Family Guides

Family Guides

Family guides explain each AWS2-* control family in plain language for readers who need more context than the formal standard draft provides.

Non-normative guidance

Family guides do not create new requirements. They explain purpose, level intent, control detail, evidence examples, and external mapping context for the current working draft.

FamilyGuideFormal standard
AWS2-SCPAWS2-SCP: Scope, Inventory, And OwnershipCandidate requirements
AWS2-DELAWS2-DEL: Delegation, Authority, And IdentityCandidate requirements
AWS2-WSBAWS2-WSB: Workspace And Execution BoundariesCandidate requirements
AWS2-RUNAWS2-RUN: Runtime Policy, Approvals, And Action ControlCandidate requirements
AWS2-SRCAWS2-SRC: Skill, Tool, And Connector Source TrustCandidate requirements
AWS2-CTXAWS2-CTX: Context, Memory, And Instruction Boundary ControlCandidate requirements
AWS2-SECAWS2-SEC: Secrets, Credentials, And Sensitive Data HandlingCandidate requirements
AWS2-LOGAWS2-LOG: Logs, Receipts, And TraceabilityCandidate requirements
AWS2-VALAWS2-VAL: Validation, Testing, And ReviewCandidate requirements
AWS2-GOVAWS2-GOV: Governance, Exceptions, And Change ManagementCandidate requirements

How to use these guides

  • Start with the guide when you need purpose, level intent, control rationale, and evidence examples.
  • Use the formal standard draft when you need candidate requirement text, levels, and normative wording.
  • Treat levels as cumulative: Level 2 builds on Level 1, and Level 3 builds on both.
  • Use external mapping notes as context, not as a replacement for the formal standard draft.