Skip to content

D-111: the native control catalog is authored first, framework authority second - #11

Merged
itcmsgr merged 1 commit into
mainfrom
arch/native-control-catalog
Sep 19, 2026
Merged

itcmsgr merged 1 commit into
mainfrom
arch/native-control-catalog

Conversation

@itcmsgr

@itcmsgr itcmsgr commented Sep 19, 2026

Copy link
Copy Markdown
Owner

Freezes the layering LINUX FACT -> NATIVE CONTROL -> EVIDENCE -> OPTIONAL MAPPING as an architecture invariant before W1-D is designed, with the ISE-* namespace fixed and control/evidence/mapping ownership separated.

The effect is that the technical engine can be completed without waiting for any provider: a later agreement adds a mapping pack, a refusal costs nothing already built.

make check-native-catalog enforces it — the registry and the catalog document must agree on the families, no criterion may be derived from a framework, and no production module may be named after a provider. Three injections prove it refuses.

…ity second

Frozen as an architecture invariant before W1-D is designed.

  LINUX FACT -> ISEDRAF NATIVE CONTROL -> RESULT/EVIDENCE -> OPTIONAL MAPPING

An external framework is never the source of a control. ISEDRAF authors its own
criteria in the frozen ISE-* namespace from Linux system behaviour; a mapping is a
downstream overlay added only where licensing permits, and removing every mapping
leaves the catalog unchanged.

Three ownerships kept apart: control ownership is ISEDRAF's, evidence ownership is
the customer's and the observed host's, and only framework mapping rights are
provider-specific.

The authorship claim is deliberately bounded — independently authored from Linux
behaviour and sources whose reuse rights permit it, with no claim that no patent,
contract, trademark or copyright could ever exist anywhere. An absolute claim is
cost-free to write and expensive to defend.

An earlier draft used ISE-IDENT-* for accounts. Host IDENTITY and user ACCOUNTS are
different domains; accounts are ISE-ACCOUNT-*, and ISE-IDENT stays reserved so the
earlier draft resolves to an explanation rather than silence.

make check-native-catalog requires the registry and the catalog document to AGREE,
checks the namespace, refuses a criterion derived from a framework, and refuses a
production module named after a provider. There is no cis_collector.py, and the
gate is what makes that a fact rather than an intention.

Nothing is implemented. The catalog is empty and W1-D authors it.

Gates 18. Injections 74, all firing.

Implements: D-78, D-79, D-82, D-84, D-111, GOV-001, GOV-002
Assisted-by: Claude (invariant drafting, gate design, defect injection)
@itcmsgr
itcmsgr merged commit 4d8e454 into main Sep 19, 2026
10 checks passed
@itcmsgr
itcmsgr deleted the arch/native-control-catalog branch September 19, 2026 10:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant