Introduce shared evidence model and governance imports
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a070b5-4994-7271-bd8b-7c3dbcedec4b
This commit is contained in:
parent
305a4d6bd8
commit
a2b254786e
54 changed files with 854 additions and 177 deletions
|
|
@ -245,7 +245,7 @@ And when does access become exceptional or irregular?
|
|||
|
||||
## 0.8 Relationship to Governance and Security
|
||||
|
||||
Governance owns policies, exceptions, approvals, reviews, controls, risk, and evidence.
|
||||
Governance owns policies, exceptions, approvals, reviews, controls, risk. Evidence and Evidence Source are imported from ITC-EVID.
|
||||
|
||||
Security owns threats, vulnerabilities, exposure, security findings, attack paths, incidents, and mitigations.
|
||||
|
||||
|
|
|
|||
|
|
@ -135,7 +135,7 @@ Bad:
|
|||
|
||||
## 3.3 Boundary with Governance
|
||||
|
||||
Governance owns policies, controls, risks, obligations, decisions, approvals, exceptions, and evidence.
|
||||
Governance owns policies, controls, risks, obligations, decisions, approvals, exceptions. Evidence and Evidence Source are imported from ITC-EVID.
|
||||
|
||||
Tags may identify governance-relevant work or artifacts, but should not replace policy/control/evidence records.
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue