D-111: the native control catalog is authored first, framework authority second - #11
Merged
Merged
Conversation
…ity second Frozen as an architecture invariant before W1-D is designed. LINUX FACT -> ISEDRAF NATIVE CONTROL -> RESULT/EVIDENCE -> OPTIONAL MAPPING An external framework is never the source of a control. ISEDRAF authors its own criteria in the frozen ISE-* namespace from Linux system behaviour; a mapping is a downstream overlay added only where licensing permits, and removing every mapping leaves the catalog unchanged. Three ownerships kept apart: control ownership is ISEDRAF's, evidence ownership is the customer's and the observed host's, and only framework mapping rights are provider-specific. The authorship claim is deliberately bounded — independently authored from Linux behaviour and sources whose reuse rights permit it, with no claim that no patent, contract, trademark or copyright could ever exist anywhere. An absolute claim is cost-free to write and expensive to defend. An earlier draft used ISE-IDENT-* for accounts. Host IDENTITY and user ACCOUNTS are different domains; accounts are ISE-ACCOUNT-*, and ISE-IDENT stays reserved so the earlier draft resolves to an explanation rather than silence. make check-native-catalog requires the registry and the catalog document to AGREE, checks the namespace, refuses a criterion derived from a framework, and refuses a production module named after a provider. There is no cis_collector.py, and the gate is what makes that a fact rather than an intention. Nothing is implemented. The catalog is empty and W1-D authors it. Gates 18. Injections 74, all firing. Implements: D-78, D-79, D-82, D-84, D-111, GOV-001, GOV-002 Assisted-by: Claude (invariant drafting, gate design, defect injection)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Freezes the layering
LINUX FACT -> NATIVE CONTROL -> EVIDENCE -> OPTIONAL MAPPINGas an architecture invariant before W1-D is designed, with theISE-*namespace fixed and control/evidence/mapping ownership separated.The effect is that the technical engine can be completed without waiting for any provider: a later agreement adds a mapping pack, a refusal costs nothing already built.
make check-native-catalogenforces it — the registry and the catalog document must agree on the families, no criterion may be derived from a framework, and no production module may be named after a provider. Three injections prove it refuses.