Skip to content

P1: Define standards and enterprise-assurance control mappings without compliance overclaiming #14

Description

@BunsDev

Outcome

Map the governance-plane controls and evidence to useful external frameworks while keeping implementation, effectiveness, certification, and legal conclusions distinct.

Scope

Evaluate and document control mappings, gaps, and evidence expectations for:

  • NIST CSF 2.0 governance, identify, protect, detect, respond, and recover outcomes;
  • NIST Secure Software Development Framework;
  • NIST AI RMF only where AI-system governance is actually implicated;
  • ISO/IEC 27001/27002 and, where deployment scope warrants, 27017/27018 control families;
  • SOC 2 trust-services criteria as future assurance inputs, not a self-attested certification;
  • CIS Controls and relevant GitHub/CI hardening guidance;
  • OpenSSF Scorecard and Best Practices;
  • SLSA provenance levels and supply-chain threat model;
  • SPDX and CycloneDX SBOM formats;
  • Sigstore or other signing/verifiability mechanisms;
  • privacy minimization, retention, access, correction, deletion, and audit considerations where governance data contains personal information;
  • open-source license, notices, DCO/CLA tradeoffs, vulnerability disclosure, contributor provenance, and patent policy.

Required distinctions

For every mapped item report separately:

  • policy specified;
  • mechanism implemented;
  • GitHub/service setting administratively applied;
  • positive and negative verification performed;
  • recurring control effectiveness observed;
  • missing evidence or applicability limits;
  • certification/attestation status, which must remain not claimed unless independently established.

Acceptance criteria

  • Mapping is control-to-evidence, not framework-name decoration.
  • Each mapping names the enforcing owner and authoritative evidence source.
  • Gaps and non-applicable controls are explicit.
  • No SOC 2, ISO, GDPR, CCPA, NIST, OpenSSF, SLSA, or other compliance/certification claim is made from repository policy alone.
  • Public documentation contains no private inventory, personal data, incident detail, credentials, or confidential commercial/legal material.
  • Retention and privacy decisions identify a lawful/business purpose and data-minimization path where applicable.
  • Product/protocol security and continuity conformance remain owned by their canonical repositories.
  • A future enterprise evidence export is specified as a derived, provenance-bound view rather than a second authority.

This issue produces an assurance map and gap analysis. Legal advice, certification, and auditor attestation remain outside its authority.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions