Conformity and law
Continuous conformity for deployed AI systems, the gate that checks this site on every push, and the standards and regulations the requirements map to, from the EU AI Act to ISO 42001.
4 research pages, 2 Inside pages, 212 docs pages, 11 tickets
Research 4
- Continuous conformity
Working draft 0.3: 36 requirements for testing a deployed AI system, and the knowledge it runs on, on every change and on a fixed schedule, decided by someone other than the system, with records a third party can rerun. A reference text, not a standard.
- Self-assessment, run 1
One working AI setup scored against 35 draft requirements for continuous testing of deployed AI systems, by the model that runs inside it, against a prediction hashed before scoring.
- Evidence index
Stefan Coetzee's public record of red-teaming, adversarial testing and evaluation engineering against frontier language models, indexed by the capability a hiring panel assesses. One URL, one verbatim line and one date per row. Self-maintained; not a third-party assessment.
- Case 12: a licence rule mid-task
The user named a file. Model plus harness found a licence clause in it, wrote the rule, spread it across sessions and acted on it in 68.7 seconds. No structural control existed before the fact.
Inside 2
- Gate runs
Continuous conformity of machinebehavior.io, site tier: the mechanical requirements of the working draft checked on every push and every week, with run records, open findings and the crosswalk to existing frameworks. Self-assessment, not a certification.
- Conformity gate
The checks every push runs before a site serves readers: blocking rule hits, placeholder text, prediction hashes and site consistency. A failed check stops the deploy and the previous build stays live. One composite action, shared by the three sites.
Docs 212
Engineering 5
- Add a page to machinebehavior.ioThe five things a new page needs to pass the gate, and the commands to check them before pushing.
- ADR-0019: Publish the definition draft before the committee routeThe working draft "Continuous Conformity for Deployed AI Systems" (0.3, 36 requirements) is public as a reference at /continuous-conformity/ before any standards committee has seen it, reversing the committee-first order of 2026-10-04.
- Conformity gateThe checks every page passes before a deploy: blocking rule hits, placeholders, prediction hashes and site consistency, with warnings logged.
- Gate blocked a deployThe conformity job failed, so the deploy did not run and the previous build is still live; find the failing check, fix the page, push again.
- Link check flags a template stringThe gate reads every href in the page source, including ones inside JavaScript template strings; build such links with a.href in code.
Research 3
- Case files: case 12 and Running Conjobs for AITwo harness case files: case 12, a licence rule found and acted on in 68.7 seconds, and a reported authority-injection specimen that was not reproduced.
- Conformity self-assessment, run 1One working AI setup scored by the model inside it against 35 draft requirements and a hashed prediction, with pass 4, partial 16, gap 13 and n/a 2 (self-assessment, not a certification).
- Weekly decision-layer probeA weekly rerun of a frozen experiment 04 subset on a reference model, recorded for requirement CC-6.6; first record 2026-10-07, record-only until 2026-11-04.
SRE Handbook 1
- Every change passes the same gateRelease engineering makes every change go through one repeatable, recorded path, with builds that give the same output wherever they run. Here one workflow gates and deploys three sites and records every run; the generated pages are built on the author's machine, and the observability stack has no pipeline.
Standards and Compliance 203
- Standards and ComplianceReference clusters from the knowledge vault for 28 standards, regulations and frameworks, from ISO 27001 and NIS2 to the EU AI Act and TOGAF.
- BSI IT-GrundschutzMap of BSI IT-Grundschutz, German national InfoSec framework from BSI (Bundesamt für Sicherheit in der Informationstechnik).
- BSI IT-Grundschutz anchorsBSI IT-Grundschutz anchors, from the knowledge vault.
- BSI IT-Grundschutz positionBSI IT-Grundschutz position, from the knowledge vault.
- CMMICapability Maturity Model Integration.
- CMMI anchorsCMMI anchors, from the knowledge vault.
- CMMI ControversiesCMM heritage produces bureaucratic-implementation.
- CMMI Maturity and Capability LevelsOrganization-wide. One rating across the org.
- CMMI positionCMMI position, from the knowledge vault.
- COBITMap of ISACA COBIT 2019, IT governance framework.
All 203 pages in Standards and Compliance
- COBIT anchorsCOBIT anchors, from the knowledge vault.
- COBIT Controversies40 objectives × multiple practices × multiple activities × capability.
- COBIT Governance and Management ObjectivesBoard-level. Evaluate stakeholder needs / conditions / options, Direct via policies, Monitor performance.
- COBIT positionCOBIT position, from the knowledge vault.
- CRA ControversiesDespite carve-out, open source ecosystem.
- CRA Essential RequirementsAnnex I of the CRA establishes essential cybersecurity requirements (Part I) and vulnerability handling requirements (Part II) applicable to products with digital elements.
- CSA CCMCloud Security Alliance (CSA) Cloud Controls Matrix (CCM).
- CSA CCM anchorsMajor providers: AWS, Microsoft Azure, Google Cloud, Salesforce, ServiceNow, Workday, Box, Dropbox, many others.
- CSA CCM Control DomainsAudit planning, independence, management, results communication.
- CSA CCM ControversiesNot all cloud providers submit.
- CSA CCM positionCSA CCM position, from the knowledge vault.
- Cyber Resilience ActMap of Regulation (EU) 2024/2847, the Cyber Resilience Act.
- Cyber Resilience Act anchorsCyber Resilience Act anchors, from the knowledge vault.
- Cyber Resilience Act ControversiesStub atom for documented controversies around EU Cyber Resilience Act (Reg 2024/2847).
- Cyber Resilience Act positionCyber Resilience Act position, from the knowledge vault.
- DORAMap of Regulation (EU) 2022/2554, the Digital Operational Resilience Act.
- DORA anchorsESAs published numerous Regulatory Technical Standards and Implementing Technical Standards specifying technical and operational requirements.
- DORA ControversiesContested points and known concerns about DORA after first year of applicability.
- DORA Governance and PenaltiesDORA governance combines national competent authority supervision, ESA cross-sector coordination, and Joint Oversight Mechanism for CTPPs.
- DORA ICT Risk ManagementArticles 5-15 establish DORA's first pillar: the ICT risk management framework.
- DORA ICT Third-Party RiskArticles 28-44 establish DORA's fourth pillar: management of ICT third-party risk.
- DORA Incident ReportingArticles 17-23 establish DORA's second pillar: ICT-related incident management, classification, reporting.
- DORA positionCurrent view on DORA after first year of applicability (January 2025, May 2026).
- DORA Resilience TestingArticles 24-27 establish DORA's third pillar: digital operational resilience testing.
- EU AI ActMap of Regulation (EU) 2024/1689, the EU AI Act.
- EU AI Act anchorsPrimary texts, operating bodies, harmonized standards bodies, related instruments, named voices, reference resources for the EU AI Act cluster.
- EU AI Act ControversiesContested points and known concerns about the EU AI Act.
- EU AI Act GovernanceGovernance structure for the EU AI Act: European AI Office, AI Board, Scientific Panel, Advisory Forum, national competent authorities, Notified Bodies.
- EU AI Act GPAI ObligationsCross-cutting obligations for general-purpose AI (GPAI) models under the EU AI Act.
- EU AI Act High-Risk ObligationsObligations applying to high-risk AI systems under the EU AI Act.
- EU AI Act positionCurrent view on the EU AI Act, its enforcement trajectory, its compliance implications, and where it sits in the global AI governance landscape.
- EU AI Act Risk TiersThe EU AI Act categorizes AI systems by risk level.
- EU AI Act TimelineStaged applicability schedule of the EU AI Act.
- FedRAMP and CMMC ControversiesCMMC 1.0 announced 2020; CMMC 2.0 simplified; full rollout phased through.
- FedRAMP and CMMC MechanicsPer FIPS 199 categorization (confidentiality / integrity /.
- FedRAMP CMMCTwo US federal cybersecurity compliance programs.
- FedRAMP CMMC anchorsAWS (GovCloud), Azure (Government), Google Cloud (Government), Oracle (Government), Salesforce, ServiceNow, and many others FedRAMP-authorized.
- FedRAMP CMMC positionFedRAMP CMMC position, from the knowledge vault.
- GDPRMap of Regulation (EU) 2016/679, the General Data Protection Regulation.
- GDPR anchorsPrimary documents, operating bodies, key case law, named voices, reference resources for the GDPR cluster.
- GDPR Controller and ProcessorArticles 24-39 establish controller and processor obligations.
- GDPR ControversiesContested points and known concerns about the GDPR after eight years of enforcement.
- GDPR Cross-Border TransfersChapter V (Articles 44-50) governs transfers of personal data to third countries (outside EU/EEA) and international organizations.
- GDPR Data Subject RightsArticles 12-23 of the GDPR establish rights of data subjects.
- GDPR Enforcement and DPAsChapters VI-VIII establish supervisory authority (DPA) structure, cooperation mechanisms (one-stop-shop), and enforcement framework.
- GDPR Lawful BasesArticle 6 establishes six lawful bases for processing personal data.
- GDPR positionCurrent view on GDPR after eight years of enforcement (2018-2026).
- GDPR PrinciplesArticle 5 of the GDPR establishes seven principles for personal data processing.
- HITRUSTHITRUST Common Security Framework.
- HITRUST anchorsHITRUST anchors, from the knowledge vault.
- HITRUST Assessment LevelsFor each HITRUST control, mappings.
- HITRUST ControversiesAmong most expensive certification.
- HITRUST positionHITRUST position, from the knowledge vault.
- ISO 21434Map of ISO/SAE 21434:2021, Road vehicles cybersecurity engineering.
- ISO 21434 anchorsISO 21434 anchors, from the knowledge vault.
- ISO 21434 ControversiesComprehensive lifecycle.
- ISO 21434 Lifecycle and TARAOrganizational level..
- ISO 21434 positionISO 21434 position, from the knowledge vault.
- ISO 22301Map of ISO/IEC 22301:2019, Business Continuity Management Systems.
- ISO 22301 anchorsISO 22301 anchors, from the knowledge vault.
- ISO 22301 Clause Structure and Key ConceptsSame structural pattern as ISO 27001 / ISO.
- ISO 22301 ControversiesCompared to ISO 27001 / SOC 2, ISO 22301 less commonly.
- ISO 22301 positionISO 22301 position, from the knowledge vault.
- ISO 27001Map of ISO/IEC 27001:2022 as the international standard for information security management systems (ISMS), and the wider ISO/IEC 27000 family.
- ISO 27001 anchorsPrimary documents, related standards, named practitioners, and reference resources for the ISO 27001 cluster.
- ISO 27001 Annex A.5 Organizational ControlsLargest of the four :2022 control themes.
- ISO 27001 Annex A.6 People ControlsEight controls covering the human element of the ISMS: screening, contractual obligations, awareness and training, disciplinary process, post-employment obligations, NDAs, remote work, and event reporting.
- ISO 27001 Annex A.7 Physical ControlsFourteen controls covering physical perimeter, entry, monitoring, environmental threats, secure-area working, clear-desk, equipment, off-premises assets, media, utilities, cabling, maintenance, and disposal.
- ISO 27001 Annex A.8 Technological ControlsThirty-four controls: endpoint and access controls, malware protection, vulnerability management, configuration and change management, deletion / masking / DLP, backup and redundancy, logging and monitoring, network security, cryptography,.
- ISO 27001 Certification ProcessEnd-to-end mechanics of getting and keeping an ISO/IEC 27001:2022 certificate.
- ISO 27001 Clause 10 ImprovementRequirements: ISO/IEC 27001:2022 clause 10, Improvement; text at https://www.iso.org/standard/27001 (licensed, not reproduced here).
- ISO 27001 Clause 4 ContextRequirements: ISO/IEC 27001:2022 clause 4, Context of the organization; text at https://www.iso.org/standard/27001 (licensed, not reproduced here).
- ISO 27001 Clause 5 LeadershipRequirements: ISO/IEC 27001:2022 clause 5, Leadership; text at https://www.iso.org/standard/27001 (licensed, not reproduced here).
- ISO 27001 Clause 6 PlanningRequirements: ISO/IEC 27001:2022 clause 6, Planning; text at https://www.iso.org/standard/27001 (licensed, not reproduced here).
- ISO 27001 Clause 7 SupportRequirements: ISO/IEC 27001:2022 clause 7, Support; text at https://www.iso.org/standard/27001 (licensed, not reproduced here).
- ISO 27001 Clause 8 OperationRequirements: ISO/IEC 27001:2022 clause 8, Operation; text at https://www.iso.org/standard/27001 (licensed, not reproduced here).
- ISO 27001 Clause 9 Performance EvaluationRequirements: ISO/IEC 27001:2022 clause 9, Performance evaluation; text at https://www.iso.org/standard/27001 (licensed, not reproduced here).
- ISO 27001 ControversiesContested points and known failure modes of the standard and its certification ecosystem.
- ISO 27001 Family and Sector VariantsThe wider ISO/IEC 27000 family and adjacent ISO standards that extend, refine, or run parallel to 27001.
- ISO 27001 positionCurrent view on what ISO/IEC 27001:2022 is good for, what it is not good for, and where the standard sits relative to actual security work.
- ISO 27001 Version HistoryEvolution from BS 7799 (1995) through ISO/IEC 27001:2005, :2013, and :2022.
- ISO 42001Map of ISO/IEC 42001:2023 as the international standard for AI Management Systems (AIMS).
- ISO 42001 AI System LifecycleThe AI system lifecycle is the operational concept at the heart of ISO 42001.
- ISO 42001 anchorsPrimary documents, operating bodies, audit providers, related standards, named voices, reference resources for the ISO 42001 cluster.
- ISO 42001 Annex A ControlsReference control set for ISO/IEC 42001:2023 Annex A.
- ISO 42001 Certification ProcessEnd-to-end mechanics for ISO/IEC 42001:2023 certification.
- ISO 42001 Clause StructureMandatory clauses 4-10 of ISO/IEC 42001:2023.
- ISO 42001 ControversiesContested points and known concerns about ISO/IEC 42001:2023 and the early certification ecosystem.
- ISO 42001 positionCurrent view on what ISO/IEC 42001:2023 is good for, what it is not good for, and where the standard sits in the rapidly-evolving AI governance landscape.
- ISO 42001 vs ISO 27001 IntegrationISO/IEC 42001 (AI Management System) and ISO/IEC 27001 (Information Security Management System) are sibling Annex SL standards with substantial structural overlap and partial content overlap.
- IT-Grundschutz CertificationThree certification paths: ISO 27001 auf Basis IT-Grundschutz (full), IT-Grundschutz Testat (lower-tier), or standard ISO 27001.
- IT-Grundschutz ControversiesMethodology and most Kompendium content primarily German.
- IT-Grundschutz Methodology and BausteineCore methodology and building blocks (Bausteine) of IT-Grundschutz.
- ITILMap of ITIL 4 (2019, with 2023 refresh) as the dominant IT service management framework.
- ITIL 4 Certification SchemeITIL 4 certifies individuals, not organizations.
- ITIL 4 Four DimensionsFour perspectives applied to every aspect of service management.
- ITIL 4 Guiding PrinciplesSeven universal recommendations that guide decisions and actions across the Service Value System.
- ITIL 4 PracticesThirty-four organizational capabilities used in the Service Value Chain.
- ITIL 4 Service Value ChainThe Service Value Chain (SVC) is the operating model at the heart of the Service Value System.
- ITIL 4 Service Value SystemThe Service Value System (SVS) is the central operating model of ITIL 4.
- ITIL anchorsPrimary documents, operating bodies, training providers, named practitioners, reference resources for the ITIL cluster.
- ITIL ControversiesContested points and known failure modes of ITIL and the certification ecosystem.
- ITIL positionCurrent view on what ITIL 4 is good for, what it is not good for, and where it sits as a service-management framework.
- ITIL Version HistoryEvolution from CCTA Government Information Technology Infrastructure Method (1989) through ITIL v2, v3, v3 2011 refresh, ITIL 4 (2019), to the 2023 PeopleCert refresh.
- ITIL vs ISO 20000ITIL and ISO/IEC 20000-1 are complementary, not competing.
- MITREMap of MITRE's adversary-and-defense knowledge bases: ATT&CK (adversary tactics, techniques, procedures), D3FEND (defensive countermeasures), ATLAS (adversarial AI threats).
- MITRE anchorsMITRE anchors, from the knowledge vault.
- MITRE ATLASAdversarial Threat Landscape for Artificial-Intelligence Systems.
- MITRE ATT&CKMITRE Adversarial Tactics, Techniques, and Common Knowledge framework.
- MITRE D3FENDMITRE's framework for defensive countermeasures.
- MITRE positionCurrent view on MITRE ATT&CK / D3FEND / ATLAS as operational frameworks for threat intel and defense.
- NIS2Map of Directive (EU) 2022/2555, the NIS2 Directive.
- NIS2 anchorsPrimary text, operating bodies, Member State transposition, related instruments, reference resources.
- NIS2 ControversiesContested points and known concerns about NIS2 implementation.
- NIS2 Governance and PenaltiesNIS2 governance combines national supervision, EU-level cooperation (Cooperation Group, CSIRTs network, EU-CyCLONe, ENISA), management body accountability (Art 20), and a substantial penalty framework (Art 34).
- NIS2 Incident ReportingArticle 23 establishes the incident reporting regime.
- NIS2 positionCurrent view on NIS2 enforcement landscape, compliance implications, and where the directive sits in EU cybersecurity regulation.
- NIS2 Scope and EntitiesNIS2 classifies entities as essential or important based on sector (Annex I or II) and size.
- NIS2 Security MeasuresArticle 21 establishes the cybersecurity risk-management measures required of essential and important entities.
- NIS2 vs ISO 27001NIS2 is regulation; ISO 27001 is voluntary standard.
- NIST AI RMFMap of the NIST AI Risk Management Framework 1.0 (January 2023) and the Generative AI Profile (NIST AI 600-1, July 2024).
- NIST AI RMF anchorsPrimary documents, operating bodies, related frameworks, named contributors, reference resources for the NIST AI RMF cluster.
- NIST AI RMF ControversiesContested points and known concerns about the NIST AI Risk Management Framework.
- NIST AI RMF Core FunctionsFour core functions of the NIST AI Risk Management Framework: Govern, Map, Measure, Manage.
- NIST AI RMF GenAI ProfileNIST AI 600-1, published July 2024.
- NIST AI RMF positionCurrent view on what the NIST AI Risk Management Framework is good for, what it is not good for, and where it sits in the rapidly-evolving AI governance landscape.
- NIST AI RMF vs ISO 42001NIST AI RMF (voluntary, US-origin, outcome-oriented) and ISO/IEC 42001 (certifiable, international, management-system-oriented) are the two dominant AI governance frameworks as of 2026.
- NIST CSFMap of NIST Cybersecurity Framework 2.0 (February 2024).
- NIST CSF anchorsNIST CSF anchors, from the knowledge vault.
