top of page

ATTRIBUTION & COPYRIGHT

Last updated: 10 September 2026

This page records the copyright position of every external work referenced by PRAECEPTA, the licence under which our own material is published, and the limits of what our references imply. We publish it in full because a methodology that references five regulators should be transparent about the basis on which it does so.

1. PRAECEPTA original work

 

All of the following are original works authored by PRAECEPTA CYBERSECURITY LLC:

  • MAIS Evidence Primitive identifiers, titles, assertions and rationales

  • MAIS domain structure and schema definitions

  • The Assessment Grammar Transform rule content and engine

  • The Delta Register analytical content and reasoning

  • The Framework Version Register

  • Mapping provenance records

  • The GCC Framework Crosswalk, including its direction-of-fit notation

  • All reference implementation code and tooling

 

Our evidence primitives describe evidentiary conditions in our own words. They are not restatements, paraphrases or adaptations of any framework's control text.

2. How we reference frameworks

 

PRAECEPTA references all frameworks by control identifier only. We reproduce no framework text.

 

Where our material refers to a framework requirement, it does so by its published identifier — for example A3.a, ECC-2:2024, A.5.9, ID.AM-01 — accompanied by our own description of the evidence that would satisfy it. The framework's own wording is never reproduced.

 

This is a deliberate design constraint, not an incidental practice. It means our material can be published, shared and built upon without infringing the rights of any issuing authority, and it means a framework revision is absorbed by a data change rather than a rewrite.

3. Framework copyright position

 

​​​Open Government Licence acknowledgement

 

Contains public sector information licensed under the Open Government Licence v3.0.
NCSC Cyber Assessment Framework 4.0 — © Crown copyright.

 

In the interest of accuracy, we note that the NCSC's Cyber Assessment Framework collection pages do not state a licence inline. The Open Government Licence v3.0 is the standard licence applied to UK public sector information and is applied to CAF-derived publications on gov.uk. We have written to the NCSC to confirm the applicable terms and our preferred acknowledgement wording, and will update this page on reply.

NIST material

 

NIST publications are works of the United States Government and are in the public domain. Attribution is offered as a courtesy, not as a licence requirement.

4. Saudi, Emirati and international regulatory material

 

We have written to the National Cybersecurity Authority (Kingdom of Saudi Arabia) and the UAE Cyber Security Council to confirm our basis for referencing their control identifiers in published methodology material, and to seek confirmation of official assessment terminology so that our tooling reflects each Authority's own wording rather than an approximation.

 

We reference these frameworks by identifier only pending those replies, and we will publish any guidance we receive.

5. ISO/IEC material — a specific warning

 

ISO/IEC 27001:2022 and ISO/IEC 27002:2022 are copyright-protected and licence-controlled works.

 

PRAECEPTA holds a purchased licensed copy. We reference Annex A controls by identifier only. No ISO text — including control titles, control statements, implementation guidance or Annex A wording — is reproduced in any PRAECEPTA artefact, in any format, under any circumstances.

 

If you are building on our material and intend to reproduce ISO content, you must obtain your own licence. Our CC BY 4.0 licence grants you rights in our work only. It grants you no rights whatsoever in ISO/IEC material, and nothing on this website should be read as doing so.

6. Secure Controls Framework

 

The Secure Controls Framework (SCF) is a substantial and useful body of work, freely published, with mapping methodology consistent with the set-theory relationship approach described in NIST IR 8477. We reference it here because practitioners reasonably ask how our work relates to it.

 

MAIS Evidence Primitives and mappings are authored independently from primary issuer documents. They are not derived from, adapted from, or based upon the Secure Controls Framework.

 

We note and respect that SCF free content is licensed Creative Commons Attribution-NoDerivatives 4.0 International (CC BY-ND 4.0). Those terms permit unmodified redistribution, including commercially, with attribution — but prohibit the distribution of derivative works. SCF's stated terms treat the use of artificial intelligence to generate policies, standards, procedures, metrics, risks or threats from SCF content as the creation of derivative content. Derivative commercial content requires an SCF commercial licence.

 

We record our position plainly because the distinction matters: our mapping provenance records are available for independent inspection by design partners and, on request, by anyone with a legitimate interest in verifying it. Every mapping in MAIS carries its source document title, version, publication date, clause identifier, retrieval date, author and verification status.

 

PRAECEPTA has selected a licence that permits derivatives for our own work. That is a deliberate divergence, and our reasoning is set out on our licence page.

7. Our own licensing

 

If you are citing our work

 

Based on the MEA Assurance Interoperability Standard (MAIS) by PRAECEPTA Cybersecurity LLC, licensed CC BY 4.0. praecepta.co/mais

 

PRAECEPTA GCC Framework Crosswalk v0.9.1, PRAECEPTA Cybersecurity LLC, licensed CC BY 4.0. praecepta.co/crosswalk

 

Full terms: Licence

8. No endorsement or affiliation

 

Framework names, titles, control identifiers, structures and content remain the property of their respective issuing authorities, including the National Cyber Security Centre (United Kingdom), the National Cybersecurity Authority (Kingdom of Saudi Arabia), the UAE Cyber Security Council, the Saudi Central Bank, ISO/IEC, and the National Institute of Standards and Technology (United States).

 

Reference to any framework does not imply endorsement, affiliation, approval, accreditation or certification by its issuing authority. PRAECEPTA holds no such endorsement, affiliation, approval or accreditation from any framework issuing authority, regulator or certification body.

 

Determinations of compliance and certification rest solely with the relevant regulatory authority, accredited certification body, or appointed auditor. PRAECEPTA does not make, and cannot make, such determinations.

9. Trade marks

 

All third-party names and marks referenced on this website are the property of their respective owners and are used for identification purposes only.

10. Corrections

 

If you believe anything on this page is inaccurate — including our characterisation of any licence, any rights holder's position, or our own basis for reference — tell us and we will correct it and acknowledge the correction.

 

We publish corrections rather than amending silently. A current example is on our crosswalk page.

 

 

 

This page sets out PRAECEPTA's understanding of the copyright and licensing position of the works referenced. It constitutes a statement of our own practice, not legal advice, and it is not a legal opinion on the rights of any third party. If you intend to reproduce or build upon any third-party framework content, obtain your own legal advice and, where required, your own licence.

bottom of page