github.com/gemaraproj/gemara@v0.23.0

docs/model/07.1-measurement-layers.md raw

 1---
 2layout: page
 3title: The Measurement Layers (5, 6, 7)
 4---
 5
 6Complementing the preparation done at lower layers to ensure sensitive activities are planned and executed securely, the final three layers look back on outcomes to ensure adherence to the organization’s Policies.
 7
 8Beginning with an inspection of the intended and actual outcomes, activities within Layer 5 can be described as either Intent Evaluations and Behavioral Evaluations.
 9
10Building on Evaluation Findings, Layer 6 describes Preventative Enforcement activities that serve as guardrails, blocking non-compliant designs before they go live, and Remediative Enforcement activities which produce corrections after negative outcomes are detected in a real world scenario.
11
12Finally, Layer 7 describes activities which serve to Audit the effectiveness of the organization’s Policies, Evaluation and Enforcement activities, and orchestrate Continuous Monitoring to ensure that sensitive activities remain compliant indefinitely.
13
14An old leadership adage states that “a unit only does well that which its commander inspects well.” Activities categorized within Layers 5, 6, and 7 act as that inspection which equips our organizations to excel.
15
16---
17
18## Continue Reading
19
20- **< Previous Page**: [Layer 4: Sensitive Activities](./06-sensitive-activities)
21- **> Next Page**: [Layer 5](./07.2-Layer-5)
22
23---