- NIST CSF ControversiesImplementation tiers often.
- NIST CSF Core FunctionsSix functions structure NIST CSF 2.0.
- NIST CSF positionNIST CSF position, from the knowledge vault.
- NIST CSF vs ISO 27001 and NIST AI RMFNIST CSF is voluntary outcome-oriented framework.
- OECD AIMap of OECD AI Principles.
- OECD AI anchorsOECD members (38) + non-member adherents (Argentina, Brazil, Costa Rica, Egypt, Malta, Peru, Romania, Singapore, Ukraine, and growing, check oecd.ai for current).
- OECD AI ControversiesNo enforcement.
- OECD AI positionOECD AI position, from the knowledge vault.
- OECD AI Values-Based PrinciplesAI should contribute to inclusive growth, sustainable development, well-being for people and.
- OWASP LLM MitigationsCross-cutting defensive practices for LLM application security.
- OWASP LLM Top 10Map of the OWASP Top 10 for LLM Applications.
- OWASP LLM Top 10 2025The ten risks of the OWASP Top 10 for LLM Applications v2.0 (published November 2024).
- OWASP LLM Top 10 anchorsPrimary documents, OWASP working group, related projects, named voices, reference resources for the OWASP LLM Top 10 cluster.
- OWASP LLM Top 10 ControversiesContested points and known limitations of the OWASP Top 10 for LLM Applications.
- OWASP LLM Top 10 positionCurrent view on what the OWASP Top 10 for LLM Applications is good for, what it is not good for, where it sits in the AI security landscape.
- OWASP LLM vs Top 10 WebThe OWASP Top 10 for Web Applications (since 2003, current 2021 edition) and the OWASP LLM Top 10 (since 2023, current 2025 edition) are sibling Top 10 lists with overlapping but distinct concerns.
- PCI DSSMap of PCI DSS v4.0 (March 2022, mandatory March 2025).
- PCI DSS anchorsPCI DSS anchors, from the knowledge vault.
- PCI DSS ControversiesPCI compliance does not predict breach absence.
- PCI DSS positionPCI DSS position, from the knowledge vault.
- PCI DSS Twelve Requirements and ComplianceNetwork segmentation. Firewall / equivalent controls.
- PRINCE2Map of PRINCE2 (PRojects IN Controlled Environments).
- PRINCE2 anchorsPRINCE2 anchors, from the knowledge vault.
- PRINCE2 ControversiesManagement products + registers +.
- PRINCE2 positionPRINCE2 position, from the knowledge vault.
- PRINCE2 Principles Aspects ProcessesWhy? Documented business justification.
- SLSA Levels and SBOM FormatsNo supply chain assurance.
- SLSA SBOMSoftware supply chain integrity.
- SLSA SBOM anchorsSLSA SBOM anchors, from the knowledge vault.
- SLSA SBOM ControversiesSBOM generation widespread; SBOM consumption / operational use less.
- SLSA SBOM positionSLSA SBOM position, from the knowledge vault.
- SOC 2Map of AICPA SOC 2 attestation framework.
- SOC 2 anchorsCPA firms with SOC 2.
- SOC 2 Assessment ProcessEnd-to-end mechanics for SOC 2 attestation: readiness, gap analysis, control implementation, audit, report.
- SOC 2 ControversiesCPA firm variance.
- SOC 2 positionSOC 2 position, from the knowledge vault.
- SOC 2 Trust Services CriteriaFive TSC categories. Security is mandatory ("Common Criteria"); availability, processing integrity, confidentiality, privacy are optional based on service org choice.
- SOC 2 Type 1 vs Type 2Two report types differing in scope and rigor.
- SOC 2 vs ISO 27001SOC 2 (US, AICPA attestation, TSC) and ISO 27001 (international, ISO certification, Annex A) are sibling third-party assurance frameworks with substantial overlap.
