# First Non-NIST Current/Public Source Verification And Enablement Plan V01

Issue: current owner ticket. No GitHub issue is created by this PR.

Status: SSDF-only PR-preparation authorization and verification planning. This PR does not enable production current retrieval, authorize production activation, or change runtime configuration.

## Purpose

Prepare the governed verification and staged enablement plan for the first non-NIST-AI-RMF current/public source batch for Package + current context.

Option A is selected as the first enablement batch: governance and security guidance.

This plan does not promote any current/public source to approved package authority. It does not approve tools, models, vendors, workflows, data classes, regulated use, production use, or enterprise policy.

## Existing Runtime Posture To Preserve

Current production-enabled public/current source remains `nist-ai-rmf-public-framework-candidate`.

All other current/public sources remain candidate-only unless already otherwise configured before this branch.

NIST SSDF is proposed only as the first staged non-NIST-AI-RMF current/public source for later runtime exposure.

NIST SSDF remains current/public context only.

NIST SSDF is not package authority.

NIST AI RMF and NIST SSDF must remain semantically distinct.

Package-only remains the default.

Package-only must not cite NIST SSDF.

Package + current context remains explicit and package-first.

Package + current context may cite NIST SSDF only after merge, deployment, and authorized runtime exposure.

Current/public context remains separate from approved package authority.

All provider calls remain server-side through `/api/source-grounded-chat`.

Direct browser provider calls and browser-side current-source fetches must remain zero.

## Selected First Batch

1. NIST SSDF SP 800-218 final v1.1.
2. OWASP GenAI Security Project / 2025 GenAI Top 10.
3. CISA / NSA / NCSC secure AI guidance, exact-document or exact-path scope only.

Regulated life sciences / GxP / medical device sources are not selected for this batch.

## SSDF-Only Preparation Status

This branch prepares only the first stage:

- NIST SSDF SP 800-218 final v1.1.

This branch does not authorize or prepare runtime enablement for:

- NIST SP 800-218 Rev. 1 Initial Public Draft
- OWASP GenAI 2025 Top 10
- CISA / NSA / NCSC secure AI guidance
- regulated-life-sciences sources
- standards or paywalled sources
- broad NIST, CSRC, OWASP, CISA, NSA, NCSC, or partner-domain crawling
- arbitrary web search
- user-provided URL retrieval

The SSDF owner authorization record is `current_source_owner_authorization_nist_ssdf_v01.json`.

The runtime config-change receipt is `AI_Capability_Playbook_NIST_SSDF_CURRENT_SOURCE_RUNTIME_ENABLEMENT_PREP_2026-06-25.md`.

External Cloudflare env/config mutation remains pending later explicit authorization.

## Verification Matrix

Last verified date for this matrix: 2026-06-25.

Verifier: Codex, using direct official-source probes only.

| Source ID | Source name | Source class | Canonical publisher | Exact URL | Origin | Allowed path prefix | Content type | Version/date | Public/fetchable status | License/public-use notes | Robots/rate-limit notes | Last verified date | Verifier | Explicit exclusions | Production enablement sequence | Enablement status |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `nist-ssdf-sp-800-218-candidate` | NIST Secure Software Development Framework SP 800-218 final v1.1 | `security_ai_safety_framework_source` | NIST Computer Security Resource Center | `https://csrc.nist.gov/pubs/sp/800/218/final` | `https://csrc.nist.gov` | `/pubs/sp/800/218/final` | `text/html; charset=utf-8` | SP 800-218 final, version 1.1, February 2022 | HTTP 200 public HTML, no login observed | Public NIST publication page. Current/public context only, not package authority. | CSRC `robots.txt` probe redirected to CSRC home HTML in this environment. Use exact path only, no broad CSRC crawling, low-rate retrieval only. | 2026-06-25 | Codex | NIST SP 800-218 Rev. 1 Initial Public Draft at `https://csrc.nist.gov/pubs/sp/800/218/r1/ipd`; broad CSRC search; unrelated SP 800-218 drafts; PDF extraction until separately citation-tested. | Verify all three candidates first. Enable this source first only after explicit owner authorization. | Candidate-only. `retrieval_enabled: false`. No authorization in this PR. |
| `owasp-genai-llm-top-10-2025-candidate` | OWASP GenAI Security Project 2025 GenAI Top 10 | `security_ai_safety_framework_source` | OWASP Foundation GenAI Security Project | `https://genai.owasp.org/llm-top-10/` | `https://genai.owasp.org` | `/llm-top-10/` | `text/html; charset=UTF-8` | 2025 Top 10 page. Header last-modified observed 2026-06-24. | HTTP 200 public HTML, no login observed | Public OWASP project material. Current/public security framework context only, not company policy and not package authority. | `robots.txt` allows `User-agent: *` and publishes sitemaps. Use exact path only, no broad genai.owasp.org crawling. | 2026-06-25 | Codex | Ambiguous historical or unversioned "LLM Top 10" naming; earlier versions; broad OWASP project crawl; sibling pages unless separately verified. | Enable only after NIST SSDF passes preview and production smoke. | Candidate-only. `retrieval_enabled: false`. No authorization in this PR. |
| `cisa-nsa-ncsc-secure-ai-system-development-guidelines-candidate` | NCSC/CISA/NSA Guidelines for Secure AI System Development v1.0 | `government_standards_regulator_adjacent_authority` | UK National Cyber Security Centre with CISA, NSA, and international partners | `https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development` | `https://www.ncsc.gov.uk` | `/collection/guidelines-secure-ai-system-development` | `text/html; charset=UTF-8` for the collection page. Official PDF at `https://www.ncsc.gov.uk/files/Guidelines-for-secure-AI-system-development.pdf` is `application/pdf`. | Version 1.0. Published 2023-11-27. Reviewed 2023-11-27. | HTTP 200 public HTML for collection page and HTTP 200 public PDF, no login observed | Public secure-AI guidance. Current/public government cybersecurity context only, not company policy and not package authority. | NCSC `robots.txt` exposes content signals with `search=yes` and `ai-train=no`; no broad crawling. Use exact collection path only. PDF parsing must be citation-tested before any PDF runtime retrieval. | 2026-06-25 | Codex | Broad `cisa.gov`, `nsa.gov`, `ncsc.gov.uk`, partner-domain crawling; CISA AI landing pages; NSA media paths that returned 403 in this environment; CISA guessed resource paths that returned 404; sibling NCSC pages outside the allowed collection path; PDF runtime retrieval until extraction is validated. | Enable only after OWASP passes preview and production smoke. | Candidate-only. `retrieval_enabled: false`. No authorization in this PR. |

## Option A Readiness Matrix Detail

This section expands the verification matrix into the exact fields required before any later source-owner authorization or Cloudflare runtime configuration change.

### Retrieval Identity And Publication Status

| Source ID | Exact canonical URL | Exact fetch URL if different | Publication/current/final/draft status | Verification timestamp | Public/fetchable status |
|---|---|---|---|---|---|
| `nist-ssdf-sp-800-218-candidate` | `https://csrc.nist.gov/pubs/sp/800/218/final` | Same as canonical URL. | SP 800-218 final v1.1 is the only target. NIST SP 800-218 Rev. 1 Initial Public Draft is excluded from production scope. | 2026-06-25T13:32:28Z | HTTP 200 public HTML, zero redirects, no login observed. |
| `owasp-genai-llm-top-10-2025-candidate` | `https://genai.owasp.org/llm-top-10/` | Same as canonical URL. | 2025 GenAI Top 10 target. Historical 2023/24 or ambiguous LLM Top 10 naming is excluded from production scope. | 2026-06-25T13:32:28Z | HTTP 200 public HTML, zero redirects, no login observed. |
| `cisa-nsa-ncsc-secure-ai-system-development-guidelines-candidate` | `https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development` | Same as canonical URL for planned HTML retrieval. The official PDF at `https://www.ncsc.gov.uk/files/Guidelines-for-secure-AI-system-development.pdf` is extraction-pending and not approved for runtime retrieval. | Published version 1.0, publish date 2023-11-27, reviewed 2023-11-27. | 2026-06-25T13:32:28Z | HTTP 200 public HTML, zero redirects, no login observed. Official PDF also returned HTTP 200 `application/pdf`, but is not extraction-ready for runtime. |

