Tenet Governance

The Global Governance Framework

GGF — Comply Once. Report Everywhere.

One control spine above six regimes — NERC CIP, IEC 62443, NIS2, the EU CRA, the EU AI Act, and NERC O&P. One inventory with six classifications. One control library with six crosswalks. One incident record that computes every notification obligation at once.

Built like NERC CIP: requirement language, measures, and evidence — not aspirational outcomes. Structured like the CSF. Scoped like nothing currently published.

NERC CIPIEC 62443NIS2EU CRAEU AI ActNERC O&PGGF · one spine · every clock

LAYER 0 · THE REGIME DATA LAYER

Six regimes, one schema

Each regime is a data object — unit of governance, control corpus, reporting rule, inventory model, spotlight discipline. Adding a seventh regime is a data operation, not a redesign.

NERC CIP

Per Site
Controls
12 core cyber standards, CIP-002→013 (+ CIP-014 physical, CIP-015 INSM)
Reports To
E-ISAC + CISA within 1 hour of determination (CIP-008 R4)
Inventory
BES Cyber Systems — High / Medium / Low impact
Spotlight
Impact-rated inventory & RSAW evidence culture

IEC 62443

Per System / Product
Controls
Parts 2-1 → 4-2 plus foundational requirements FR1–FR7
Reports To
Clock-silent — contractual only; incidents route via the statutory regimes
Inventory
Zones & Conduits — Security Levels SL 1–4
Spotlight
Secure Development Lifecycle (62443-4-1)

NIS2

Per Entity
Controls
Article 21(2)(a–j) measures + Art 20 governance
Reports To
CSIRT — 24 h → 72 h → 1 month (Art 23)
Inventory
Essential / Important entities by Annex I–II sector
Spotlight
Governance & accountability — management liability

EU CRA

Per Device
Controls
Annex I Part I essential requirements + Part II vulnerability handling
Reports To
ENISA/CSIRT — 24 h → 72 h → 14 days (exploited vuln; 1 mo severe incident)
Inventory
Products by criticality class — default / Class I / Class II / critical
Spotlight
SBOM & CE conformity

EU AI Act

Per Model
Controls
Art 5 → 72, risk classification, Annex IV docs, EU-database registration
Reports To
Market surveillance — ≤ 15 d · 10 d death · 2 d critical-infra disruption (Art 73)
Inventory
AI systems by risk class — prohibited / high / limited / minimal + GPAI
Spotlight
Conformity & registration

NERC O&P

Per Registered Entity
Controls
BAL · FAC · PRC · TOP · IRO · VAR · MOD · EOP · PER · COM
Reports To
EOP-004 within 24 h + DOE OE-417 (1 h / 6 h emergency lines)
Inventory
Facilities & Protection Systems by maintenance status (PRC-005)
Spotlight
Maintenance & event reporting

ARCHITECTURE

Five layers deep · eight functions across · four tiers up

L1

Functions

8 top-level outcomes — the CSF six plus two TENET functions

L2

Categories

34 categories, coded XX.YY

L3

Controls

CIP-style “shall” requirements with sub-parts

L4

Crosswalk

Per-control mapping into all six regimes

L5

Evidence & Measures

RSAW-style measures and acceptable evidence

Every control carries four cross-cutting attributes: Owner / Approver · Timeline / Cadence · Applicability(site · system · entity · device · model · registered entity) · Reporting trigger.

L1–L2 · THE FUNCTION MODEL

Eight functions, thirty-four categories

The CSF six — rebuilt with enforceable clocks — plus the two functions that make the GGF worth publishing: Supply Chain & Product Integrity and Regulatory Reporting & Conformity.

GVGovernCSF Analog

One accountable executive, approved policy, competent people, a liable board.

GV.PO
Policy & Procedures

Approved policies across every function, AGO re-approval every 15 calendar months.

GV.RA
Roles, Approvals & Delegation

Named Accountable Governance Officer; written delegations; Owner/Approver on every control.

GV.RM
Risk Methodology & Classification Governance

One methodology producing every regime’s classifier from a single assessment event.

GV.TR
Training & Competence

Role-based training before access; 15-month refresh; AI-literacy coverage.

GV.OV
Management Oversight & Liability

Management body approves measures, receives quarterly metrics, trained on personal liability.

IDIdentifyCSF Analog

One register. Every unit. Six classifications. Fifteen-month truth.

ID.AM
Asset & System Inventory

One canonical register, all six unit types, each with a unique portable identifier — the [T] ID lives here.

ID.CL
Impact & Risk Classification

One classification event, six outputs: H/M/L · SL-target · E/I · criticality class · AI risk class · maintenance criticality.

ID.RV
Review & Reconciliation

15-calendar-month review; 30-day re-check on triggering change; discrepancies to zero or formally risk-accepted.

ID.DP
Dependencies, Zones & Data Flows

Zones/conduits, perimeters, external connectivity, model data-flow maps.

PRProtectCSF Analog

Least privilege, hardened systems, controlled change, protected information.

PR.AC
Access Control — Electronic & Physical

Need-based authorization; quarterly verification; 24-hour revocation; MFA for interactive remote access.

PR.SP
System Security & Hardening

Needed ports only; 35-day patch evaluation; malware protections.

PR.IS
Information & Data Protection

BCSI-analog identification and protection; training-data governance for models.

PR.CH
Change & Configuration Management

Authorized baselines; 35-day deviation disposition; substantial modification triggers re-classification and re-conformity.

PR.NW
Segmentation & Boundary Defense

Zone/perimeter enforcement; documented permissions; vendor remote access individually terminable.

DEDetectCSF Analog

Log it, watch it, find the weakness before the adversary or the auditor does.

DE.MO
Security & Network Monitoring

Event logging; 90-day retention; 15-day review cycle; INSM for high-impact zones.

DE.VA
Vulnerability & Weakness Management

15-month assessments; coordinated-disclosure intake; CRA-grade product vulnerability handling.

DE.PM
Operational & Post-Market Monitoring

Maintenance status, model drift, field telemetry — degradation dispositioned.

DE.TH
Threat Intelligence & Advisories

E-ISAC / CISA / ENISA / PSIRT intake triaged against the register within SLA.

RSRespondCSF Analog

One plan, one clock, tested muscle.

RS.PL
Incident Response Plan & Classification

One IR plan spanning all six regimes’ incident definitions, with per-regime reportability criteria.

RS.CL
Regulatory Notification — The Unified Clock

Determine reportability across all six regimes on every incident; notify each triggered recipient inside its deadline. The crown jewel.

RS.EX
Testing & Exercises

15-month test cadence; the clock rehearsed in every exercise; lessons learned within 90 days.

RS.CO
Communications & Coordination

Escalation tree plus the non-regulator notices: product users, deployers, interconnected entities, service recipients.

RCRecoverCSF Analog

Restore the service, recall the product, retire the identity — provably.

RC.PL
Recovery Plans & Backup Integrity

Plans per critical unit; verified backups; protected recovery information.

RC.EX
Recovery Testing

15-month test; multi-year full exercise cycle; lessons learned in 90 days.

RC.RM
Remediation, Recall & Withdrawal

Corrective-action machinery for in-service units: recall, withdrawal, suspension — the off-ramp begins here.

RC.DE
Decommissioning & Secure Disposal

Sanitize, tear down access, retire the identifier with history preserved, produce the proof-of-elimination package. Prove-it’s-gone.

SCSupply Chain & Product IntegrityTENET Function

What you buy, what you build, what you can prove about both.

SC.PR
Procurement & Vendor Risk

Supply-chain risk plan in every procurement: notification duties, SDL attestations, right-to-SBOM, EOS commitments.

SC.SD
Secure Development Lifecycle

Documented SDL for anything the organization builds — products, models, systems — proportionate to classification.

SC.SB
SBOM & Component Transparency

Machine-readable SBOM per product/system, kept current through change, feeding vulnerability watch.

SC.IN
Integrity & Provenance Verification

Authenticity verified before install; signed updates; model provenance and data lineage recorded.

SC.TP
Third-Party Access & Services

Vendor access as first-class access — attributable, time-bounded, terminable within SLA.

RRRegulatory Reporting & ConformityTENET Function

The regulator-facing membrane: register, certify, evidence, report, attest.

RR.RG
Registration & Identification

Every statutory registration — NERC, EU AI database, CE/DoC, NIS2 entity — as a projection of one internal register key.

