Skip to main content

External Framework Candidate Directory

Purpose

This directory makes the full external-framework observatory scope visible.

The main External Frameworks index contains registered pages, crosswalks, mappings, fixtures, and internal mirror records. This directory contains the additional source-required candidates that are already documented in the expanded intake registry but do not yet have full framework pages.

registered page != intake candidate
intake candidate != sourced framework
source required != rejected
candidate visibility != validation
candidate directory != execution authority

Current Coverage

registered framework and crosswalk entries: 19
additional source-required candidates: 42
total visible observatory entries: 61
intake classes represented: 10

The total is a discovery and work-planning count. It is not a framework ranking, compatibility score, certification count, or validation claim.

Policy As Code

CandidateStatusIntended Intake Role
Open Policy Agentsource_requiredPolicy-as-code and authorization decision point candidate.
Cedar Policysource_requiredAuthorization policy language candidate.
Regosource_requiredPolicy language candidate for rule mapping.

Identity And Authority

CandidateStatusIntended Intake Role
SPIFFE/SPIREsource_requiredWorkload identity and trust-domain candidate.
OpenID Connectsource_requiredIdentity assertion and authentication-context candidate.
OAuth 2.0source_requiredDelegated authorization candidate.
W3C Decentralized Identifierssource_requiredDecentralized identity candidate.
W3C Verifiable Credentialssource_requiredCredential proof and claim-evidence candidate.

Provenance And Trace

CandidateStatusIntended Intake Role
in-totosource_requiredSupply-chain provenance and layout-verification candidate.
SLSAsource_requiredSoftware supply-chain assurance candidate.
Sigstoresource_requiredArtifact signing and transparency-log candidate.
OpenLineagesource_requiredData-lineage and reconstruction candidate.
W3C PROVsource_requiredProvenance-model candidate.

Risk And Assurance

CandidateStatusIntended Intake Role
NIST Cybersecurity Frameworksource_requiredCybersecurity risk-management candidate.
NIST SP 800-53source_requiredSecurity and privacy controls candidate.
NIST SP 800-207 Zero Trust Architecturesource_requiredZero-trust architecture candidate.
SOC 2source_requiredAssurance and control-reporting candidate.
Cloud Security Alliance CCMsource_requiredCloud control-matrix candidate.
NIST Secure Software Development Frameworksource_requiredSecure-development lifecycle candidate.
OSCALsource_requiredMachine-readable control and assessment candidate.
AI Verifysource_requiredAI testing and governance toolkit candidate.

Threat And Security

CandidateStatusIntended Intake Role
STRIDEsource_requiredThreat-modeling candidate.
MITRE ATT&CKsource_requiredAdversarial-technique knowledge candidate.
MITRE D3FENDsource_requiredDefensive-technique knowledge candidate.

Privacy And Data Governance

CandidateStatusIntended Intake Role
GDPRsource_requiredPrivacy and consent-governance candidate.
NIST Privacy Frameworksource_requiredPrivacy risk-management candidate.
ISO/IEC 27701source_requiredPrivacy information-management candidate.

Model Evaluation And Monitoring

CandidateStatusIntended Intake Role
Model Cardssource_requiredModel documentation and intended-use candidate.
Datasheets for Datasetssource_requiredDataset documentation and provenance candidate.
MLCommons AI Safetysource_requiredAI safety-evaluation candidate.
HELMsource_requiredModel-evaluation benchmark candidate.
garaksource_requiredLLM vulnerability-scanning candidate.
promptfoosource_requiredLLM evaluation and regression-testing candidate.

Runtime Governance

CandidateStatusIntended Intake Role
Guardrails AIsource_requiredLLM output-validation and guardrail candidate.
Llama Guardsource_requiredLLM safety-classifier candidate.
NeMo Guardrailssource_requiredLLM guardrail and conversation-control candidate.

Agent Protocols

CandidateStatusIntended Intake Role
Agent2Agent Protocolsource_requiredAgent-interoperability protocol candidate.
Model Context Protocolsource_requiredTool and context protocol candidate.
OpenAPIsource_requiredTool-contract and API-description candidate.

Regulatory And Standards

CandidateStatusIntended Intake Role
OECD AI Principlessource_requiredInternational AI-governance principle candidate.
UNESCO Recommendation on AI Ethicssource_requiredInternational AI-ethics framework candidate.
NIST AI RMF Generative AI Profilesource_requiredGenerative-AI risk-profile candidate.

Promotion Path

Each candidate remains in source_required until the existing promotion gates are satisfied:

canonical source
source version or publication date
published scope
published non-claims or bounded StegVerse non-claims
artifact type
relationship class
benchmark relevance
authority boundary
evidence posture

After those gates, a candidate may move through:

source_required
-> sourced_intake
-> page_candidate
-> mapping_candidate
-> fixture_candidate

No candidate is promoted solely because it appears in this directory.

Non-Claims

This directory does not certify external frameworks.
This directory does not claim that all candidates are comparable.
This directory does not claim compatibility with StegVerse.
This directory does not grant execution authority.
This directory does not turn an unsourced candidate into usable evidence.

Candidate visibility is observatory work. Standing must still be reconstructed from current source, evidence, authority, policy, delegation, admissibility, and commit-time conditions.