Standard

Candidate Control Families

Working draft

This page renders the current awoss working draft. It is not a released standard, certification program, compliance framework, legal analysis, endorsement, or public conformance claim.

This section defines first-pass candidate control families for the working draft. The requirements are intentionally written in normative style so they can be reviewed for clarity and testability, but they remain candidate requirements until a released awoss version exists.

Each family includes:

  • objective
  • primary layer and typical owner
  • applicability notes
  • candidate Level 1, Level 2, and Level 3 requirements
  • minimum evidence examples
  • mapping notes
  • claim limits

The current candidate requirements have been revised against the completed source-first and family-first crosswalk baseline. They remain working-draft candidate requirements until a released awoss version exists, and mapping notes in this section remain informative rather than conformance, legal, or certification claims.

IDFamilyPrimary layerTypical owner
AWOSS-SCPScope, inventory, and ownershipWorkspace and endpointBusiness or workflow owner
AWOSS-DELDelegation, authority, and identityRuntime platformIdentity/IAM owner and workflow approver
AWOSS-WSBWorkspace and execution boundariesWorkspace and endpointEndpoint/workspace operations or platform engineering
AWOSS-RUNRuntime policy, approvals, and action controlRuntime platformAgent runtime or platform operations
AWOSS-SRCSkill, tool, and connector source trustSkill or skill-set sourceSoftware supply-chain or tool-source owner
AWOSS-CTXContext, memory, and instruction boundary controlRuntime platformRuntime configuration and data/context governance
AWOSS-SECSecrets, credentials, and sensitive data handlingWorkspace and endpointSecurity, secrets, or data-protection owner
AWOSS-LOGLogs, receipts, and traceabilityEvidence and auditObservability, audit, or evidence owner
AWOSS-VALValidation, testing, and reviewEvidence and auditSecurity validation, assurance, or independent review
AWOSS-GOVGovernance, exceptions, and change managementOrganization and governanceGovernance/risk owner and accountable business sponsor