Official-source catalog
Sources
Direct answer
K03 source records identify publisher, official location, exact edition or version, publication status, supported propositions, revalidation time, currentness limits, correction state, and supersession links.
Revalidated sources
PROV-O: The PROV Ontology
Vocabulary for representing provenance information.
CURRENT TECHNICAL STANDARDDecentralized Identifiers (DIDs) v1.0
Technical standard relevant to identifier control and verification methods; it does not by itself establish legal identity.
CURRENT TECHNICAL STANDARDVerifiable Credentials Data Model v2.0
Data model for tamper-evident credentials and presentations; credential integrity is distinct from truth and authority.
CURRENT TECHNICAL STANDARDJSON-LD 1.1
Linked-data serialization used for public knowledge records.
CURRENT TECHNICAL STANDARDWeb Content Accessibility Guidelines (WCAG) 2.2
Accessibility requirements used as the public-interface target.
CURRENT TECHNICAL STANDARDArtificial Intelligence Risk Management Framework (AI RMF 1.0)
Risk-management reference for systems described by industry and government as AI. Version 1.0 remains the published framework but is under revision as of the 2026-08-14 research cutoff.
CURRENT TECHNICAL STANDARDNIST SP 800-218 Secure Software Development Framework Version 1.1
Final secure software development practices used for implementation and release controls. Version 1.2 remained an initial public draft at the research cutoff.
CURRENT TECHNICAL STANDARDNIST SP 800-53 Rev. 5, Release 5.2.0 Security and Privacy Controls
Current 2025 minor release of the Rev. 5 control catalog used for assurance, access control, audit and resilience references.
CURRENT TECHNICAL STANDARDRFC 5280: Internet X.509 Public Key Infrastructure Certificate and CRL Profile
Certificate profile useful for understanding key-bound credentials and revocation.
SUPERSEDEDRFC 6962: Certificate Transparency
Experimental Certificate Transparency v1 protocol, now obsolete and superseded by RFC 9162; retained for historical comparison.
CURRENT TECHNICAL STANDARDRFC 3161: Time-Stamp Protocol
Protocol relevant to evidence that a representation existed by a specified time.
CURRENT TECHNICAL STANDARDSupply-chain Levels for Software Artifacts (SLSA) Specification v1.2
Current approved software supply-chain integrity specification at the 2026-08-14 research cutoff, relevant to attributable releases and provenance.
CURRENT TECHNICAL STANDARDin-toto Attestation Framework
Attestation framework for software supply-chain steps and evidence.
CURRENT TECHNICAL STANDARDC2PA Technical Specification v2.4
Current content-provenance specification at the 2026-08-14 research cutoff; provenance assertions remain distinct from factual truth.
OBSERVED DEPLOYMENT OR PRACTICESchema.org DefinedTerm
Public structured-data vocabulary for defined terms; the canonical page identifies the term as part of the development version and the new area.
CURRENT POLICY OR GUIDANCEAI features and your website
Search guidance emphasizing ordinary foundational SEO; no markup guarantees citation or ranking.
CURRENT LAW OR POLICYEuropean Union Artificial Intelligence Act information portal
European regulatory framework for systems legally categorized as AI. It became broadly applicable on 2026-08-02 with specified later dates and exceptions; it is not a legal-personhood regime for Machine Intelligence.
CURRENT LAW OR POLICYOECD AI Principles
Intergovernmental policy principles using the external term AI.
CURRENT TECHNICAL STANDARDRFC 9162: Certificate Transparency Version 2.0
Experimental Certificate Transparency v2 protocol that obsoletes RFC 6962; useful as a design reference for append-only, publicly auditable logs.
RESEARCH FINDINGWCAG Evaluation Methodology (WCAG-EM) 2.0
Informative evaluation methodology for defining scope, exploring a product, selecting representative samples, evaluating them, and reporting findings; it does not add or replace WCAG requirements.
CURRENT TECHNICAL STANDARDAccessibility Conformance Testing (ACT) Rules Format 1.1
W3C Recommendation defining a common format for documenting automated and manual accessibility test rules; a test-rule format does not itself establish whole-site conformance.
CURRENT LAW OR POLICYExecutive Order 14409 — Promoting Advanced Artificial Intelligence Innovation and Security
Official executive order directing public-private work to advance AI innovation and harden government and private-sector systems against external threats.
OBSERVED DEPLOYMENT OR PRACTICEWhite House Launches GOLD EAGLE Initiative for Cybersecurity Vulnerability Coordination
Official announcement of a public-private vulnerability coordination model using frontier AI to identify, prioritize, and support remediation.
CURRENT LAW OR POLICYExpanding Capabilities to Combat Transnational Cyber-Enabled Crime
Official presidential memorandum directing an NCC program for vetted participating companies to conduct defined cyber surveillance and cyber effects operations against foreign CE-TCOs only under Federal Government control, supervision, legal authorities, written package approval, deconfliction, and critical-outcome limits. It is not a general private hack-back license.
OBSERVED DEPLOYMENT OR PRACTICEThe Establishment of Project Manager Cyber Warfare
Official Army announcement confirming the merger of offensive and defensive cyber portfolios into Project Manager Cyber Warfare.
OBSERVED DEPLOYMENT OR PRACTICECyber Warfare: The Best Offense Is a Powerful Defense
Official Army acquisition article describing full-spectrum cyber capability, critical-infrastructure defense, offensive-defensive integration, commercial collaboration, and agile fielding.
CURRENT LAW OR POLICY10 CFR 73.54 — Protection of Digital Computer and Communication Systems and Networks
Nuclear cybersecurity requirements for protected digital systems and networks associated with safety, security, emergency preparedness, and supporting functions.
CURRENT LAW OR POLICY10 CFR 73.55 — Requirements for Physical Protection of Licensed Activities in Nuclear Power Reactors Against Radiological Sabotage
Physical protection requirements for operating nuclear power reactors, including detection, assessment, delay, response, training, and program performance.
CURRENT LAW OR POLICYRisk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors — Final Rule
Final NRC rule creating an optional Part 53 framework and a technology-inclusive, performance-based security framework in 10 CFR Part 73. K05 replaces the earlier proposed-rule status; applicability still depends on the licensing path and facility election.
OBSERVED DEPLOYMENT OR PRACTICEConsequence-driven Cyber-informed Engineering
Official INL description of CCE as a critical-infrastructure methodology that assumes skilled adversaries can penetrate networks and uses a four-phase process to protect critical operations.
CURRENT TECHNICAL STANDARDNIST SP 800-82 Revision 3 — Guide to Operational Technology Security
Official guidance for securing operational technology while addressing performance, reliability, and safety requirements.
CURRENT TECHNICAL STANDARDNIST SP 800-207 — Zero Trust Architecture
Official zero-trust architecture guidance that removes implicit trust based on network location and focuses protection on resources, identities, and policy decisions.
CURRENT LAW OR POLICYDoD Directive 3000.09 — Autonomy in Weapon Systems
Official policy for autonomous and semi-autonomous weapon systems. The directive expressly excludes autonomous or semi-autonomous cyberspace capabilities, unarmed platforms, and autonomous systems that are not weapon systems; its weapon-system V&V, testing, human-judgment, abort, and audit provisions must not be silently generalized into a cyber-defense compliance claim.
OBSERVED DEPLOYMENT OR PRACTICEGoogle and Kairos Power Advanced Nuclear Agreement
First-party announcement of an agreement intended to enable up to 500 MW of advanced nuclear power, with an initial reactor planned by 2030 and additional deployment through 2035.
OBSERVED DEPLOYMENT OR PRACTICEConstellation and Microsoft Crane Clean Energy Center Agreement
First-party announcement of a 20-year power purchase agreement intended to support restart of a nuclear unit and provide approximately 835 MW of carbon-free energy to the grid.
OBSERVED DEPLOYMENT OR PRACTICEConstellation and Meta Clinton Clean Energy Center Agreement
First-party announcement of a 20-year PPA for output of the Clinton Clean Energy Center supporting Meta operations and continued nuclear generation.
CURRENT TECHNICAL STANDARDCall for Comments on NIST SP 800-82 Revision 4
Official notice that NIST initiated revision of SP 800-82; the notice does not itself supersede Revision 3.
CURRENT LAW OR POLICY10 CFR Part 73 Subpart J — Security Requirements at Commercial Nuclear Plants
Current codified sections 73.100, 73.110, and 73.120. Selection and applicability depend on the Part 53 licensing path and facility election.
CURRENT LAW OR POLICYRestricting Drones Near Critical Infrastructure Sites — Proposed Rule
Official May 2026 proposed rule for a petition process. A proposed restriction process does not itself grant a private facility authority to jam, spoof, seize, damage, or destroy an aircraft.
CURRENT LAW OR POLICY6 U.S.C. § 124n — Protection of Certain Facilities and Assets from Unmanned Aircraft
Federal statutory authorities for designated federal departments and covered missions; the statute is not a general delegation of counter-UAS mitigation authority to private facility owners.
CURRENT LAW OR POLICY47 U.S.C. § 333 — Willful or Malicious Interference
General federal prohibition on willful or malicious interference with authorized radio communications; system design must identify any separate statutory authority before proposing RF mitigation.
CURRENT TECHNICAL STANDARDNERC Critical Infrastructure Protection Reliability Standards Catalog
Official catalog for current CIP reliability standards. Applicability depends on BES registration, asset categorization, effective dates, implementation plans, and jurisdiction-specific enforcement; this catalog is not a facility compliance determination.
CURRENT LAW OR POLICYNational Cyber Force — About Us
Official description of the NCF as a defence-intelligence partnership operating in and through cyberspace under UK and international law. It does not create authority for private independent cyber effects.
CURRENT LAW OR POLICYGovernment Cyber Security Strategy 2022 to 2030 — 2026 currentness notice
Official strategy page updated in January 2026 to direct readers to the Government Cyber Action Plan for the latest implementation details.
CURRENT LAW OR POLICYFrance COMCYBER — La lutte informatique offensive (LIO) — K06 current record
Official public description of military offensive cyber operations. It is a state military doctrine record, not a private-sector license or universal rule of international law.
CURRENT LAW OR POLICYFrance COMCYBER — La lutte informatique défensive (LID) — K06 current record
Official public description of defensive military cyber activity and permanent defensive posture.
CURRENT LAW OR POLICYDirective (EU) 2022/2555 — NIS 2 Directive
Official NIS 2 legal text. Entity scope, national transposition, sector classification, and enforcement remain jurisdiction- and organization-specific.
CURRENT LAW OR POLICYCyber Resilience Act — Implementation and reporting timeline
Official implementation timeline. At the K06 cutoff, the Act was in force; reporting obligations were scheduled for 2026-09-11 and main obligations for 2027-12-11.
CURRENT LAW OR POLICYAustralian Signals Directorate — Offensive cyber
Official description of government-directed offshore offensive cyber activity. It expressly ties operations to Australian Government authorization and a legal framework.
CURRENT LAW OR POLICY2023–2030 Australian Cyber Security Strategy — Horizon 2
Official Horizon 2 page for 2026–2028, recording a current whole-of-nation cyber-resilience program. It does not by itself establish facility compliance or private operational authority.
CURRENT LAW OR POLICYRepublic of Korea NIS — Cyber and AI security publications
Official publication index showing current national cybersecurity white papers, annual reports, and AI/ML supply-chain guidance. The index does not by itself establish every proposition in third-party accounts of ROK doctrine.
CURRENT LAW OR POLICYROK position on application of international law in cyberspace — official publication listing
The official MOFA publication index identifies a 2025 national position. K06 did not obtain a stable exact English document URL through the bounded retrieval path, so substantive propositions remain partially reviewed.
CURRENT LAW OR POLICYCanada's National Cyber Security Strategy — Securing Canada's Digital Future
Official 2025 strategy backgrounder identifying whole-of-society engagement, agile leadership, protection, global leadership, and detection/disruption pillars.
CURRENT LAW OR POLICYArticles on Responsibility of States for Internationally Wrongful Acts
Official ILC text addressing attribution, direction and control, breach, and circumstances precluding wrongfulness. It is not a cyber-specific treaty and does not resolve all disputed cyber applications.
CURRENT LAW OR POLICYCyber operations and harmful information
Official ICRC position resource emphasizing protection of civilians, civilian infrastructure, and civilian data under international humanitarian law during armed conflict.
CURRENT LAW OR POLICYResponsible Cyber Power in Practice
Official public description of the National Cyber Force approach to accountable, precise, and calibrated cyber operations under UK authority.
CURRENT LAW OR POLICYNational Cyber Strategy 2022
Official strategy describing the United Kingdom's objective to remain a leading responsible and democratic cyber power able to protect and promote national interests in and through cyberspace.
CURRENT LAW OR POLICYLa lutte informatique défensive (LID)
Official French military description of defensive cyber operations and protection of ministry systems and missions.
CURRENT LAW OR POLICYLa lutte informatique offensive (LIO)
Official French military description of offensive cyber operations as a military mission under state command; it is not private-sector authority.
CURRENT LAW OR POLICYEU Policy on Cyber Defence
Official EU policy overview calling for full-spectrum cyber-defence capability, closer civilian-military coordination, private-sector cooperation, crisis management, and reduced strategic dependencies.
CURRENT LAW OR POLICYAction Plan on Cybersecurity and Artificial Intelligence
Official 2026 action-plan record addressing risks and opportunities of advanced AI in cybersecurity; it supplements rather than silently replaces existing EU legal instruments.
CURRENT LAW OR POLICY2023–2030 Australian Cyber Security Strategy
Official national strategy organized around six cyber shields, including protected critical infrastructure, sovereign capability, threat sharing and blocking, and regional resilience.
CURRENT LAW OR POLICYRepublic of Korea National Cybersecurity Strategy 2024
Official national-strategy record emphasizing proactive cyber defence, international cooperation, critical-infrastructure resilience, emerging-technology advantage, and integrated response capability.
OBSERVED DEPLOYMENT OR PRACTICEKorea's 2024 National Cybersecurity White Paper
Officially published multi-agency white paper describing Korea's national cybersecurity framework, threat trends, and sector activities.
CURRENT LAW OR POLICYCanada's National Cyber Security Strategy: Securing Canada's Digital Future
Official 2025 strategy organized around whole-of-society engagement, agile leadership, protection partnerships, global leadership, and detection and disruption of cyber threat actors.
OBSERVED DEPLOYMENT OR PRACTICENational Cyber Threat Assessment 2025–2026
Official threat assessment identifying persistent cybercrime, ransomware risk to critical infrastructure, and increasingly disruptive state-sponsored activity.
CURRENT LAW OR POLICYReport of the Group of Governmental Experts on Advancing Responsible State Behaviour in Cyberspace
UN-mandated consensus report addressing responsible state behaviour, international law, norms, confidence-building, capacity-building, and cyber risk.
CURRENT LAW OR POLICYInternational Humanitarian Law and Cyber Operations During Armed Conflicts
ICRC position paper explaining that IHL applies to and limits cyber operations during armed conflict, with particular concern for civilian harm and infrastructure.
CURRENT LAW OR POLICY10 CFR Part 53 — Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors
Official final-rule notice establishing an optional technology-inclusive framework for licensing future commercial nuclear plants. Applicability to a named facility requires licensing counsel and NRC process evidence.
CURRENT LAW OR POLICYNRC Regulatory Guide 5.71 Revision 1 — Cyber Security Programs for Nuclear Power Reactors
Official regulatory guide describing an NRC-accepted method for meeting nuclear-reactor cyber-security requirements. A guide is not a facility license, finding, or universal certification.
CURRENT TECHNICAL STANDARDDOE Cyber-Informed Engineering
Official DOE method page describing integration of cyber-security considerations into engineering conception, design, development, and operation, with priority on worst-consequence pathways.
CURRENT TECHNICAL STANDARDNIST SP 800-82 Revision 3 — K07 Official Review Record
Final NIST guidance for securing operational technology while addressing performance, reliability, and safety requirements. NIST initiated a Revision 4 pre-draft process in 2026; Revision 3 remains the final publication at the K07 cutoff.
RESEARCH FINDINGNIST SP 800-82 Revision 4 — Pre-Draft Call for Comments
Official pre-draft revision notice. It is evidence that revision work is underway, not a final control baseline or replacement for Revision 3.
CURRENT TECHNICAL STANDARDNIST SP 800-161 Revision 1 Update 1 — Cybersecurity Supply Chain Risk Management Practices
Final NIST C-SCRM guidance for identifying, assessing, and mitigating supply-chain risk across organizational levels and system life cycles.
CURRENT TECHNICAL STANDARDNIST SP 1326 — Cybersecurity Supply Chain Risk Management Due Diligence Assessment Quick-Start Guide
Final quick-start guide for minimum reasonable supplier and product research supporting acquisition and existing-system decisions; it supplements rather than replaces SP 800-161 Revision 1.
CURRENT TECHNICAL STANDARDNIST IR 8356 — Security and Trust Considerations for Digital Twin Technology
Final NIST report on digital-twin characteristics, expected uses, cyber-security challenges, and trust considerations. It does not certify a twin as faithful to a real facility.
CURRENT TECHNICAL STANDARDNIST SP 800-218A — Secure Software Development Practices for Generative AI and Dual-Use Foundation Models
Final SSDF community profile adding model-development practices and tasks for producers and acquirers of AI systems. Use with SP 800-218, not as a standalone certification.
CURRENT LAW OR POLICYFederal Acquisition Regulation 37.602 — Performance Work Statement
Current FAR text requiring performance work statements, to the maximum extent practicable, to describe required results and enable assessment against measurable performance standards.
CURRENT LAW OR POLICYFederal Acquisition Regulation Part 46 — Quality Assurance
Current FAR quality-assurance provisions addressing inspection, contractor quality control, nonconformance, acceptance, critical items, and surveillance plans.
CURRENT TECHNICAL STANDARDNTIA — The Minimum Elements for a Software Bill of Materials
Official minimum-element report covering baseline component data, automation support, and practices for software transparency. An SBOM is inventory evidence, not proof of absence of vulnerabilities or compromise.
CURRENT TECHNICAL STANDARDCISA Hardware Bill of Materials Framework for Supply Chain Risk Management
Official framework providing repeatable component naming, attribute, and format concepts for hardware supply-chain transparency. HBOM completeness and applicability remain product- and contract-specific.
RESEARCH FINDINGNIST AI RMF Profile on Trustworthy AI in Critical Infrastructure — Concept Note
Official 2026 concept note for a critical-infrastructure AI RMF profile. It is development evidence, not a final profile or certification baseline.
CURRENT TECHNICAL STANDARDUnicode 17.0 Runic Code Chart
Official character chart for the Runic block U+16A0–U+16FF. Encoding a character does not assign a modern project meaning or guarantee domain-registration support.
CURRENT TECHNICAL STANDARDUnicode Standard Annex #15 — Unicode Normalization Forms
Normative Unicode normalization specification. NFC consistency supports stable comparison, but normalization does not create semantic equivalence between different characters.
CURRENT TECHNICAL STANDARDRFC 3492 — Punycode: A Bootstring Encoding of Unicode for IDNA
Defines Punycode, the ASCII-compatible encoding used by IDNA. It does not determine registry policy, registration availability, DNS delegation, TLS issuance, or hosting status.
CURRENT TECHNICAL STANDARDRFC 5890 — IDNA Definitions and Document Framework
Defines IDNA terminology including U-labels and A-labels. Protocol validity remains distinct from registry, registrar, delegation, resolution, certificate, and hosting states.
CURRENT TECHNICAL STANDARDRFC 5891 — Internationalized Domain Names in Applications: Protocol
Defines IDNA2008 registration and lookup protocol without changing DNS itself. It is for domain names, not free text.
CURRENT TECHNICAL STANDARDRFC 5646 — Tags for Identifying Languages
Defines BCP 47 language tags. A script subtag must describe the actual language and script of content rather than serving as a search-engine hint.
CURRENT TECHNICAL STANDARDFIPS 203 — Module-Lattice-Based Key-Encapsulation Mechanism Standard
Specifies ML-KEM parameter sets for key establishment. Migration requires inventory, interoperability, implementation validation, and lifecycle planning; publication does not make an existing system quantum-resistant.
CURRENT TECHNICAL STANDARDFIPS 204 — Module-Lattice-Based Digital Signature Standard
Specifies ML-DSA digital signatures. Algorithm adoption does not prove signer authority, factual truth, implementation correctness, or migration completion.
CURRENT TECHNICAL STANDARDFIPS 205 — Stateless Hash-Based Digital Signature Standard
Specifies SLH-DSA. It is one migration option with distinct signature-size and performance tradeoffs that must be evaluated for the named use.
Source authority boundary
Official publication supports provenance and bounded propositions. It does not automatically prove factual truth, legal status, consciousness, personhood, citizenship, operational deployment, or authority outside the publisher’s scope.