Standard

Candidate Control Families

Working draft

This page renders the current aws2 working draft. It is not a released standard, certification program, compliance framework, legal analysis, endorsement, or public conformance claim.

This section defines first-pass candidate control families for the working draft. The requirements are intentionally written in normative style so they can be reviewed for clarity and testability, but they remain candidate requirements until a released aws2 version exists.

Each family includes:

  • objective
  • primary layer and typical owner
  • applicability notes
  • candidate Level 1, Level 2, and Level 3 requirements
  • minimum evidence examples
  • mapping notes
  • claim limits

The current candidate requirements have been revised against the completed source-first and family-first crosswalk baseline. They remain working-draft candidate requirements until a released aws2 version exists, and mapping notes in this section remain informative rather than conformance, legal, or certification claims.

IDFamilyPrimary layerTypical owner
AWS2-SCPScope, inventory, and ownershipWorkspace and endpointOrganization or governance
AWS2-DELDelegation, authority, and identityRuntime platformOrganization or governance
AWS2-WSBWorkspace and execution boundariesWorkspace and endpointWorkspace or endpoint
AWS2-RUNRuntime policy, approvals, and action controlRuntime platformRuntime platform
AWS2-SRCSkill, tool, and connector source trustSkill or skill-set sourceSkill or skill-set source
AWS2-CTXContext, memory, and instruction boundary controlRuntime platformRuntime platform
AWS2-SECSecrets, credentials, and sensitive data handlingWorkspace and endpointWorkspace or endpoint
AWS2-LOGLogs, receipts, and traceabilityEvidence and auditEvidence or audit
AWS2-VALValidation, testing, and reviewEvidence and auditEvidence or audit
AWS2-GOVGovernance, exceptions, and change managementOrganization and governanceOrganization or governance