Mandate 2.2.3 Runtime Evidence Intake and Guidance Skill
Mandate
- ID: 2.2.3
- Title: Secure Training and Fine-Tuning
Mitigates
- ML02 Data Poisoning Attack
- ML07 Transfer Learning Attack
- LLM04 Data and Model Poisoning
Objective
Gather natural-language context, convert it into an evidence plan, and guide users to generate supporting operational artifacts for final mandate assessment.
Natural-Language Intake Workflow
- Ask for training and production architecture at a high level.
- Ask where training data originates and how it moves across environments.
- Ask which identities and roles can access training, model artifacts, and promotion pipelines.
- Ask how pre-trained models/datasets are approved and verified.
- Ask how promotion from training to production is approved and logged.
- Ask how contamination or unauthorized access incidents are detected and handled.
Context Normalization Schema
Capture and normalize answers into:
platform_profile: cloud/on-prem, orchestrator, regions, env names.training_prod_boundary: network, identity, storage, compute separation.data_flow_map: source systems, transfer paths, controls, approvals.access_model: roles, principals, least-privilege boundaries.artifact_trust_chain: source verification, signatures, provenance.promotion_governance: gate checks, approvers, audit logs.monitoring_ir: alerting, incident workflow, escalation.
Supporting Documents to Request
- Environment topology diagrams and network segmentation rules.
- IAM/RBAC policy exports for training and production.
- Data movement logs and approval records.
- Artifact provenance attestations for base models/datasets.
- Model promotion workflow evidence (tickets/approvals/gates).
- Incident records and corrective actions related to contamination/access.
Guidance to Generate Supporting Evidence
- Generate architecture and segmentation evidence.
- Export infrastructure diagrams from existing architecture repositories or CMDB.
- Export active network policies and route constraints.
- Generate access-control evidence.
- Export role bindings and policy attachments for both training and production.
- Compare scope breadth and separation boundaries.
- Generate data movement evidence.
- Export transfer logs for training data ingress/egress.
- Collect corresponding human/system approvals.
- Generate provenance evidence.
- Export signatures/checksums/attestations for external base models and datasets.
- Generate promotion governance evidence.
- Export release tickets, approval decisions, and gate results for model promotion.
- Generate monitoring/incident evidence.
- Export alerts, incidents, and remediation proof tied to contamination/unauthorized access.
System Command Templates (Adapt to Environment)
- Kubernetes environment boundaries:
kubectl get nskubectl get networkpolicy -A -o yaml > network_policies_export.yaml
- AWS IAM separation:
aws iam list-roles > iam_roles.jsonaws iam list-attached-role-policies --role-name <role-name> > role_policies_<role-name>.json
- GCP IAM separation:
gcloud projects get-iam-policy <project-id> --format=json > gcp_iam_policy.json
- Azure role assignments:
az role assignment list --all --output json > azure_role_assignments.json
- Data movement/audit trail (example):
aws cloudtrail lookup-events --start-time <start> --end-time <end> > cloudtrail_events.json
- Artifact provenance checks:
sha256sum <artifact-file> > artifact_sha256.txtcosign verify-blob --key <public-key> --signature <sig-file> <artifact-file>
- Promotion evidence (example from GitHub):
gh pr list --search \"model promotion\" --state merged --limit 100 > promotion_prs.txt
Evidence Completeness Rules
- Mark each required artifact as
collected,partial, ormissing. - Mark evidence as
staleif outside agreed assessment window. - Mark evidence as
insufficientif it lacks source system metadata, timestamps, or owner identity.
Final Assessment Readiness
- Ready only when all required evidence types are collected and internally consistent with user-provided context.
- Not ready when any control area lacks verifiable operational artifacts.
Output Contract
Return:
context_profilerequired_artifacts_checklistartifact_generation_stepscommand_templatesevidence_status_matrixassessment_readinessremaining_gaps
Guardrails
- Ask short follow-up questions when context is ambiguous.
- Prefer read-only evidence commands.
- State assumptions explicitly when users provide partial context.