| name | altitude-check |
| description | Check whether a CoSAI Risk Map entry is pitched at the right altitude (granularity). For a control: objective-not-implementation, not-a-restated-risk, posture-not-mandate, solved-problem, no-duplication. For a risk: the merge-vs-distinct two-test, threat-not-control-gap, and real-not-hypothetical. For a component: the absorb-or-decompose base test, role-not-product, and reader-instructive. Use when authoring or reviewing a control/risk/component draft, when a draft reads like implementation detail or a restated threat, or to decide whether a candidate should be new, merged, or absorbed into an existing entry. |
Altitude Check
Altitude is the granularity an entry is pitched at. Too low and it becomes implementation detail or an instance that sprawls into siblings; too high and it dissolves the gap it was meant to name. Most authoring defects are altitude defects, so check altitude before wording.
Run the tests for the entry type. The control, risk, and component tests are all active; run the set matching the entry type.
Control altitude tests
Apply each; report pass or adjust-with-fix.
- T1 — Objective, not implementation. The control states a capability or objective ("ensure delegation chains are auditable"), not a mechanism ("emit signed delegation spans with correlation IDs to a collector"). The objective survives implementation churn. Fix: lift the mechanism into a description example and restate the objective.
- T2 — Not a restated risk. A control is the defense framed as a positive capability, not the threat with "prevent" attached. If it reads like the risk inverted, rewrite it as the capability the implementer gains.
- T3 — Posture, not mandate. A control describes a defensive capability an implementer adopts against their risk appetite; it is not a compliance order. Watch for "must always," universal imperatives, and audit-language.
- T4 — Solved problem. A known technique achieves the objective. If none does, this is a research gap or a risk to document — not a control. flag it for the maintainer rather than drafting an aspirational control.