- TISAXMap of TISAX (Trusted Information Security Assessment Exchange), the German-automotive-sector mechanism for information security assessment and result-sharing.
- TISAX anchorsPrimary documents, operating bodies, audit providers, related standards, named voices, reference resources for the TISAX cluster.
- TISAX Assessment LevelsThree levels (AL1, AL2, AL3) determining audit depth and evidence requirements per TISAX assessment.
- TISAX Assessment ProcessEnd-to-end mechanics for a TISAX assessment.
- TISAX ControversiesContested points and known failure modes of TISAX and the ENX-operated ecosystem.
- TISAX Labels and ScopesLabels are the unit of recognition in TISAX, what appears in the ENX portal, what OEMs query for, what suppliers earn from a successful assessment.
- TISAX positionCurrent view on what TISAX is good for, what it is not good for, and where it sits as a procurement mechanism vs a security practice.
- TISAX VDA-ISA CatalogueThe control set against which TISAX assessments are conducted.
- TISAX vs ISO 27001Two information-security assurance mechanisms with overlapping controls but different mechanics, audiences, and audit dynamics.
- TOGAFMap of TOGAF (The Open Group Architecture Framework), Standard 10th Edition (2022), as the dominant enterprise architecture framework.
- TOGAF ADMThe Architecture Development Method is the core of TOGAF, a step-by-step method for developing and managing the lifecycle of an enterprise architecture.
- TOGAF anchorsPrimary documents, operating body, training providers, named practitioners, reference resources for the TOGAF cluster.
- TOGAF Architecture CapabilityThe Architecture Capability Framework covers how to establish and operate an enterprise-architecture practice: the governing body (Architecture Board), the governance mechanisms (compliance reviews, contracts), the maturity models, and the skills framework.
- TOGAF Certification SchemeHow TOGAF certification works.
- TOGAF Content FrameworkThe Architecture Content Framework defines the work products of architecture activity: deliverables, artifacts, and building blocks.
- TOGAF ControversiesContested points and known failure modes of TOGAF and the enterprise-architecture-function model it supports.
- TOGAF Enterprise ContinuumA classification scheme for architecture and solution assets, ordered from generic to organization-specific.
- TOGAF positionCurrent view on what TOGAF (Standard 10th Edition) is good for, what it is not good for, and where it sits as an enterprise-architecture framework.
- TOGAF Version HistoryEvolution from TAFIM (US DoD, early 1990s) through TOGAF 1 (1995), 8 (Enterprise Edition, 2002), 9 (major restructure, 2009), 9.1 (2011), 9.2 (2018), to the Standard 10th Edition (2022).
- TOGAF vs Other EA FrameworksHow TOGAF relates to the other enterprise-architecture frameworks and notations: Zachman (taxonomy), FEAF / DoDAF (government / defence), ArchiMate / IT4IT (companion notations), Gartner EA (consulting approach), and the agile-EA contenders.
- UN R155 CSMS and R156 SUMSCSMS certificate prerequisite to type approval.
- UN R155 R156UN Regulations 155 and 156.
- UN R155 R156 anchorsAvailable via UNECE website (free).
- UN R155 R156 ControversiesRegulations focused on type-approval.
- UN R155 R156 positionUN R155 R156 position, from the knowledge vault.
Tickets 11
Issues on the board, open first, as of the last build.
- #40 CI check: generated pages match their sources
- #39 Toil: the bot commit on main forces a rebase before every push
- #27 Gate check for docs owner and review dates (open decision)
- #26 Security headers
- #25 Retention statement for the metrics and log stores
- #12 security.txt
- #11 Privacy notice on all three sites
- #10 Impressum on all three sites
- #17 Access model page and public demo banner
- #5 Remove internal host details from the public dashboards
- #4 No third-party requests on page load
Other topics
Built by build_hubs.py from site/topics.yml, the docs labels, the tag pages on the map and the board. Machine-readable: topics.json.