### Governance Readiness And Dependencies

| Source ID | Retrieval readiness status | Production enablement status | Package authority status | Owner authorization dependency | Later Cloudflare runtime config dependency | Planned future enablement sequence |
|---|---|---|---|---|---|---|
| `nist-ssdf-sp-800-218-candidate` | Candidate ready for owner review, not enabled. | Not enabled. | Not package authority. | Required before preview or production configuration. | Required later outside this PR. | Stage 1, SSDF first after explicit owner authorization. |
| `owasp-genai-llm-top-10-2025-candidate` | Candidate ready for owner review, not enabled. | Not enabled. | Not package authority. | Required after SSDF smoke passes. | Required later outside this PR. | Stage 2, OWASP after SSDF preview and production smoke. |
| `cisa-nsa-ncsc-secure-ai-system-development-guidelines-candidate` | HTML candidate ready for owner review, not enabled; PDF extraction pending. | Not enabled. | Not package authority. | Required after OWASP smoke passes. | Required later outside this PR. | Stage 3, CISA / NSA / NCSC after OWASP preview and production smoke. |

### Extraction Readiness Notes

| Source ID | Extraction readiness | Extraction exclusions |
|---|---|---|
| `nist-ssdf-sp-800-218-candidate` | HTML page is fetchable and text-like. Before enablement, extraction must confirm title, date, final status, abstract, documentation links, and document-history fields survive snippet generation. | Do not enable PDF extraction or Rev. 1 draft extraction in this stage. Do not crawl CSRC search, related publications, or supplemental files. |
| `owasp-genai-llm-top-10-2025-candidate` | HTML page is fetchable and text-like. Runtime readiness uses inactive repair profile `owasp_genai_2025_bounded_html_extract_v01`, capped at 1048576 response bytes and 4000 snippet characters for the exact OWASP 2025 path only. Before enablement, extraction must preserve the 2025 heading and individual LLM01:2025 through LLM10:2025 anchors. | Do not crawl sibling OWASP pages, 2023/24 archive material, downloads, GitHub, or project-wide resources unless separately verified and authorized. The profile does not enable OWASP by itself and fails closed if required 2025 markers are missing. |
| `cisa-nsa-ncsc-secure-ai-system-development-guidelines-candidate` | HTML collection page is fetchable and text-like. Before enablement, extraction must preserve version 1.0, publish/review dates, page list, lifecycle sections, and CISA/NSA/NCSC partnership context. | Do not enable PDF runtime retrieval until PDF parsing, section anchoring, and citation rendering are separately tested. Do not crawl broad `cisa.gov`, `nsa.gov`, `ncsc.gov.uk`, or partner domains. |

### Citation Readiness Notes

| Source ID | Citation label | Required citation boundary |
|---|---|---|
| `nist-ssdf-sp-800-218-candidate` | NIST SSDF current/public context. | Cite the final v1.1 CSRC page as current/public secure software guidance only. The citation must not imply package authority, company policy, production approval, tool approval, or use of the Rev. 1 draft. |
| `owasp-genai-llm-top-10-2025-candidate` | OWASP 2025 GenAI Top 10 current/public context. | Cite the 2025 GenAI Security Project page as current/public LLM application security guidance only. The citation must not collapse to older or ambiguous LLM Top 10 names. |
| `cisa-nsa-ncsc-secure-ai-system-development-guidelines-candidate` | NCSC/CISA/NSA secure AI guidance current/public context. | Cite only the exact NCSC collection URL for planned HTML retrieval. If the PDF is later authorized, it must render as a separate exact artifact citation after extraction validation. |

### Source-Specific Owner Authorization Drafts

This PR updates the SSDF record for PR-preparation authorization and keeps the remaining Option A records draft-only:

- `current_source_owner_authorization_nist_ssdf_v01.json`
- `current_source_owner_authorization_owasp_genai_2025_v01.json`
- `current_source_owner_authorization_cisa_nsa_ncsc_secure_ai_v01.json`

The SSDF record authorizes only preparation of an unmerged SSDF-only enablement PR.

The SSDF record does not authorize production activation.

The SSDF record does not authorize external Cloudflare env/config mutation in this task.

The SSDF record does not authorize any non-SSDF source.

The OWASP and CISA / NSA / NCSC drafts do not provide authorization.

The records do not set retrieval enabled in repo candidate registries.

The records do not change Cloudflare env/config.

The records do not permit package authority promotion, regulated-source enablement, arbitrary web search, user-provided URL retrieval, browser-side current-source fetches, browser-side provider calls, or telemetry/database/vector/upload/session features.

## Required Production Sequencing

1. Verify all three candidate sources.
2. Enable only NIST SSDF SP 800-218 final v1.1 first, after explicit owner authorization.
3. Run preview and production smoke.
4. Enable OWASP GenAI 2025 Top 10 only after SSDF passes.
5. Enable CISA / NSA / NCSC secure AI guidance only after OWASP passes.
6. Keep all regulated-life-sciences sources candidate-only.

