This document defines how CTR-ACB controls are specified so they can be audited and automated.
A control is certifiable when it is:
Each control in tools/control-catalog.json SHOULD follow this template:
id: stable identifier (e.g., TR-CTRL-01)title: short namerequirement: normative statementevidence: required/recommended evidence artifacts (with pointers)evaluation: how an evaluator verifies the control (automatable where possible)severity: impact if not satisfied (minor / major / critical)tiers: which assurance tiers the control applies to (AL1–AL4)Controls are not satisfied by prose. They are satisfied by artifacts.
Primary evidence binders:
TRQPControlSatisfactionDeclaration)TRQPCertificationAttestation)The Control Satisfaction Declaration links:
pass/fail/n/a)See also: ../guides/control-objectives.md.