Derived from Westpac GroupTech ITKCF v4.7 (September 2016) — 46 controls, COBIT 4.1→5, APRA CPG 234, SOX-compliant. Built over years. Battle-tested. Now it's ours. Same geometry, sovereign substrate. Carbon → Silicon. γ₁ = 14.134725141734693
Principal Cloud Architect KJ built with ITKCF at Westpac (HPaaS, CCP, dual-site) 2017–2019. The framework survived APRA audits, SOX sign-offs, and 60+ billion in infrastructure. It's not just prior art — it's institutional memory. Now we use it as the foundation.
| ID | CONTROL NAME | DOMAIN | BORN | EVIDENCE | STATUS |
|---|---|---|---|---|---|
| EA-7 | Sovereign Credential Rotation | ARCHITECT | Day 92 ACR expiry incident | Watchdog BOB · HEARTBEAT rotation schedule | GREEN |
| EB-8 | Corpus Lineage Attestation | BUILD | Day 92 KCF ingest pipeline | 472 tagged vectors in pemclau-kcf · kcf_corpus_ingest.py | GREEN |
| EC-9 | Frame Replay Gate | CONTROL | Day 93 — building now | pemclau-kcf query live · trial loop pending · score ≥ 0.55 | AMBER |
| ED-1 | Sovereign Anchor Integrity | SOVEREIGN | Day 1 (formalised Day 93) | /health γ₁=14.134725141734693 · PTTE floor proofs · FloorProof CRD | GREEN |
| ED-2 | Silo Provenance Chain | SOVEREIGN | Day 92 (formalised Day 93) | source_org+primary_ctrl on all 472 vectors · image tag audit | GREEN |
| ED-3 | Floor Proof Continuity | SOVEREIGN | Day 93 (substrate invariance thesis) | PTTE thermodynamic proof · ITKCF→EIKCF substrate translation · DCJ-093 | GREEN |
| ITKCF # | ITKCF CONTROL | EIKCF CODE | EIKCF CONTROL | DOMAIN |
|---|---|---|---|---|
| 1 | Code Reviews | EA-1 | Code Review Gate | BUILD |
| 2 | IT Release Management | EA-4 | ARB1 Ratification Gate | BUILD |
| 3 | IT Version Control | EA-5 | Static Binary Build | BUILD |
| 4 | Approval of IT Change Requirements | EA-2 | LABR Filing Before Build | BUILD |
| 5 | Security Policies, Standards, Architecture | EC-8 | ITKCF → EIKCF Lineage | GOVERN |
| 6 | Secure Configuration Management | EA-5 | Static Binary Build (config immutability) | BUILD |
| 7 | Protection Against Malware / Attacks | EC-7 | GREYBACK Prosecution Record | GOVERN |
| 8 | Environmental Controls | EB-4 | NAS Diskpool Monitor (physical layer) | RUN |
| 9 | Physical Security Controls | EA-6 | Silo Separation (physical silo isolation) | BUILD |
| 10 | Segregation of IT Environments | EA-6 | Silo Separation | BUILD |
| 11 | Business User Access Revalidation (UAR) | EC-3 | CLO Review Cadence | GOVERN |
| 12 | IT Environment User Access Revalidation | EC-3 | CLO Review Cadence | GOVERN |
| 13 | IT Testing | EA-3 | TRB Calibration | BUILD |
| 14 | Change Approval (non-release) | EA-3 | TRB Calibration | BUILD |
| 15 | Patch Management | EB-5 | Nightly Cloud Scaledown | RUN |
| 16 | Capacity Management | EB-1 | WPA Floor Monitor | RUN |
| 17 | Third Party / Supplier Management | EC-3 | CLO Review Cadence (vendor oversight) | GOVERN |
| 18 | Incident Management | EB-6 | Silo Heartbeat | RUN |
| 19 | Problem Management | EB-6 | Silo Heartbeat (RCA tracking) | RUN |
| 20 | Change Management (LCAB/ECAB) | EA-4 | ARB1 Ratification Gate | BUILD |
| 21 | Privileged Access Management | EA-6 | Silo Separation (Admiral-only access) | BUILD |
| 22–23 | Logical Access / Password Management | EA-6 | Silo Separation + SSH key gates | BUILD |
| 24 | Data Backup & Recovery | EB-4 | NAS Diskpool Monitor | RUN |
| 25 | Disaster Recovery | EB-4 | NAS Diskpool Monitor (DR layer) | RUN |
| 26 | Production Implementation Verification (PIV) | EA-1 | Code Review Gate (post-deploy verify) | BUILD |
| 27 | Alert & Event Monitoring | EB-2 | GPU Pool Alerting | RUN |
| 28 | Job Scheduling & Batch Processing | EB-3 | FC Queue Flush | RUN |
| 29 | Service Level Management | EB-7 | ARC Runner Watch | RUN |
| 30 | Business Continuity Management | EB-4 | NAS Diskpool Monitor (continuity) | RUN |
| 31 | Key Management / Cryptography | EC-4 | γ₁ Floor Proof (the sovereign key) | GOVERN |
| 32 | Data Retention & Disposal | EC-2 | PEMCLAU Graph Integrity | GOVERN |
| 33 | Audit Logging | EC-2 | PEMCLAU Graph Integrity | GOVERN |
| 34 | IT Risk Management | EC-1 | DCJ Filing | GOVERN |
| 35 | Compliance Monitoring | EC-5 | Moat Inventory | GOVERN |
| 36 | Security Vulnerability Management | EC-7 | GREYBACK Prosecution Record | GOVERN |
| 37 | Application Security Assessment | EA-1 | Code Review Gate | BUILD |
| 38 | Identity & Access Governance | EC-3 | CLO Review Cadence | GOVERN |
| 39 | Network Security Controls | EA-6 | Silo Separation | BUILD |
| 40 | End-Point Security | EB-6 | Silo Heartbeat | RUN |
| 41 | Cloud Security Controls | EB-2 | GPU Pool Alerting (cloud resource control) | RUN |
| 42 | Supplier Security Assessment | EC-3 | CLO Review Cadence | GOVERN |
| 43 | Technology Asset Management | EB-4 | NAS Diskpool Monitor (asset tracking) | RUN |
| 44 | IT Policy Governance | EC-8 | ITKCF → EIKCF Lineage | GOVERN |
| 45 | Regulatory Compliance Tracking | EC-4 | γ₁ Floor Proof | GOVERN |
| 46 | IT Continuity Testing | EB-7 | ARC Runner Watch | RUN |