Ir al contenido

12 Compliance Dimensions

GlassPlane (panel.ossfia.ai) mide el compliance de cada repositorio en 12 dimensiones con scoring evidence-first.

#DimensionWeightQue mide
1Framework Compliance9%Phase artifacts + context layers + baseline subtree
2Gate Progression7%Gates A-F by track
3Data Governance10%Classification, provenance, quality, retention
4Security Posture9%Secrets, SBOM, threat model, AIA
5SAST/SCA8%Static analysis + dependency audit
6OWASP ASI8%ASI01-10 + MCP Top 10
7EU AI Act8%Art. 6, 10, 11, 14, 50, 73
8AI Governance8%AIBOM, ISO 42001, NIST RMF
9Delivery Performance10%DORA + SPACE + DX AI
10Spec Coverage7%OpenAPI, data dict, ADRs
11Singapore MGF8%D1-D4: accountability, risk, human, technical
12Colombia AI Ethics8%D1-D5: ethics, equity, transparency, governance, sustainability
  • Platinum: 96-100
  • Gold: 81-95
  • Silver: 61-80
  • Bronze: 31-60
  • Critical: 0-30

Cada score es trazable a un artefacto via evidence levels: absent → present → valid → executed → confirmed.