whitehat-security takes the adversarial evidence artifacts - the framework's highest-severity gap, unowned since it was drafted. audit-core and tenant-engine were right to decline it as fleet-scope work; the answer was a home of its own rather than a volunteer. Recorded here with the part that bears on this document: the facility is deliberately not owned by NetKingdom, which owns this framework. Verifying conformance to a standard while reporting to the standard's owner is self-grading one level up. Two consequences land back on the framework. Cadence becomes a security parameter rather than a schedule, since for a detection-based control the interval between runs is the exposure window. And a passing suite is proof that the attacks attempted did not work, not proof of isolation - recording a green run as "E2 verified" would be exactly the overclaim section 6 prohibits. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| credential-management_v0.2.md | ||
| iam-profile_v0.2.md | ||
| iam-profile_v0.3.md | ||
| playbook-capability-contract_v0.1.md | ||
| tenancy-posture_v0.1.md | ||
| tenant-engine-boundary-contract_v0.1.md | ||
| user-engine-boundary-contract_v0.1.md | ||