UAIF / CM / CM-02

RAG leakage

Objective

Apply base contribution 1.5 subject to effective cap 1.5.

UAIF requirement

Data exfiltration via retrieval-augmented generation

Business impact

Adjusts severity context through an explicit, capped and reviewable contribution rather than an opaque score change.

Validation approach

Apply the specification-defined context modifier deterministically and retain the input, expected result, actual result, version and reviewer disposition.

Expected evidence

Versioned input fixture or incident record, calculation or test trace, expected outcome, actual outcome, exception record and reviewer approval where required.

Mapping and source

UAIF Technical Specification and its applicable taxonomy, profile or conformance clause.

Implementation guidance

Implement this context modifier as a versioned UAIF rule. Keep configuration, thresholds and exceptions visible; do not represent it as an independently certifiable GAISSF control.

Assessment considerations

Test representative, boundary, adverse and conflicting inputs. Confirm repeatability, version alignment, exception handling and retention of the complete decision or calculation trace.

Artifact classification

Context modifier, not a GAISSF control

This page documents a UAIF taxonomy, calculation or conformance artifact. It must not be represented as an independently certifiable control unless a future approved assurance publication expressly establishes that status.