This is a living security reference. The seven controls are stable; the numbers, standards, and vendor patterns around them move. When a material shift lands — a revised standard, a new figure, a changed vendor posture — we log the delta below with citations rather than silently rewriting the body. The baseline entry records the assumptions the whole brief rests on.
Three assumptions underpin everything in this brief. If any of them is wrong, the brief is wrong — so we state them plainly and version them. Everything else — the seven controls, the two reference architectures, the diagnostic questions — is downstream of these.
ASSUMPTION
WHAT IT MEANS
STANCE
Trust below the agent
The decisive trust controls live at the data layer — identity, access, delegation, provenance, credentials, inheritance, evidence — not in model behavior. Securing the model is necessary and insufficient.
FOUNDATIONAL
Evidence over assertion
A control counts only if it can be demonstrated against artifacts and live tests — identity documents, real denial logs, bypass resistance — not attested on a questionnaire. Documentation is not demonstration.
FOUNDATIONAL
Continuity over point-in-time
Trust is a posture, not a certificate. In a field that changes monthly, a point-in-time pass ages badly; the audit log itself is the continuous evidence stream (control 07). We evaluate for continuity, not a snapshot.
FOUNDATIONAL
EDITOR'S NOTE
Baseline issue, v1.0. Future entries will log changes to standards (NIST, CSA), vendor data-layer patterns (Microsoft, SAP, frontier labs), and the numeric claims that are tagged throughout — each with a citation and a date. The seven controls and three assumptions above are not expected to change; the evidence around them will.