registrystack / registrystack/registry-stack

Publish a DPI Safeguards-aligned coverage profile with honest enforcement status

Aperta
#595 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
area:docs area:platform area:registryctl area:relay criticality:p2 documentation enhancement post-1.0 triage:roadmap
Lingua principale
Rust
Stelle
2
Fork
0
Merge medio
2h 55m
PR unite (30g)
130

Descrizione

Tracked by #590. Depends on #593. Runtime-enforced outcomes also depend on #594.

## Outcome

Registry Stack publishes a versioned, reviewable DPI Safeguards-aligned profile that maps relevant framework requirements to concrete Registry Stack controls, external operator responsibilities, or explicit unsupported gaps without inventing a `dpi:` field taxonomy or claiming blanket compliance.

## Requirements

- Pin the exact DPI Safeguards framework source, version, retrieval provenance, and content digest used by the profile.
- Separate framework safeguards from semantic concepts and privacy classification vocabularies.
- Map only requirements relevant to Registry Stack's bounded responsibilities.
- For each mapping, record the safeguard reference, interpretation, applicable product surface, expected evidence, owner, and one status:
- `enforceable`
- `declared_external`
- `unsupported`
- `not_applicable` with rationale
- Bind `enforceable` entries to stable safeguard-profile rule IDs and concrete implementation tests or runtime evidence.
- Keep organizational controls, legal determinations, retention operations, human oversight, and other external responsibilities visibly outside runtime enforcement when Registry Stack cannot prove them.
- Produce a deterministic coverage report from the selected Registry Stack release, enabled features, semantic/classification profiles, and safeguard profile.
- Prevent report-only configuration, descriptive metadata, or an unverified classification from being presented as enforced.
- Include a review and update procedure for new framework versions and changed Registry Stack capabilities.

## Acceptance criteria

- [ ] Every included safeguard has an exact source reference and one unambiguous status.
- [ ] Every `enforceable` claim points to a stable rule ID, enforcement point, and passing evidence.
- [ ] External and unsupported responsibilities remain visible in generated output.
- [ ] No mapping treats `DPI Safeguards`, `HIPAA`, `GDPR`, or another regime name as an inherent field classification.
- [ ] The generated report is deterministic, bounded, versioned, and digest-covered.
- [ ] Documentation states that the profile is implementation coverage evidence, not a legal compliance certification.
- [ ] An independent policy/security review finds no unsupported enforcement claim.

## Non-goals

- A universal compliance engine
- Automated legal-basis or jurisdiction decisions
- Runtime interpretation of mutable framework web pages
- Replacing institution-specific risk assessment, approvals, or operating procedures
- Making every DPI Safeguards principle a Relay runtime feature

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

La issue non indica file, test o punti di ingresso. Inizia esaminando le dipendenze in #590, #593 e #594 e le convenzioni esistenti del repository per profili ed evidenze. Il lavoro è completato quando un report di coverage versionato e deterministico soddisfa ogni criterio di accettazione elencato, è stata effettuata una revisione indipendente di policy/security e non vengono fatte affermazioni di enforcement non supportate.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
rust
Ambito
documentation, security
Tipo di issue
Funzionalità
Difficoltà
5/5
Tempo stimato
Più di una settimana
Stato di attività
Tranquilla
Chiarezza
Abbastanza chiara
Idoneità per principianti
25/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.