Appendices

Appendix B: Control Family Summary

Working draft

This page renders the current aws2 working draft. It is not a released standard, certification program, compliance framework, legal analysis, endorsement, or public conformance claim.

IDFamilyPrimary evidence examplesLevel 1 focusLevel 2 focusLevel 3 focus
AWS2-SCPScope, inventory, and ownershipscope record, inventory export, owner matrix, intended-use note, component mapnamed boundary, owners, data/context sources, and exclusionsrepeatable inventory, boundary review, and claim-scope reviewhistorical scope records and drift review
AWS2-DELDelegation, authority, and identityauthority model, agent identity record, role matrix, authorization tests, approval recordsdocumented authority paths and execution/approval rolesleast privilege, approval expectations, and recorded high-impact identity contextseparation of execution and approval authority
AWS2-WSBWorkspace and execution boundariesresource inventory, sandbox config, egress policy, boundary testsreachable resources, execution capabilities, and boundary exclusionsscoped production access, egress limits, monitoring, and review for broad impactvalidated boundary enforcement, bypass monitoring, and retained boundary evidence
AWS2-RUNRuntime policy, approvals, and action controlruntime policy, allowlists, approval receipts, denied-action logs, mediation testshigh-impact actions, policy gates, and runtime decision capabilitiesenforced approval gates, recorded outcomes, interruption, rollback, and budget controlspre-execution mediation, recurring policy-path tests, and stronger record integrity
AWS2-SRCSkill, tool, and connector source trustsource register, source-trust profile record, permission declarations, version pins, update receipts, drift testsinventory, origin records, requested permissions, and dependency chainreviewed updates, provenance records, source-trust profile records, and runtime-version drift checksintegrity controls, high-impact source review, rollback or retirement path
AWS2-CTXContext, memory, and instruction boundary controlcontext inventory, precedence rules, memory policy, retrieval inventory, boundary testsknown context sources, trust relationships, and prohibited storage locationscontrols on lower-trust override, memory writes, redaction, and durable context attributionpoisoning tests, material change records, and isolation for high-risk workflows
AWS2-SECSecrets, credentials, and sensitive data handlingsensitive-location inventory, entitlement review, redaction policy, export receipts, denied-exfiltration testssensitive locations, prohibited storage, and sensitive-export action classesleast-privilege access, approval for sensitive movement, and redaction or derived evidencevalidated secret handling, retained redaction/export evidence, and enterprise-control integration where applicable
AWS2-LOGLogs, receipts, and traceabilitylog inventory, receipt schema, sampled receipts, retention policy, reconstruction testsrecorded events, receipt format, and redaction expectationsretained attributable records, structured exports, and sensitive-data-safe review packetsprotected logs, integrity controls, high-impact workflow reconstruction, and monitoring linkage
AWS2-VALValidation, testing, and reviewvalidation plan, control coverage matrix, policy tests, adversarial summary, monitoring review, findings trackerscoped validation methods, review artifact, and gap recordpre-production tests, human oversight review, logging/sensitive-data review, and remediation trackingrecurring validation, independent review, adversarial/tabletop testing, and drift review
AWS2-GOVGovernance, exceptions, and change managementowner record, exception register, adoption gate, supplier due-diligence record, claim-limit recordgovernance owner, exception record, and conservative claim posturereview triggers, exception expiry, coordinated expansion, and external mapping reviewseparated review, governance procedure exercises, and formal reassessment triggers