Frameworks & Standards
Buyers often evaluate Legra through frameworks that were not written for knowledge graphs: cybersecurity frameworks, AI risk frameworks, privacy law, identity trust frameworks, data-product standards, and audit criteria.
This section does that mapping directly. It explains where Legra gives you native evidence, where it gives you useful building blocks, and where the framework remains the responsibility of your organization, deployment, or auditor.
These pages are not certification claims. Legra can help produce evidence for an assessment, but the assessment itself depends on how Legra is deployed, operated, governed, and integrated into the rest of your environment.
How to read the status
| Status | Meaning |
|---|---|
| Native fit | Legra has product primitives that directly support the framework’s assessment question. |
| Partial fit | Legra supplies useful evidence or architecture, but surrounding controls are still required. |
| Roadmap | The direction fits Legra, but the feature should not be treated as complete yet. |
| External responsibility | The framework depends mainly on customer process, deployment, legal analysis, or third-party audit. |
Data product, catalog, ontology, and data-management frameworks
- DPROD - OMG Data Product Ontology, with Legra workspaces as publishable data products.
- DCAT - W3C Data Catalog Vocabulary, with Legra catalogs, services, distributions, and versioned metadata.
- FIBO - EDM Association’s Financial Industry Business Ontology for financial-services semantics.
- FAIR Data Principles - findable, accessible, interoperable, and reusable digital assets.
- DAMA-DMBOK - data-management governance, architecture, quality, metadata, integration, and lifecycle practice areas.
- DCAM - EDM Association’s Data Management Capability Assessment Model for assessing data-management maturity.
Business capability and semantic-delivery methods
- EKG Principles - ten principles for identity, shared meaning, distribution, contextual truth, self-description, measurement, business purpose, control, ecosystems, and standards.
- EKGF Use Case Tree Method - business-owned EKG use-case planning, governance, reuse, stories, outcomes, and executable semantic components.
Federated data spaces and trust
- Gaia-X Compliance - machine-readable self-descriptions, federated trust, sovereignty, conformity evidence, and data-space participation.
Semantic interoperability and domain standards
- W3C Linked Data standards - RDF, SPARQL, SHACL, PROV, OWL, and related standards used to evaluate semantic interoperability.
Identity and trust frameworks
- IDESG / IDEF - identity ecosystem assessment, privacy, security, interoperability, and accountability.
Cybersecurity and defensive architecture
- MITRE ATT&CK - adversary behavior mapping and threat-informed defense.
- MITRE D3FEND - defensive countermeasure taxonomy and acquisition support.
- NIST Cybersecurity Framework - governance, identify, protect, detect, respond, and recover outcomes.
AI risk, governance, and security
- NIST AI RMF - govern, map, measure, and manage AI risk.
- ISO/IEC 42001 - organizational AI management systems, accountability, lifecycle governance, and continual improvement.
- CSA AI Controls Matrix - auditable controls for cloud-based AI providers, orchestrators, applications, and customers.
- MITRE ATLAS - adversary tactics and techniques against predictive, generative, and agentic AI systems.
- EU AI Act - AI regulatory obligations, especially for high-risk AI systems and data governance evidence.
Privacy and assurance
- NIST Privacy Framework - outcome-based enterprise privacy-risk management aligned with the NIST Cybersecurity Framework.
- GDPR - privacy, access control, minimization, provenance, and data-subject-process evidence.
- ISO/IEC 27701 - privacy information management for organizations acting as PII controllers or processors.
- ISO/IEC 27001 - information security management system evidence.
- SOC 2 - service-organization controls for security, availability, confidentiality, processing integrity, and privacy.
Terms that are not frameworks
Some terms used in white papers or architecture discussions are useful, but they are not assessment frameworks by themselves. Examples include Knowledge Communication Protocol, Sovereign World Model, Attribute-Based Encryption, SWRL policy enforcement, dynamic masking credentials, and Active Directory, OAuth, or SCADA bridges.
Those terms should be described as architecture patterns, roadmap items, or integration ideas unless they are tied to a specific external framework or implemented Legra feature.