{
  "draft_id": "option-a-cisa-nsa-ncsc-secure-ai-owner-authorization-draft-v01",
  "draft_status": "draft_only_no_authorization",
  "source_id": "cisa-nsa-ncsc-secure-ai-system-development-guidelines-candidate",
  "source_name": "NCSC/CISA/NSA Guidelines for Secure AI System Development v1.0",
  "source_class": "government_standards_regulator_adjacent_authority",
  "publisher": "UK National Cyber Security Centre with CISA, NSA, and international partners",
  "canonical_url": "https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development",
  "fetch_url": "https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development",
  "allowed_origin": "https://www.ncsc.gov.uk",
  "allowed_path_prefix": "/collection/guidelines-secure-ai-system-development",
  "content_type": "text/html; charset=UTF-8",
  "version_or_date": "Version 1.0, published 2023-11-27, reviewed 2023-11-27",
  "publication_current_final_draft_status": "published_version_1_0_exact_collection_target",
  "public_fetchable_status": "HTTP 200 public HTML, zero redirects, no login observed on 2026-06-25; official PDF also returned HTTP 200 application/pdf but is extraction-pending",
  "license_public_use_notes": "Public NCSC-hosted secure AI guidance naming CISA, NSA, and international partners. Use only as current/public government cybersecurity context.",
  "robots_rate_limit_notes": "NCSC robots.txt content signals show search=yes and ai-train=no. Use exact collection path only, no broad government-domain crawling.",
  "verifier": "Codex official-source probe",
  "verification_timestamp": "2026-06-25T13:32:28Z",
  "retrieval_readiness_status": "candidate_ready_for_owner_review_not_enabled_html_only",
  "production_enablement_status": "not_enabled",
  "package_authority_status": "not_package_authority",
  "explicit_exclusions": [
    "broad cisa.gov crawling",
    "broad nsa.gov crawling",
    "broad ncsc.gov.uk crawling",
    "partner-domain crawling",
    "sibling NCSC pages outside exact collection path",
    "PDF runtime retrieval until extraction and citation testing pass"
  ],
  "depends_on_owner_authorization": true,
  "depends_on_later_cloudflare_runtime_config_change": true,
  "planned_future_enablement_sequence": "stage_3_cisa_nsa_ncsc_after_owasp_preview_and_production_smoke",
  "runtime_env_or_config_variable_to_change": "AICD_CURRENT_CONTEXT_SOURCE_REGISTRY_JSON",
  "old_runtime_value": "record_outside_repo_redacted_in_public_receipts",
  "new_runtime_value": "record_outside_repo_redacted_in_public_receipts",
  "authorizer_name": "to_be_supplied",
  "authorizer_role": "to_be_supplied",
  "approval_reference": "to_be_supplied_issue_ticket_or_signed_record",
  "approval_timestamp": "to_be_supplied_iso_timestamp",
  "authorization_scope_notes": "This draft does not provide authorization and does not change runtime config. A later owner record must authorize exactly this source ID, URL, origin, and path prefix after OWASP smoke passes.",
  "cloudflare_config_changed_in_this_pr": false,
  "production_enablement_authorized_by_this_draft": false,
  "retrieval_enabled_by_this_draft": false,
  "package_authority_promotion_allowed": false,
  "regulated_life_sciences_enablement_allowed": false,
  "browser_side_current_source_fetches_allowed": false,
  "browser_side_provider_calls_allowed": false,
  "arbitrary_web_search_allowed": false,
  "user_provided_url_retrieval_allowed": false,
  "telemetry_database_vector_upload_session_attachment_allowed": false
}
