRIEF⚪ Informational Advisory

OWASP Subtractive Security Project Introduces “Path Erasure Rate” to Eliminate Attack Paths

OWASP released the Subtractive Security Top 10 and the Path Erasure Rate standard, urging organizations to remove unnecessary attack paths across OS, cloud and IoT layers. The guidance provides a measurable way to demonstrate control removal, a key SOC 2 audit requirement.

LiveThreat™ Intelligence · 📅 August 04, 2026· 📰 helpnetsecurity.com
Severity
Informational
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
helpnetsecurity.com

OWASP Subtractive Security Project Introduces “Path Erasure Rate” to Eliminate Attack Paths

What Happened — OWASP released the Subtractive Security Top 10 and an accompanying engineering standard called Path Erasure Rate (PER). The framework lists attack‑path categories to be removed across Windows, Linux, macOS, Active Directory, AWS, Microsoft 365, network and IoT environments, shifting focus from “detect‑and‑respond” to “erase‑and‑constrain.”

Why It Matters for Compliance & Audit Readiness

  • SOC 2 control‑mapping expects organizations to remove unnecessary privileges and services (CC6.1, CC6.2) and to retain evidence that those controls are in place. PER gives a measurable denominator for that evidence.
  • Continuous‑compliance programs can use the PER score as audit‑ready proof that attack‑path reduction is being actively managed, reducing alert fatigue and strengthening the “risk mitigation” narrative in audits.
  • The approach aligns with the Control Mapping capability, which automates evidence collection for removed or constrained attack paths.

Who Is Affected — Enterprises of all sizes that rely on endpoint, cloud, and identity infrastructure; particularly those pursuing SOC 2 Type II certification in technology, SaaS, and professional services sectors.

Recommended Actions

  • Inventory current attack paths per the Subtractive Security Top 10 lists.
  • Prioritize erasure of high‑risk paths (e.g., unused service accounts, default admin credentials).
  • Document erasure actions and capture PER metrics as part of your SOC 2 evidence repository.
  • Adjust monitoring rules to focus only on non‑erasable paths, thereby improving signal‑to‑noise for EDR/SIEM alerts.

Source: Help Net Security – OWASP Subtractive Security

Technical Notes — The methodology does not rely on a specific vulnerability; it is a control‑oriented framework that can be applied to Windows, Linux, macOS, Active Directory, AWS, Microsoft 365, network devices and IoT. No CVE identifiers are associated.

📰 Original Source
https://www.helpnetsecurity.com/2026/08/04/owasp-subtractive-security/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →