K05 assurance architecture

Control Mapping Register

Direct answer

K05 maps controls to external frameworks only where a bounded relationship is documented. Every mapping states its relationship and applicability limits; none is a universal compliance determination.

Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.
No compliance shortcut. These records identify a documented relationship. They do not determine whether a framework applies to a named facility, whether a control fully implements a requirement, whether the control operates effectively, or whether a competent authority accepts the evidence.

DoD Directive 3000.09

Applicability-qualified relationships to DoD Directive 3000.09
ControlRelationshipReferenceApplicability boundary
AUT-01 — Bounded autonomous action tieringAPPLIES ONLY IF CAPABILITY IS A COVERED WEAPON SYSTEMWeapon-system applicability, human judgment, V&V/T&E, robustness, transparency, and abort behaviorThe directive expressly excludes autonomous cyberspace capabilities, unarmed platforms, and non-weapon autonomous systems.
PHY-01 — Multi-sensor disagreement managementAPPLIES ONLY IF CAPABILITY IS A COVERED WEAPON SYSTEMWeapon-system applicability, human judgment, V&V/T&E, robustness, transparency, and abort behaviorThe directive expressly excludes autonomous cyberspace capabilities, unarmed platforms, and non-weapon autonomous systems.
PHY-02 — Non-destructive delay and access denialAPPLIES ONLY IF CAPABILITY IS A COVERED WEAPON SYSTEMWeapon-system applicability, human judgment, V&V/T&E, robustness, transparency, and abort behaviorThe directive expressly excludes autonomous cyberspace capabilities, unarmed platforms, and non-weapon autonomous systems.
PHY-03 — Counter-UAS authority separationAPPLIES ONLY IF CAPABILITY IS A COVERED WEAPON SYSTEMWeapon-system applicability, human judgment, V&V/T&E, robustness, transparency, and abort behaviorThe directive expressly excludes autonomous cyberspace capabilities, unarmed platforms, and non-weapon autonomous systems.
EVD-01 — Tamper-evident decision receiptsAPPLIES ONLY IF CAPABILITY IS A COVERED WEAPON SYSTEMWeapon-system applicability, human judgment, V&V/T&E, robustness, transparency, and abort behaviorThe directive expressly excludes autonomous cyberspace capabilities, unarmed platforms, and non-weapon autonomous systems.

INL Consequence-driven Cyber-informed Engineering

Applicability-qualified relationships to INL Consequence-driven Cyber-informed Engineering
ControlRelationshipReferenceApplicability boundary
GOV-01 — Authority and mission registerINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
GOV-02 — Site-tailoring and applicability recordINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
GOV-03 — Hazard and assurance-defeater registerINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
ARC-01 — Critical-function decompositionINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
ARC-02 — Deterministic safety separationINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
ARC-03 — Trust-zone microsegmentationINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
ID-01 — Non-human workload identityINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
ID-02 — Privileged session controlINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
SUP-01 — SBOM and component provenanceINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
SUP-02 — Signed update and rollbackINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
MGT-01 — BMC isolation and attestationINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
MGT-02 — Hardware-rooted attestationINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
OT-01 — Passive OT asset and dependency discoveryINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
OT-02 — Physics-informed detectionINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
OT-03 — Independent safe-state pathINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
PWR-01 — Load-rejection and islanding assuranceINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
CLG-01 — Cooling independent protectionINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
TIM-01 — Assured time and holdoverINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
AUT-01 — Bounded autonomous action tieringINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
AUT-02 — Causal response guardINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
AUT-03 — Multi-agent trust boundariesINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
AUT-04 — Model and data provenance and driftINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
PHY-01 — Multi-sensor disagreement managementINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
PHY-02 — Non-destructive delay and access denialINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
PHY-03 — Counter-UAS authority separationINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
EM-01 — Electromagnetic resilienceINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
REC-01 — Clean-room restorationINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
REC-02 — Critical-function recovery objectivesINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
EVD-01 — Tamper-evident decision receiptsINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
EVD-02 — Independent verification and replayINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
EVD-03 — Readiness downgrade on evidence failureINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.
OPS-01 — Incident command and deconflictionINFORMSConsequence prioritization and critical-function assuranceUseful for high-consequence pathway analysis; not a regulatory certification.

