Cybersecurity assurance
The most direct technical analogue: accredited vendor-paid labs, repeated criticism of checkbox compliance, and crowdsourced adversarial testing that pays per finding.
Path signature
S standards O oversight M mandate O oversight T trigger
Similarity of its opening to frontier AI: 0.11 (matched opening SOMOT)
Stages reached
| Voluntary | not reached |
| Trigger | 2013 |
| Mandate | 2004 |
| Standards | 1985 |
| Oversight | 1999 |
| Independence | not reached |
| Access | not reached |
Mechanisms
| Before reform | Now | |
|---|---|---|
| pays | A | A |
| selects | A | A |
| access | deep | deep |
| publishes | summary | summary |
| oversees | none | regulator |
Vendor picks and pays an accredited lab or assessor; certificates public, reports not.
Payer, access, publication
Who pays. Vendor or merchant pays the accredited assessor.
Access. Documentation, source review, and testing environments per scheme.
Publication. Certificates public; reports confidential; bug bounty disclosures partly public.
Milestones
| Year | Kind | Event | Strength | Harm | |
|---|---|---|---|---|---|
| 1985 | standards | TCSEC (Orange Book): government evaluation of trusted systems. | 2 | source | |
| 1999 | accreditation | Common Criteria (ISO/IEC 15408) with accredited commercial evaluation labs. | 3 | source | |
| 2004 | mandate | PCI DSS: card networks require assessments by Qualified Security Assessors. | 2 | source | |
| 2011 | accreditation | FedRAMP accredits third-party assessment organizations for cloud services. | 3 | source | |
| 2013 | trigger | Target breach at a PCI-compliant merchant. | integrity_failure: Breach at a merchant certified compliant | source |
seed; secondary sources; verify each milestone against a primary source before citing in the paper Data: data/industries/cybersecurity-assurance.json