{"policy_id":"LAKA-ADOPTED-STANDARDS","version":"1.0.0","as_of":"2026-09-03","review_frequency":"quarterly-and-on-upstream-release","standards":[{"id":"NIST-CSF","adopted_version":"2.0","purpose":"program outcomes across Govern, Identify, Protect, Detect, Respond, and Recover"},{"id":"NIST-SP-800-61","adopted_version":"Revision 3","purpose":"incident preparation, response, and recovery integration"},{"id":"NIST-SP-800-115","adopted_version":"final","purpose":"technical security testing and assessment governance"},{"id":"OWASP-ASVS","adopted_version":"5.0.0","purpose":"web application security requirements and verification objectives"},{"id":"OWASP-WSTG","adopted_version":"4.2 stable","purpose":"web application test-method references"},{"id":"FIRST-CVSS","adopted_version":"4.0","purpose":"vulnerability severity characteristics and vector"},{"id":"FIRST-EPSS","adopted_version":"current-daily-model-output","purpose":"separate 30-day exploitation probability signal"},{"id":"CISA-KEV","adopted_version":"current-catalog-snapshot","purpose":"known exploitation signal"},{"id":"MITRE-ATTACK","adopted_version":"pin-snapshot-in-production","purpose":"adversary behavior vocabulary"},{"id":"MITRE-D3FEND","adopted_version":"pin-snapshot-in-production","purpose":"defensive countermeasure knowledge graph"}],"rules":["Store exact framework and tool versions with profiles, tests, findings, and evidence.","Preserve historical mappings when upgrading standards.","Test parser and rule changes before accepting a new upstream version.","Never reinterpret old evidence using a newer profile without recording the transformation."]}