Outcome
Map the governance-plane controls and evidence to useful external frameworks while keeping implementation, effectiveness, certification, and legal conclusions distinct.
Scope
Evaluate and document control mappings, gaps, and evidence expectations for:
NIST CSF 2.0 governance, identify, protect, detect, respond, and recover outcomes;
NIST Secure Software Development Framework;
NIST AI RMF only where AI-system governance is actually implicated;
ISO/IEC 27001/27002 and, where deployment scope warrants, 27017/27018 control families;
SOC 2 trust-services criteria as future assurance inputs, not a self-attested certification;
CIS Controls and relevant GitHub/CI hardening guidance;
OpenSSF Scorecard and Best Practices;
SLSA provenance levels and supply-chain threat model;
SPDX and CycloneDX SBOM formats;
Sigstore or other signing/verifiability mechanisms;
privacy minimization, retention, access, correction, deletion, and audit considerations where governance data contains personal information;
open-source license, notices, DCO/CLA tradeoffs, vulnerability disclosure, contributor provenance, and patent policy.
Required distinctions
For every mapped item report separately:
policy specified;
mechanism implemented;
GitHub/service setting administratively applied;
positive and negative verification performed;
recurring control effectiveness observed;
missing evidence or applicability limits;
certification/attestation status, which must remain not claimed unless independently established.
Acceptance criteria
Mapping is control-to-evidence, not framework-name decoration.
Each mapping names the enforcing owner and authoritative evidence source.
Gaps and non-applicable controls are explicit.
No SOC 2, ISO, GDPR, CCPA, NIST, OpenSSF, SLSA, or other compliance/certification claim is made from repository policy alone.
Public documentation contains no private inventory, personal data, incident detail, credentials, or confidential commercial/legal material.
Retention and privacy decisions identify a lawful/business purpose and data-minimization path where applicable.
Product/protocol security and continuity conformance remain owned by their canonical repositories.
A future enterprise evidence export is specified as a derived, provenance-bound view rather than a second authority.
This issue produces an assurance map and gap analysis. Legal advice, certification, and auditor attestation remain outside its authority.
Outcome
Map the governance-plane controls and evidence to useful external frameworks while keeping implementation, effectiveness, certification, and legal conclusions distinct.
Scope
Evaluate and document control mappings, gaps, and evidence expectations for:
Required distinctions
For every mapped item report separately:
not claimedunless independently established.Acceptance criteria
This issue produces an assurance map and gap analysis. Legal advice, certification, and auditor attestation remain outside its authority.