Skip to content

NIST AI 600-1: register the framework and transcribe its 211 suggested actions - #187

Open
Prasad-desh wants to merge 6 commits into
GenAI-Security-Project:mainfrom
Prasad-desh:nist-ai-600-1
Open

Prasad-desh wants to merge 6 commits into
GenAI-Security-Project:mainfrom
Prasad-desh:nist-ai-600-1

Conversation

@Prasad-desh

Copy link
Copy Markdown

What this PR changes

Adds NIST AI 600-1 (the AI RMF Generative AI Profile) as a framework registry. Refs #119 — the agent-safe half of that ticket: registration and transcription only. No mapping rows are asserted, and no vulnerability IDs are affected. Which suggested action addresses which entry is security judgment (C4) and belongs to a framework-owner reviewer per STRAT-04.

  • data/frameworks/nist-ai-600-1.json — 211 suggested actions across 49 AI RMF subcategories. control_id is the document's own Action ID, description the Suggested Action verbatim, parent the AI RMF subcategory (resolves against nist-ai-rmf.json). inventory_completeness: complete, 211 of 211
  • data/framework-sources.json — registered, current_version: "2024-07"
  • scripts/control-ids.js — id grammar ^(?:GV|MP|MS|MG)-\d{1,2}\.\d{1,2}-\d{3}$, so checkControlIdShapes() covers it from day one
  • scripts/control-ids.test.mjs — three tests, one asserting all 211 registry ids satisfy the grammar
  • scripts/exports.test.mjs — see Notes for reviewers
  • Regenerated: data/stats.json, docs/frameworks-registry.js, README markers

Type of change

  • New mapping file
  • Update to existing mapping (content, controls, CVE refs)
  • Bug fix (broken link, typo, incorrect cross-ref)
  • New recipe (shared/RECIPES.md)
  • New tool (shared/TOOLS.md)
  • Infrastructure (scripts, CI, templates)
  • Translation (i18n/)

Source / evidence

NIST AI 600-1, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, July 2024 — https://doi.org/10.6028/NIST.AI.600-1

Every control id and description is transcribed from the suggested-action tables of that document.

Checklist

Content

  • Follows the file template structure — N/A, no mapping file is added
  • Severity ratings consistent with AIVSS / OWASP definitions — N/A, none assigned
  • Cross-references bidirectional — N/A, no mapping file
  • All referenced vulnerability IDs are valid — this PR references none
  • License header present — N/A for JSON registries; shape matches the other data/frameworks/*.json

Links & data

  • All internal .md links resolve — no .md files changed
  • All external URLs return 200 — the one URL added is the NIST DOI above
  • data/schema.json compatible — the registry validates against data/framework-schema.json; no new entry type

Project hygiene

  • Changelog entry added — the registry carries its own changelog block; no mapping file was modified
  • CHANGELOG.md updated — conditional on a new mapping file, which this isn't. Happy to add an [Unreleased] note if you'd prefer, given the AISVS entry there mentions its registry
  • README.md counts updated — file count unchanged; the freshness marker moved 4 current → 5 via npm run stats
  • Ran validation locally — npm run build passes and validate.js is clean and unchanged from a clean clone of this base

For new mapping files only

N/A — no mapping file is added.

Notes for reviewers

Test suite. npm test is 92/92 on this branch. A clean clone of this base is 89/89, so the three added tests pass and nothing regresses. npm run build is deterministic across two runs, and git status shows only the intended files.

Why exports.test.mjs changed. prose-shaped control ids do not spread beyond the known set runs an OSCAL export for every file in data/frameworks/, but compliance-report.js resolves --framework from the names the mappings cite. A registry nothing maps is therefore not found, and the test failed with No framework matching "NIST AI 600-1". Since #119 requires a registry with no mappings, the two cannot both hold. The fix skips registries nothing references, with the reasoning in a comment; it exempts no framework that does produce a prose id, and it currently skips exactly one registry. Happy to solve it the other way if you would rather compliance-report.js emit an empty catalog.

One transcription detail. A pattern match over the PDF finds 212 ids, but GV-1.1-002 appears only in the explanation of the Action ID scheme ("GV-1.1-002 corresponds to the second suggested action for Govern 1.1"). GOVERN 1.1 has exactly one action; the tables define 211. It is recorded in inventory_completeness so it does not get re-added later.

Two calls to confirm or overrule.

  1. Titles. The actions carry no titles, and every other registry's are short (max 62 chars). title is derived mechanically — first sentence when it is 120 characters or fewer, else the leading clause, else a word-boundary cut — with the verbatim text always in description. Nothing is authored, but the rule is mine.
  2. Subcategories not duplicated. The 49 subcategories stay in nist-ai-rmf.json and appear here only as parent values. Including them would add 49 non-actions to the denominator that inventory-completeness.js exists to protect. CIS does carry its parents (hence REGISTRY_EXTRA_SHAPES), so precedent could cut the other way.

The last scope bullet of #119 is omitted. "Prepare the empty mapping file(s) under the four source lists with the schema v2 columns in place" cannot be met as written: validate.js enforces REQUIRED_SECTIONS on every mapping file (Why, Quick-reference, Audience, a per-entry ###, References), so three stubs carrying only the v2 header produced 16 errors. A mapping file cannot exist without authored prose, which is what the ticket rules out. Left out to keep the branch green — happy to add them with the required sections filled if you would rather have the scaffolding. Also worth noting ast-top10 holds only MAESTRO, so "the four source lists" is three files in practice.

Branch name is nist-ai-600-1 rather than the feat/ form in CONTRIBUTING; it was committed through the web UI before I reread the guide. Say the word and I will redo it on a renamed branch.

Transcription and verification done with AI assistance; I reviewed the diff and ran the build, validators and test suite locally.

…gistry (refs GenAI-Security-Project#119)

Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 1, 2026 13:08

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants