What does this framework offer over established open source security frameworks, like the OWASP SAMM? Why not contribute your efforts back to those projects instead of proliferating an additional standard?
I always worry when I see a project like this debut with very little meat on the bones, but a HUGE fleshed out "Code of Conduct" for contributors. What's driving this?