diff --git a/canon/standards/tenancy-posture_v0.1.md b/canon/standards/tenancy-posture_v0.1.md index 8adf77e..bfae362 100644 --- a/canon/standards/tenancy-posture_v0.1.md +++ b/canon/standards/tenancy-posture_v0.1.md @@ -785,10 +785,19 @@ minimum-level vocabulary alongside isolation. right to decline it as fleet-scope work; the answer was a home of its own rather than a volunteer. - Independence is the design point, and it bears on this document: a facility - verifying conformance to this framework is deliberately **not** owned by - NetKingdom, which owns the framework. Self-grading one level up is still - self-grading. + **Owned by NetKingdom** — corrected 2026-08-17; an earlier revision of this + section proposed otherwise on independence grounds and was overruled. + Offensive security is security work and belongs with the repo that owns + security. The facility is framed offensively rather than as a conformance + checker: it is pointed at infrastructure we choose, our own estate among + them, and conformance testing is one use of a general capability. + + The residual tension is recorded rather than resolved: NetKingdom owns this + framework *and* the facility that tests conformance to it, so those findings + are NetKingdom assessing NetKingdom. The mitigation is that findings leave + for `risk-nexus`, under `the-custodian`, rather than being closed in place. + Proportionate, not perfect. Revisit if conformance findings start getting + quietly closed. Two consequences land back here. **Cadence is now a security parameter, not a schedule** — for any control whose guarantee is detection rather than