The One Home Rule
Each part of the framework — a definition, a requirement, a piece of guidance — has exactly one controlling home. Nothing gets patched in a summary, a public page, or a derived document while the real source stays wrong. If two things ever seem to disagree, the controlling source wins, and the disagreement gets formally resolved rather than quietly smoothed over.
Human Authority
A person is accountable, not an algorithm
Material decisions — what counts as a requirement, whether evidence is sufficient, what claim is allowed to be made — require a named human, currently the framework's owner, Towseef Ahmed. AI and automation can draft, compare, and support that work, but they don't own or approve it.
Named accountable areas
Eight areas, each with a clear owner
Architecture
Durable decisions about how the framework is put together — not routine day-to-day changes.
Standards
The shared definitions and rules everything else builds on.
Catalogs
The structured records — the actual list of Domains, Capabilities, and Controls.
Guidance
The informative how-to content that helps you apply a Control, without changing what it requires.
Assessment
How verification works — separate from the requirements themselves.
Publication
What gets released publicly, and how it's reviewed before that happens.
Legal
Licensing and rights — kept separate from framework approval itself.
Implementation
Any actual software or tooling built on top of DEFEND, governed on its own track.
How change happens
A proposed change is named, its scope defined, its impact assessed across every affected area — not just the obvious one — and then a human disposition is issued: confirmed, amended, deferred, or rejected. The change lands in its controlling source first; everything derived from it (this site included) is updated afterward, never the other way around.