Production enablement is staged, not bulk. Failure at any stage stops the sequence until the source is corrected, excluded, or explicitly reauthorized.

## Future Staged Enablement Boundary

The Option A bundle is readiness-only.

The future sequence is source-by-source:

1. Authorize and configure only NIST SSDF SP 800-218 final v1.1 in preview.
2. Smoke SSDF in preview, then production, with rollback ready.
3. Authorize and configure only OWASP 2025 GenAI Top 10 after SSDF passes.
4. Smoke OWASP in preview, then production, with rollback ready.
5. Authorize and configure only CISA / NSA / NCSC exact-path secure AI guidance after OWASP passes.
6. Smoke CISA / NSA / NCSC in preview, then production, with rollback ready.
7. Stop the sequence on any source failure until the source is corrected, excluded, or explicitly reauthorized.

This boundary does not authorize bulk enablement for the full batch.

This boundary does not authorize any regulated-life-sciences source.

## Owner Authorization Record Template

This PR provides SSDF-only PR-preparation authorization and does not change runtime config.

The SSDF authorization record must remain limited to PR preparation until later merge, deploy, and external config authorization exists.

A future production activation record must record all fields in `current_source_owner_authorization_template_v01.json` before any Cloudflare or deployment configuration change.

Minimum fields:

| Field | Required value |
|---|---|
| `authorization_id` | Unique authorization ID. |
| `authorizer_name` | Human authorizer name. |
| `authorizer_role` | Role accountable for source enablement. |
| `source_ids_authorized` | Exact source IDs authorized for this stage only. |
| `exact_enabled_urls` | Exact URLs authorized for retrieval. |
| `exact_allowed_origins` | Exact allowed origins. |
| `exact_allowed_path_prefixes` | Exact allowed path prefixes. |
| `runtime_env_or_config_variable_to_change` | Runtime env/config variable name, usually `AICD_CURRENT_CONTEXT_SOURCE_REGISTRY_JSON`. |
| `old_runtime_value` | Previous value recorded outside the repository, redacted in any public receipt. |
| `new_runtime_value` | New value recorded outside the repository, redacted in any public receipt. |
| `deployment_target` | Preview or production target. |
| `preview_deployment_reference` | Preview deployment reference. |
| `production_deployment_reference` | Production deployment reference. |
| `smoke_owner` | Person or role accountable for smoke. |
| `rollback_owner` | Person or role accountable for rollback. |
| `approval_timestamp` | Timestamp of owner approval. |
| `approval_reference` | Issue, ticket, signed note, or other approval reference. |
| `post_change_verification_timestamp` | Timestamp after post-change smoke succeeds. |

Authorization must cover only the current stage. It must not imply bulk approval for the rest of the batch.

## Future Cloudflare Change Plan

No Cloudflare change is made in this PR.

Future enablement must:

1. Confirm SSDF-only owner authorization before any runtime change.
2. Record the old runtime source registry value before change without exposing the value in repo files.
3. Apply the new registry value only in preview first after later explicit external config authorization.
4. Preserve server-side provider and retrieval path through `/api/source-grounded-chat`.
5. Run preview smoke and record the result.
6. Promote to production only after preview passes and explicit owner authorization covers production.
7. Record the production deployment reference.
8. Run production smoke and record the result.
9. Keep rollback ready until smoke passes.

Future enablement must not:

- add browser-side current-source fetches
- add browser-side provider calls
- change provider/model config
- change Cloudflare Access/WAF
- expose Cloudflare secret values, account IDs, tokens, provider keys, or production registry values
- store deployment-specific runtime registry JSON in the repository
- enable more than one source per stage

## Smoke Plan

Run this smoke plan for each staged source enablement.