NERC CIP

Applicability-qualified relationships to NERC CIP
ControlRelationshipReferenceApplicability boundary
GOV-01 — Authority and mission registerMAY IMPLEMENT OR SUPPORTCurrent applicable CIP standards and implementation plansOnly after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis.
GOV-02 — Site-tailoring and applicability recordMAY IMPLEMENT OR SUPPORTCurrent applicable CIP standards and implementation plansOnly after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis.
GOV-03 — Hazard and assurance-defeater registerMAY IMPLEMENT OR SUPPORTCurrent applicable CIP standards and implementation plansOnly after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis.
PWR-01 — Load-rejection and islanding assuranceMAY IMPLEMENT OR SUPPORTCurrent applicable CIP standards and implementation plansOnly after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis.
CLG-01 — Cooling independent protectionMAY IMPLEMENT OR SUPPORTCurrent applicable CIP standards and implementation plansOnly after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis.
EVD-01 — Tamper-evident decision receiptsMAY IMPLEMENT OR SUPPORTCurrent applicable CIP standards and implementation plansOnly after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis.
EVD-02 — Independent verification and replayMAY IMPLEMENT OR SUPPORTCurrent applicable CIP standards and implementation plansOnly after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis.
EVD-03 — Readiness downgrade on evidence failureMAY IMPLEMENT OR SUPPORTCurrent applicable CIP standards and implementation plansOnly after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis.
OPS-01 — Incident command and deconflictionMAY IMPLEMENT OR SUPPORTCurrent applicable CIP standards and implementation plansOnly after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis.

NIST SP 800-207

Applicability-qualified relationships to NIST SP 800-207
ControlRelationshipReferenceApplicability boundary
GOV-01 — Authority and mission registerINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
GOV-02 — Site-tailoring and applicability recordINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
GOV-03 — Hazard and assurance-defeater registerINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
ARC-01 — Critical-function decompositionINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
ARC-02 — Deterministic safety separationINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
ARC-03 — Trust-zone microsegmentationINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
ID-01 — Non-human workload identityINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
ID-02 — Privileged session controlINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
SUP-01 — SBOM and component provenanceINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
SUP-02 — Signed update and rollbackINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
MGT-01 — BMC isolation and attestationINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
MGT-02 — Hardware-rooted attestationINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
OT-01 — Passive OT asset and dependency discoveryINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
OT-02 — Physics-informed detectionINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
OT-03 — Independent safe-state pathINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
PWR-01 — Load-rejection and islanding assuranceINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
CLG-01 — Cooling independent protectionINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
TIM-01 — Assured time and holdoverINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
AUT-01 — Bounded autonomous action tieringINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
AUT-02 — Causal response guardINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
AUT-03 — Multi-agent trust boundariesINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
AUT-04 — Model and data provenance and driftINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
PHY-01 — Multi-sensor disagreement managementINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
PHY-02 — Non-destructive delay and access denialINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
PHY-03 — Counter-UAS authority separationINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
EM-01 — Electromagnetic resilienceINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
REC-01 — Clean-room restorationINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
REC-02 — Critical-function recovery objectivesINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
EVD-01 — Tamper-evident decision receiptsINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
EVD-02 — Independent verification and replayINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
EVD-03 — Readiness downgrade on evidence failureINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.
OPS-01 — Incident command and deconflictionINFORMSZero Trust Architecture principlesApplies to identity- and resource-centric access design; does not replace OT safety analysis.

NIST SP 800-82 Rev. 3

Applicability-qualified relationships to NIST SP 800-82 Rev. 3
ControlRelationshipReferenceApplicability boundary
GOV-01 — Authority and mission registerINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
GOV-02 — Site-tailoring and applicability recordINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
GOV-03 — Hazard and assurance-defeater registerINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
ARC-01 — Critical-function decompositionINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
ARC-02 — Deterministic safety separationINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
ARC-03 — Trust-zone microsegmentationINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
ID-01 — Non-human workload identityINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
ID-02 — Privileged session controlINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
SUP-01 — SBOM and component provenanceINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
SUP-02 — Signed update and rollbackINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
MGT-01 — BMC isolation and attestationINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
MGT-02 — Hardware-rooted attestationINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
OT-01 — Passive OT asset and dependency discoveryINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
OT-02 — Physics-informed detectionINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
OT-03 — Independent safe-state pathINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
PWR-01 — Load-rejection and islanding assuranceINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
CLG-01 — Cooling independent protectionINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
TIM-01 — Assured time and holdoverINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
AUT-01 — Bounded autonomous action tieringINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
AUT-02 — Causal response guardINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
AUT-03 — Multi-agent trust boundariesINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
AUT-04 — Model and data provenance and driftINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
PHY-01 — Multi-sensor disagreement managementINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
PHY-02 — Non-destructive delay and access denialINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
PHY-03 — Counter-UAS authority separationINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
EM-01 — Electromagnetic resilienceINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
REC-01 — Clean-room restorationINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
REC-02 — Critical-function recovery objectivesINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
EVD-01 — Tamper-evident decision receiptsINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
EVD-02 — Independent verification and replayINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
EVD-03 — Readiness downgrade on evidence failureINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
OPS-01 — Incident command and deconflictionINFORMSOT security program, architecture, risk, and control guidanceApplies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.

