NIST AI 600-1: register the framework and transcribe its 211 suggested actions - #187
Open
Prasad-desh wants to merge 6 commits into
Open
Prasad-desh wants to merge 6 commits into
Prasad-desh wants to merge 6 commits into
Conversation
…gistry (refs GenAI-Security-Project#119) Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this PR changes
Adds NIST AI 600-1 (the AI RMF Generative AI Profile) as a framework registry. Refs #119 — the agent-safe half of that ticket: registration and transcription only. No mapping rows are asserted, and no vulnerability IDs are affected. Which suggested action addresses which entry is security judgment (C4) and belongs to a framework-owner reviewer per STRAT-04.
data/frameworks/nist-ai-600-1.json— 211 suggested actions across 49 AI RMF subcategories.control_idis the document's own Action ID,descriptionthe Suggested Action verbatim,parentthe AI RMF subcategory (resolves againstnist-ai-rmf.json).inventory_completeness: complete, 211 of 211data/framework-sources.json— registered,current_version: "2024-07"scripts/control-ids.js— id grammar^(?:GV|MP|MS|MG)-\d{1,2}\.\d{1,2}-\d{3}$, socheckControlIdShapes()covers it from day onescripts/control-ids.test.mjs— three tests, one asserting all 211 registry ids satisfy the grammarscripts/exports.test.mjs— see Notes for reviewersdata/stats.json,docs/frameworks-registry.js, README markersType of change
Source / evidence
NIST AI 600-1, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, July 2024 — https://doi.org/10.6028/NIST.AI.600-1
Every control id and description is transcribed from the suggested-action tables of that document.
Checklist
Content
data/frameworks/*.jsonLinks & data
.mdlinks resolve — no.mdfiles changeddata/schema.jsoncompatible — the registry validates againstdata/framework-schema.json; no new entry typeProject hygiene
changelogblock; no mapping file was modifiedCHANGELOG.mdupdated — conditional on a new mapping file, which this isn't. Happy to add an[Unreleased]note if you'd prefer, given the AISVS entry there mentions its registryREADME.mdcounts updated — file count unchanged; the freshness marker moved 4 current → 5 vianpm run statsnpm run buildpasses andvalidate.jsis clean and unchanged from a clean clone of this baseFor new mapping files only
N/A — no mapping file is added.
Notes for reviewers
Test suite.
npm testis 92/92 on this branch. A clean clone of this base is 89/89, so the three added tests pass and nothing regresses.npm run buildis deterministic across two runs, andgit statusshows only the intended files.Why
exports.test.mjschanged.prose-shaped control ids do not spread beyond the known setruns an OSCAL export for every file indata/frameworks/, butcompliance-report.jsresolves--frameworkfrom the names the mappings cite. A registry nothing maps is therefore not found, and the test failed with No framework matching "NIST AI 600-1". Since #119 requires a registry with no mappings, the two cannot both hold. The fix skips registries nothing references, with the reasoning in a comment; it exempts no framework that does produce a prose id, and it currently skips exactly one registry. Happy to solve it the other way if you would rathercompliance-report.jsemit an empty catalog.One transcription detail. A pattern match over the PDF finds 212 ids, but
GV-1.1-002appears only in the explanation of the Action ID scheme ("GV-1.1-002 corresponds to the second suggested action for Govern 1.1"). GOVERN 1.1 has exactly one action; the tables define 211. It is recorded ininventory_completenessso it does not get re-added later.Two calls to confirm or overrule.
titleis derived mechanically — first sentence when it is 120 characters or fewer, else the leading clause, else a word-boundary cut — with the verbatim text always indescription. Nothing is authored, but the rule is mine.nist-ai-rmf.jsonand appear here only asparentvalues. Including them would add 49 non-actions to the denominator thatinventory-completeness.jsexists to protect. CIS does carry its parents (henceREGISTRY_EXTRA_SHAPES), so precedent could cut the other way.The last scope bullet of #119 is omitted. "Prepare the empty mapping file(s) under the four source lists with the schema v2 columns in place" cannot be met as written:
validate.jsenforcesREQUIRED_SECTIONSon every mapping file (Why, Quick-reference, Audience, a per-entry###, References), so three stubs carrying only the v2 header produced 16 errors. A mapping file cannot exist without authored prose, which is what the ticket rules out. Left out to keep the branch green — happy to add them with the required sections filled if you would rather have the scaffolding. Also worth notingast-top10holds only MAESTRO, so "the four source lists" is three files in practice.Branch name is
nist-ai-600-1rather than thefeat/form in CONTRIBUTING; it was committed through the web UI before I reread the guide. Say the word and I will redo it on a renamed branch.Transcription and verification done with AI assistance; I reviewed the diff and ran the build, validators and test suite locally.