Family Guides

Family Guides

Family guides explain each AWOSS-* control family in plain language for readers who need more context than the formal standard draft provides.

Non-normative guidance

Family guides do not create new requirements. They explain purpose, level intent, control detail, evidence examples, and external mapping context for the current working draft.

FamilyGuideFormal standard
AWOSS-SCPAWOSS-SCP: Scope, Inventory, And OwnershipCandidate requirements
AWOSS-DELAWOSS-DEL: Delegation, Authority, And IdentityCandidate requirements
AWOSS-WSBAWOSS-WSB: Workspace And Execution BoundariesCandidate requirements
AWOSS-RUNAWOSS-RUN: Runtime Policy, Approvals, And Action ControlCandidate requirements
AWOSS-SRCAWOSS-SRC: Skill, Tool, And Connector Source TrustCandidate requirements
AWOSS-CTXAWOSS-CTX: Context, Memory, And Instruction Boundary ControlCandidate requirements
AWOSS-SECAWOSS-SEC: Secrets, Credentials, And Sensitive Data HandlingCandidate requirements
AWOSS-LOGAWOSS-LOG: Logs, Receipts, And TraceabilityCandidate requirements
AWOSS-VALAWOSS-VAL: Validation, Testing, And ReviewCandidate requirements
AWOSS-GOVAWOSS-GOV: Governance, Exceptions, And Change ManagementCandidate requirements

How to use these guides

  • Start with the guide when you need purpose, level intent, control rationale, and evidence examples.
  • Use the formal standard draft when you need candidate requirement text, levels, and normative wording.
  • Treat levels as cumulative: Level 2 builds on Level 1, and Level 3 builds on both.
  • Use external mapping notes as context, not as a replacement for the formal standard draft.