Skip to content

Standard Template

Describe the problem and what this standard intends to prevent/enable.

List the axiom IDs this standard supports (e.g., A2, A3, A5), and a brief rationale.

  • System types in scope
  • Risk tiers (Tier 0–3)
  • Stakeholders (operators, developers, deployers, auditors)

Add only the definitions needed to interpret this standard. Prefer referencing 00_foundations/definitions.md over redefining terms.

Use MUST/SHOULD/MAY statements. Prefer numbered requirements.

Describe tier-specific expectations, controls, and escalation triggers (Tier 0–3). Avoid duplicating requirements unless necessary.

State what evidence an auditor can verify (artifacts, logs, tests, controls).

Document important technical, organizational, and legal limits that affect compliance or interpretation.

Identify likely future updates, open problems, and planned extensions without creating speculative obligations.

Explain the ethical/technical reasoning and tradeoffs.

Appendix B (Non-normative): Failure Modes & Abuse Cases

Section titled “Appendix B (Non-normative): Failure Modes & Abuse Cases”

List likely failure modes, misuse, and how requirements mitigate them.

Track major changes and migration notes.