standards.sgit.ai / subsets

The subset method

Nobody wants to read eight instruments. Everybody wants the twelve provisions across eight instruments that bear on the problem actually in front of them. That is a page type, and it is the most sellable output this method produces.

create a subset, a graph, of those standards that has just the bits, the controls, and the elements relevant here… You almost recreate a small standard based on this.

What a subset is

A subset takes one real problem and pulls together every provision, from every instrument here, that bears on it — each one cited, each one carrying its own instrument's label and licensing position, and each one linked back to its provision page. It is not a summary of the instruments and it is not a new standard. It is a view over the graph, computed rather than written, which is what makes it maintainable when one of the eight instruments is amended.

A subsetA summary
IsA view over provisions that exist elsewhereNew text about provisions
Each itemCites a provision, with its address and its instrument's labelParaphrases several, attributed loosely or not at all
When an instrument is amendedThe affected item is flagged — the content hash under its positional hash movedSilently wrong, and looks current
Against a paywalled standardLegitimate — it cites and interprets, it never reproducesUsually a licence breach wearing a summary's clothes

Why this page type sidesteps the ISO problem

A subset cites and interprets; it never reproduces. An ISO clause enters a subset as a reference — number, title, and the project's own reading of what it asks for — which is exactly what an ISO folder may legitimately hold. So the instruments that cannot have a folder here can still appear in a subset, and appear usefully. That is not a loophole; it is the difference between citation and reproduction, and it is the same difference a footnote in a book relies on.

What the first subset found

Across eight instruments spanning EU law, US law, ISO standards and security frameworks, the substantive overlap turned out to be small and repetitive:

The throughline across all of them is the same small set of ideas: least privilege, data minimisation, access control, supply-chain and third-party risk, traceable evidence, and accountability.

That is worth publishing for two opposite reasons. It is reassuring — an organisation doing those six things well is in a defensible position under most of them at once. And it is a warning — six shared ideas do not mean six shared obligations, and the differences between how NIS2 and DORA treat third-party risk are precisely where an organisation gets caught. A subset that collapsed the eight into the six would be the merge failure at a larger scale. Bridges, not merges →

Published

Subset 1

Agentic access

What eight instruments require of an organisation that lets an autonomous agent hold credentials and act on real systems. Spanning GDPR, NIST, ISO/IEC 27001, HIPAA, the EU AI Act, NIS2, DORA, and the OWASP/MITRE agentic layer.

Read →
Not built

The rest

Incident reporting across NIS2, DORA, GDPR and the AI Act is the obvious second — four different clocks, four different addressees, one incident. It does not exist. Neither does anything else.

The honest limit on all of this. A subset is a view over a graph. With one instrument modelled, the subset below is a curated table with citations rather than a computed view — the provisions from the other seven instruments are referenced, not modelled, and nothing recomputes when one of them changes. It becomes the thing it is supposed to be at instrument four or five, not now. It is published anyway because the shape is the argument, and because a table that says which provisions bear on agentic access is useful before it is automatic.