NRC 10 CFR Part 73

Applicability-qualified relationships to NRC 10 CFR Part 73
ControlRelationshipReferenceApplicability boundary
GOV-01 — Authority and mission registerMAY IMPLEMENT OR SUPPORT73.54/73.55 or 73.100/73.110/73.120 as selected and applicableOnly for an NRC-regulated facility within the selected licensing and security framework; license basis controls.
GOV-02 — Site-tailoring and applicability recordMAY IMPLEMENT OR SUPPORT73.54/73.55 or 73.100/73.110/73.120 as selected and applicableOnly for an NRC-regulated facility within the selected licensing and security framework; license basis controls.
GOV-03 — Hazard and assurance-defeater registerMAY IMPLEMENT OR SUPPORT73.54/73.55 or 73.100/73.110/73.120 as selected and applicableOnly for an NRC-regulated facility within the selected licensing and security framework; license basis controls.
ARC-01 — Critical-function decompositionMAY IMPLEMENT OR SUPPORT73.54/73.55 or 73.100/73.110/73.120 as selected and applicableOnly for an NRC-regulated facility within the selected licensing and security framework; license basis controls.
ARC-02 — Deterministic safety separationMAY IMPLEMENT OR SUPPORT73.54/73.55 or 73.100/73.110/73.120 as selected and applicableOnly for an NRC-regulated facility within the selected licensing and security framework; license basis controls.
ARC-03 — Trust-zone microsegmentationMAY IMPLEMENT OR SUPPORT73.54/73.55 or 73.100/73.110/73.120 as selected and applicableOnly for an NRC-regulated facility within the selected licensing and security framework; license basis controls.
OT-01 — Passive OT asset and dependency discoveryMAY IMPLEMENT OR SUPPORT73.54/73.55 or 73.100/73.110/73.120 as selected and applicableOnly for an NRC-regulated facility within the selected licensing and security framework; license basis controls.
OT-02 — Physics-informed detectionMAY IMPLEMENT OR SUPPORT73.54/73.55 or 73.100/73.110/73.120 as selected and applicableOnly for an NRC-regulated facility within the selected licensing and security framework; license basis controls.
OT-03 — Independent safe-state pathMAY IMPLEMENT OR SUPPORT73.54/73.55 or 73.100/73.110/73.120 as selected and applicableOnly for an NRC-regulated facility within the selected licensing and security framework; license basis controls.
PWR-01 — Load-rejection and islanding assuranceMAY IMPLEMENT OR SUPPORT73.54/73.55 or 73.100/73.110/73.120 as selected and applicableOnly for an NRC-regulated facility within the selected licensing and security framework; license basis controls.
CLG-01 — Cooling independent protectionMAY IMPLEMENT OR SUPPORT73.54/73.55 or 73.100/73.110/73.120 as selected and applicableOnly for an NRC-regulated facility within the selected licensing and security framework; license basis controls.
PHY-01 — Multi-sensor disagreement managementMAY IMPLEMENT OR SUPPORT73.54/73.55 or 73.100/73.110/73.120 as selected and applicableOnly for an NRC-regulated facility within the selected licensing and security framework; license basis controls.
PHY-02 — Non-destructive delay and access denialMAY IMPLEMENT OR SUPPORT73.54/73.55 or 73.100/73.110/73.120 as selected and applicableOnly for an NRC-regulated facility within the selected licensing and security framework; license basis controls.
PHY-03 — Counter-UAS authority separationMAY IMPLEMENT OR SUPPORT73.54/73.55 or 73.100/73.110/73.120 as selected and applicableOnly for an NRC-regulated facility within the selected licensing and security framework; license basis controls.
EM-01 — Electromagnetic resilienceMAY IMPLEMENT OR SUPPORT73.54/73.55 or 73.100/73.110/73.120 as selected and applicableOnly for an NRC-regulated facility within the selected licensing and security framework; license basis controls.
OPS-01 — Incident command and deconflictionMAY IMPLEMENT OR SUPPORT73.54/73.55 or 73.100/73.110/73.120 as selected and applicableOnly for an NRC-regulated facility within the selected licensing and security framework; license basis controls.

Machine-readable mapping summary

Framework counts and boundary · Complete control records