2. Normative References
2.1 Normative References
- RFC 2119 — Key words for use in RFCs to Indicate Requirement Levels
- RFC 8174 — Leiba, B., “Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words”, BCP 14, RFC 8174, May 2017.
2.2 Informative References
These standards are referenced for context and alignment but are not normatively invoked by this Standard.
-
ISO 9001:2015 — Quality management systems — Requirements
-
ISO/IEC 25010:2023 — Systems and software Quality Requirements and Evaluation — Product quality model
-
SAFe 6.0 — Scaled Agile Framework (Scaled Agile, Inc.)
-
Scrum Guide — The Scrum Guide (Schwaber & Sutherland, 2020)
-
Kanban Method — Kanban: Successful Evolutionary Change for Your Technology Business (Anderson, 2010)
-
DORA Metrics — Accelerate: The Science of Lean Software and DevOps (Forsgren, Humble & Kim, 2018)
-
ISO/IEC 12207:2017 — Systems and software engineering — Software life cycle processes
-
IEEE 29148:2018 — ISO/IEC/IEEE 29148:2018, Systems and software engineering — Life cycle processes — Requirements engineering.
-
CMMI — CMMI Institute, “CMMI for Development, Version 2.0”, 2018.
Supply chain, provenance, and attestation
This layer answers what produced an artifact and how a statement about it is encoded. This standard consumes such statements as evidence (Section 8.6) and does not define their format.
- SLSA — Supply-chain Levels for Software Artifacts (OpenSSF). Governs the provenance of an artifact — what built it, from which sources, under which isolation. Adjacent to Section 8.6(d): SLSA answers where an artifact came from, Section 8.6(d) requires that a verdict be bound to a digest the relying party measured.
- in-toto Attestation Framework — (OpenSSF/CNCF). Governs the shape of an attestation: subject, predicate type, and payload for a statement about an artifact. Section 8.6 requires evidence to correspond to state; it does not require this or any other envelope.
- DSSE — Dead Simple Signing Envelope (Secure Systems Lab / OpenSSF). Governs the signing envelope for such statements. Same boundary as above.
- W3C PROV-DM — Provenance Data Model (W3C Recommendation). A deliberately general meta-model for recording provenance; it leaves the semantics of verification to the consuming domain. It records what happened; it does not state when a verdict may be issued.
- W3C Verifiable Credentials Data Model — (W3C Recommendation). Governs typed, signed attestations about identity and claims. Adjacent as a document format; it does not specify a verification operation against a measured state.
AI system governance and V&V planning
This layer governs an AI system as a product, or the planning of verification, rather than the production of engineering artifacts by an agent.
- ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system. Governs the AI system an organization builds and operates as a product, through a management system with annexed controls. Producer and product are the other way round from the case this standard addresses.
- NIST SP 800-218 — Secure Software Development Framework (SSDF), Version 1.1.
- NIST SP 800-218A — SSDF Community Profile for Generative AI and Dual-Use Foundation Models. Addressees are named in the profile itself: producers of models, producers of systems built on them, and acquirers. Artifacts produced by an agent, and the placement of a control over that production, are outside its stated scope.
- IEEE 1012-2024 — IEEE Standard for System, Software, and Hardware Verification and Validation. Governs V&V planning by integrity level; the 2024 revision states applicability to systems built on generative AI. It leaves the placement of a control and the form of evidence open to the adopting organization.
NOTE: The full normative texts of ISO/IEC 42001:2023 and IEEE 1012-2024 are paid publications. Their treatment here is based on published structure, control titles, and public analyses, and no claim is made in this standard about the content of their individual clauses.