OWASP Subtractive Security Project Introduces “Path Erasure Rate” to Eliminate Attack Paths
What Happened — OWASP released the Subtractive Security Top 10 and an accompanying engineering standard called Path Erasure Rate (PER). The framework lists attack‑path categories to be removed across Windows, Linux, macOS, Active Directory, AWS, Microsoft 365, network and IoT environments, shifting focus from “detect‑and‑respond” to “erase‑and‑constrain.”
Why It Matters for Compliance & Audit Readiness
- SOC 2 control‑mapping expects organizations to remove unnecessary privileges and services (CC6.1, CC6.2) and to retain evidence that those controls are in place. PER gives a measurable denominator for that evidence.
- Continuous‑compliance programs can use the PER score as audit‑ready proof that attack‑path reduction is being actively managed, reducing alert fatigue and strengthening the “risk mitigation” narrative in audits.
- The approach aligns with the Control Mapping capability, which automates evidence collection for removed or constrained attack paths.
Who Is Affected — Enterprises of all sizes that rely on endpoint, cloud, and identity infrastructure; particularly those pursuing SOC 2 Type II certification in technology, SaaS, and professional services sectors.
Recommended Actions
- Inventory current attack paths per the Subtractive Security Top 10 lists.
- Prioritize erasure of high‑risk paths (e.g., unused service accounts, default admin credentials).
- Document erasure actions and capture PER metrics as part of your SOC 2 evidence repository.
- Adjust monitoring rules to focus only on non‑erasable paths, thereby improving signal‑to‑noise for EDR/SIEM alerts.
Source: Help Net Security – OWASP Subtractive Security
Technical Notes — The methodology does not rely on a specific vulnerability; it is a control‑oriented framework that can be applied to Windows, Linux, macOS, Active Directory, AWS, Microsoft 365, network devices and IoT. No CVE identifiers are associated.