Correct question 3: whitehat is NetKingdom's
An earlier revision of this section asserted the adversarial facility was deliberately not NetKingdom's, on independence grounds. Overruled, and the counter-argument is better: offensive security is security work. The facility is also framed more broadly than this document assumed - it is pointed at infrastructure we choose, our own estate among them, and testing conformance to this framework is one use of a general capability rather than its purpose. The tension I raised is left in the text rather than deleted, because it is real: NetKingdom now owns both this framework and the facility that tests conformance to it. The mitigation is that findings leave for risk-nexus under separate ownership instead of being closed in place, and the trigger to revisit is conformance findings starting to close quietly. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
e25545d9d0
commit
cb32f6d68c
1 changed files with 13 additions and 4 deletions
|
|
@ -785,10 +785,19 @@ minimum-level vocabulary alongside isolation.
|
|||
right to decline it as fleet-scope work; the answer was a home of its own
|
||||
rather than a volunteer.
|
||||
|
||||
Independence is the design point, and it bears on this document: a facility
|
||||
verifying conformance to this framework is deliberately **not** owned by
|
||||
NetKingdom, which owns the framework. Self-grading one level up is still
|
||||
self-grading.
|
||||
**Owned by NetKingdom** — corrected 2026-08-17; an earlier revision of this
|
||||
section proposed otherwise on independence grounds and was overruled.
|
||||
Offensive security is security work and belongs with the repo that owns
|
||||
security. The facility is framed offensively rather than as a conformance
|
||||
checker: it is pointed at infrastructure we choose, our own estate among
|
||||
them, and conformance testing is one use of a general capability.
|
||||
|
||||
The residual tension is recorded rather than resolved: NetKingdom owns this
|
||||
framework *and* the facility that tests conformance to it, so those findings
|
||||
are NetKingdom assessing NetKingdom. The mitigation is that findings leave
|
||||
for `risk-nexus`, under `the-custodian`, rather than being closed in place.
|
||||
Proportionate, not perfect. Revisit if conformance findings start getting
|
||||
quietly closed.
|
||||
|
||||
Two consequences land back here. **Cadence is now a security parameter, not
|
||||
a schedule** — for any control whose guarantee is detection rather than
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue