trqp-assurance-hub

Control framework

This document defines how CTR-ACB controls are specified so they can be audited and automated.

A control is certifiable when it is:

Control template

Each control in tools/control-catalog.json SHOULD follow this template:

Evidence binding model

Controls are not satisfied by prose. They are satisfied by artifacts.

Primary evidence binders:

The Control Satisfaction Declaration links:

Practical guidance

See also: ../guides/control-objectives.md.