Skip to harness content
Open technical reference map

Production domain 08

Security & Data Protection

3 capabilities and 3 controls define the canonical obligation set for this domain.

Domain 08Dependencies: none
Canonical pathcontrols/production-layers.v2.jsonRevision69bab1cInspect source

Applicability and claim boundary

This domain defines obligations. It does not prove that a specific repository or run satisfies them.

Applicability
Assess this domain when the authorized workload can affect its capabilities. Resolve every control as required, potentially affected, or not applicable before completion.
Proof level
The accepted formats below identify possible evidence inputs. A format alone does not establish semantic or authoritative assurance; provenance and the commissioned proof contract set the supported level.
Claim boundary
Static controls are requirements, not execution evidence, provider attestation, or proof of production readiness.

Capabilities

threat-management

Threat Management

Maintain current assets, boundaries, threats, and mitigations.

secret-management

Secret Management

Keep secrets out of source and under governed storage and rotation.

vulnerability-management

Vulnerability Management

Find, triage, and remediate vulnerabilities within policy.

Controls

SEC-THREAT-001Threat Management

Assets, trust boundaries, threats, and mitigations are current.

Accepted evidence format: Artifact, Provider report
SEC-SECRETS-001Secret Management

Secrets are absent from source and use governed storage and rotation.

Accepted evidence format: Command output
SEC-VULNERABILITY-001Vulnerability Management

Known vulnerabilities are scanned, triaged, and remediated by SLA.

Accepted evidence format: Command output