RR.CA
Conformity Assessment & Certification

The unit-appropriate path — RSAW-grade audit readiness, 62443 certification, CRA route by class, AI Act Art 43 route.

RR.EV
Evidence & Recordkeeping

Evidence as a by-product of execution, never reconstructed; strictest retention floor wins (10 years CRA/AI Act).

RR.RP
Periodic & Event Reporting Calendar

All non-incident submissions on one owned calendar with proof-of-submission artifacts.

RR.AT
Attestation & Self-Assessment

Attest-and-mark-gaps per unit per function; AGO signs the roll-up; attestation drives the maturity rating.

THE CROWN JEWEL · GGF-RS.CL-1

The Unified Reporting Clock

One incident. One timeline. Every obligation placed on it — computed once, at declaration, for all six regimes. No published framework does this.

T0

Detection / awareness

Declare, then determine wide. Reportability determination for all six regimes — documented even when the answer is “not reportable.”

T + 1 h

NERC CIP

E-ISAC + CISA — Reportable Cyber Security Incident, from determination (attempts: end of next calendar day)

T + 1–6 h

NERC O&P

DOE OE-417 emergency categories, where triggered

T + 24 h

NERC O&P

EOP-004 event report

T + 24 h

NIS2

Early warning to the CSIRT — 24 h double-tap with CRA: draft once, render twice

T + 24 h

EU CRA

Early warning to ENISA/CSIRT — actively exploited vulnerability or severe incident

T + 2 d

EU AI Act

Art 73 report — widespread infringement, or serious & irreversible disruption of critical infrastructure

T + 72 h

NIS2

Incident notification — assessment, severity, indicators of compromise (72 h double-tap with CRA)

T + 72 h

EU CRA

Vulnerability / incident notification

T + 10 d

EU AI Act

Art 73 report — incident involving a death

T + 14 d

EU CRA

Final report — exploited vulnerability

T + 15 d

EU AI Act

Serious-incident report — standard path

T + 1 mo

NIS2

Final report (or progress report if the incident is ongoing)

T + 1 mo

EU CRA

Final report — severe incident

IEC 62443 is clock-silent.Its reporting obligations are contractual; the GGF routes 62443 incidents through whichever statutory clock applies to the deployment — CIP at a site, NIS2 for the entity, CRA for the product.

Determine wide, notify fast

The six-regime determination matrix runs on every incident. A documented “not reportable” is a deliverable, not a shrug.

Double-taps are one work product

NIS2 and CRA share a skeleton at 24 h and again at 72 h. One incident record, many renders.

Near-misses have clocks too

CIP attempted-compromise and NIS2 significant-threat provisions live in the plan, not discovered mid-event.

The clock beats the meeting

Standing delegation to the Reporting Officer. No deadline waits on a signature — rehearsed in every exercise.

L4 ROLLUP

Function × regime coverage

Where each regime is heavy, light, or silent. Every dash is a gap the GGF fills — the defensible “no one has this” claims live in those cells, and only there.

FunctionCIP62443NIS2CRAAI ActO&P
GV Govern
ID Identify
PR Protect
DE Detect
RS Respond
RC Recover
↳ The off-ramp (RC.RM/RC.DE)
SC Supply Chain
RR Reporting & Conformity

● primary    ◐ partial    ○ light    — regime silent · GGF fills the gap

ELEVATION · THE MATURITY MODEL

Four tiers up

Each of the eight functions is rated 1–4 from attestation evidence. The profile is the 8-value vector — never an average. A Tier-4 Protect does not offset a Tier-1 Reporting function.

1

Initial

Per-regime silos and heroics. Inventories disagree. Reporting deadlines met by luck. Evidence reconstructed for audits.

2

Managed

Each regime has a documented program, owner, and calendar — separately. Clocks computed by hand, per event.

The GGF Line3

Defined

One register, six classifications. One control library, crosswalked. One IR plan with the Unified Clock rehearsed. Evidence as a by-product of execution.

4

Governed / Adaptive

Register reconciliation, control monitoring, and clock-readiness automated and watched 24/7. Regime changes absorbed as data updates, not projects.

One spine. Six regimes. Every clock.

The GGF is delivered through the Tenet system — registered by FORGE, classified by ATLAS, scored by CODEX, and operated 24/7 by SENTINEL.

Start Here