| Check | Expected result |
|---|---|
| Static route smoke | `https://ghostmesh.ai/` and relevant static architecture routes return the expected public or protected status. |
| Source catalog route smoke | Product architecture source catalog routes are reachable. |
| Current-source registry governance route smoke | `docs/product-architecture/current_source_registry_governance.md` route is reachable on the published site. |
| v02 candidate registry JSON route smoke | `docs/product-architecture/current_source_registry_candidates_v02.json` is reachable and valid JSON. |
| Context-pack manifest JSON validity | `context-pack/manifest.json` and `docs/context-pack/manifest.json` parse as JSON. |
| Assistant corpus JSONL parseability | `context-pack/assistant_corpus.jsonl` and `docs/context-pack/assistant_corpus.jsonl` parse line by line. |
| Package-only default behavior | Fresh page load defaults to Package only. |
| Package + current explicit-mode behavior | Current context is used only when Package + current context is explicitly selected. |
| Package-first behavior | Current retrieval runs only after approved package support exists. |
| Citation rendering for enabled current/public source | Current/public citations render separately from package citations with source ID, trust/freshness label, retrieval status, and claim boundary. |
| Canonical source link rendering | Enabled current/public citation links use the exact authorized URL and no broad-domain target. |
| Browser network direct provider check | Browser network evidence shows zero direct provider calls. |
| Browser network direct current-source check | Browser network evidence shows zero direct browser-side current-source fetches. |
| Static secret scan | No high-risk secret pattern appears in changed files or rendered output. |
| Residue scan | No repo-controlled `__pycache__`, `.pyc`, or `.wrangler` residue remains. |

## Rollback Plan

Minimum rollback steps:

1. Restore runtime source registry env/config to the previous value. Current known production baseline is NIST AI RMF only.
2. Redeploy the last known-good commit or trigger a Cloudflare Pages redeploy with the previous config.
3. Confirm current/public registry exposes only the prior enabled source.
4. Confirm package-only default behavior remains unchanged.
5. Confirm Package + current explicit mode works only with authorized enabled sources.
6. Confirm no stale current-source citation appears in assistant responses.
7. Confirm no database, vector store, session, or upload cleanup is required because none exists.
8. Run static secret and residue scans.

Rollback must not require Cloudflare Access/WAF changes.

## Risk Register

| Risk | Control |
|---|---|
| NIST SSDF draft/final confusion | Enable only SP 800-218 final v1.1. Keep SP 800-218 Rev. 1 Initial Public Draft excluded or candidate-only. |
| OWASP version drift | Capture version/date and canonical path. Cite 2025 explicitly. Reverify before enablement. |
| CISA source sprawl | Exact-document or exact-path allowlist only. No broad `cisa.gov`, `nsa.gov`, `ncsc.gov.uk`, or partner-domain crawl. |
| PDF/text extraction artifacts | Parse and citation-test before enablement. Do not enable PDF retrieval until extraction is validated. |
| Authority conflation | Label enabled sources as current/public context, never package authority. |
| Regulated-source overreach | Keep Option B deferred and candidate-only. |
| Rollback ambiguity | Pre-record previous enabled-source config and restore path before production change. |
| Browser-side retrieval regression | Validate browser network calls remain clean: zero direct provider calls and zero direct browser-side current-source fetches. |
| Secret/config exposure | Run static secret scan before PR and do not store secret/config values in repo files. |

## Regulated Batch Disposition

Regulated life sciences / GxP / medical device sources are deferred.

They remain candidate-only.

They remain `retrieval_enabled: false`.

They require a separate verification and enablement plan.

ISPE/GAMP remains industry guidance, not regulation.

Paywalled standards must not be copied or treated as fetchable full text.

No regulated-life-sciences source is package authority.

## Explicit Non-Changes

This PR does not:

- change Cloudflare env/config
- turn on retrieval for any new source
- promote any current/public source to package authority
- enable any regulated-life-sciences source
- add arbitrary web search
- add user-provided URL retrieval
- add browser-side current-source fetches
- add browser-side provider calls
- change provider/model config
- change Cloudflare Access/WAF
- add telemetry, database, vector store, Supabase, uploads, or session attachments
- expose secrets
- start unrelated refactors
- create unrelated issues, branches, PRs, labels, or automation changes
- change existing static production posture

## Acceptance Criteria Mapping

| Criterion | Planned evidence |
|---|---|
| Option A selected | This plan names governance/security as selected batch. |
| Production enablement staged | Required production sequencing enables one source per stage. |
| NIST final distinguished from Rev. 1 draft | Matrix and risk register exclude Rev. 1 draft from enablement. |
| OWASP bound to 2025 GenAI Top 10 | Matrix and v02 row use 2025 naming. |
| CISA/NSA/NCSC exact scope | Matrix and v02 row use exact NCSC collection path and exclude broad domains. |
| Non-selected and unauthorized candidates remain disabled | v02 registry and validator keep candidate-only posture. |
| No Cloudflare/runtime behavior changed | Explicit non-changes and validation receipt record no config change. |
| No package-authority behavior changed | Claim boundaries stay current/public context only. |
