Introduce shared evidence model and governance imports
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a070b5-4994-7271-bd8b-7c3dbcedec4b
This commit is contained in:
tegwick 2026-09-05 21:16:29 +02:00
parent 305a4d6bd8
commit a2b254786e
54 changed files with 854 additions and 177 deletions

View file

@ -245,7 +245,7 @@ And when does access become exceptional or irregular?
## 0.8 Relationship to Governance and Security
Governance owns policies, exceptions, approvals, reviews, controls, risk, and evidence.
Governance owns policies, exceptions, approvals, reviews, controls, risk. Evidence and Evidence Source are imported from ITC-EVID.
Security owns threats, vulnerabilities, exposure, security findings, attack paths, incidents, and mitigations.

View file

@ -135,7 +135,7 @@ Bad:
## 3.3 Boundary with Governance
Governance owns policies, controls, risks, obligations, decisions, approvals, exceptions, and evidence.
Governance owns policies, controls, risks, obligations, decisions, approvals, exceptions. Evidence and Evidence Source are imported from ITC-EVID.
Tags may identify governance-relevant work or artifacts, but should not replace policy/control/evidence records.