GSWG Glossary
A
acquired trust #assurance#gswg

Trust gained through direct experience.

version 4, commit a8d8630, created 2021-11-15, last modified 2021-11-20, contributors ScottPerryCPA - Drummond Reed

C
controlled document #gswg

A component document of a governance framework that follows the modular architecture of the ToIP governance metamodel. All controlled documents must be listed in the primary document.

version 1, commit 05f7784, created 2021-11-16, contributors Drummond Reed

cryptographic trust #assurance#gswg

Trust based on reliance on cryptography for assurance about the relationship between public and private keys in a public key infrastructure (PKI).

version 4, commit d686412, created 2021-11-16, last modified 2021-11-21, contributors Drummond Reed - ScottPerryCPA

D
direct trust #assurance#gswg

In a [trust relationship] between a subject and an object, direct trust derives from the subject’s direct experience with the object and not through any other [party].

version 2, commit 93cd757, created 2021-11-21, last modified 2021-11-21, contributors Drummond Reed

G
governance framework #gswg

A set of business, legal, and technical [definitions], [policies], [specifications], and contracts by which the members of a trust community agree to be governed in order to achieve their desired objectives. ToIP-compliant governance frameworks follow the ToIP governance metamodel.

version 1, commit 2b59d06, created 2021-12-02, contributors Drummond Reed

H
human auditable requirement #gswg#reqs

A requirement expressed in a human language that can only be fulfilled by a human actor performing a set of processes and practices against which conformance can only be tested by an auditor of some kind. In a ToIP-compliant governance framework, human-auditable requirements are expressed as policies.

version 2, commit ae68cd5, created 2021-11-20, last modified 2021-11-21, contributors Drummond Reed

I
inherent trust #assurance#gswg

Trust that stems from our acceptance of the innate laws of nature and established social norms. Inherent trust is not controllable from a risk mitigation standpoint; it just exists.

version 2, commit 5358dbd, created 2021-11-15, last modified 2021-11-20, contributors ScottPerryCPA - Drummond Reed

K
keyword #gswg#reqs

A specified word used to define normative requirements. The ToIP Governance Metamodel Specification specifies that all requirements MUST be expressed using RFC 2119 keywords spelled in ALL CAPITALS.

version 1, commit d8449ef, created 2021-11-21, contributors Drummond Reed

M
machine testable requirement #gswg#reqs

A requirement written in a machine-readable format such that conformance of a software actor implementing the requirement can be tested by an automated test suite or rules engine. In a ToIP-compliant governance framework, machine-readable requirements are expressed as rules in a rules-based language.

version 3, commit 991de00, created 2021-11-20, last modified 2021-11-21, contributors Drummond Reed

mandatory #gswg#reqs

A requirement expressed using one of the following RFC 2119 keywords: "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT".

version 1, commit b5f2b5a, created 2021-11-20, contributors Drummond Reed

N
non transitive trust #assurance#gswg

The trust conveyed within the boundaries of an ecosystem.

version 5, commit 413de7c, created 2021-11-20, last modified 2021-11-21, contributors Drummond Reed - ScottPerryCPA

O
option #gswg#reqs

A requirement expressed using one of the following RFC 2119 keywords: "MAY", "OPTIONAL".

version 1, commit 0eab121, created 2021-11-20, contributors Drummond Reed

P
policy #gswg#reqs

A human-auditable requirement that specifies some set of processes and practices that an actor must follow in order to be in conformance with the requirement.

version 2, commit 2c76a2e, created 2021-11-20, last modified 2021-11-20, contributors Drummond Reed

practice #gswg#reqs

A specified activity that an actor must perform as part of a process.

version 3, commit 1225e95, created 2021-11-20, last modified 2021-11-20, contributors ScottPerryCPA - Drummond Reed

primary document #gswg

The starting point document ("home page") of a governance framework that follows the modular architecture of the ToIP governance metamodel. In this metamodel, the primary document is required to include a list of all other controlled documents.

version 2, commit 6991377, created 2021-11-16, last modified 2021-11-20, contributors Drummond Reed

process #gswg#reqs

A specified set of actions that an actor must take in order to be in conformance with a policy. A process may consist of a set of practices.

version 4, commit a543e56, created 2021-11-20, last modified 2021-11-20, contributors ScottPerryCPA - Drummond Reed

R
recommendation #gswg#reqs

A requirement expressed using one of the following RFC 2119 keywords: "SHOULD", "SHOULD NOT", "RECOMMENDED".

version 2, commit 9e6c28e, created 2021-11-20, last modified 2021-11-20, contributors ScottPerryCPA - Drummond Reed

referential trust #assurance#gswg

Trust established through a trustworthy intermediary transferring trust upon a third party.

version 3, commit 59b8520, created 2021-11-16, last modified 2021-11-20, contributors ScottPerryCPA

requirement #gswg#reqs

In the context of a governance framework (GF), a requirement states a condition that an actor (human or machine) must meet in order to be in conformance. This condition may be stated as either a policy (a human-auditable requirement) or a rule (a machine-testable requirement). A requirement may be either a mandatory, a recommendation, or an option.

version 5, commit 0b03576, created 2021-11-20, last modified 2021-11-20, contributors Drummond Reed

rule #gswg#reqs

A machine-testable requirement written in a machine-readable language that can be processed by a rules engine.

version 2, commit 85d091a, created 2021-11-20, last modified 2021-11-20, contributors Drummond Reed

S
specification #gswg#reqs

A document or set of documents containing any combination of human-auditable requirements and machine-testable requirements needed to produce interoperability amongst implementations of the specification. A specification may be included directly in a governance framework as a controlled document or it may be referenced via a permalink.

version 2, commit fbc02fd, created 2021-11-21, last modified 2021-11-22, contributors Drummond Reed

specification profile #gswg#reqs

A particular type of specification that defines requirements for using another specification.

version 1, commit 0b9fae8, created 2021-11-22, contributors Drummond Reed

T
transitive trust #assurance#gswg

In a [trust relationship] between a subject and an object, transitive trust does not derive from the subject’s direct experience with the object, but from the subject’s experience with another party that has direct experience with the object.

version 1, commit b51775d, created 2021-11-21, contributors Drummond Reed