Spaces:
Running on Zero
Running on Zero
Download app.py from Soha85/Integrated_frameworks_demo: direct link, hf CLI and curl.
- Browser
- Download file 19.2 kB
-
https://huggingface.co/spaces/Soha85/Integrated_frameworks_demo/resolve/main/app.py
- Command line
-
hf download hf://spaces/Soha85/Integrated_frameworks_demo/app.py
-
curl -L -o app.py https://huggingface.co/spaces/Soha85/Integrated_frameworks_demo/resolve/main/app.py
19.2 kB
| import gradio as gr | |
| from datetime import datetime | |
| import spaces | |
| def _dummy_gpu_warmup(): | |
| return True | |
| # ============================================================================== | |
| # 1. DETAILED KNOWLEDGE BASE FOR CONSULTANTS (TOGAF + DAMA + ISO 27001/27701/8000) | |
| # ============================================================================== | |
| DETAILED_PHASES = { | |
| "Phase 0: Preliminary Framework & Foundation": { | |
| "framework_scope": "TOGAF v10 Preliminary | DAMA-DMBOK Ch. 1, 3 | ISO 27001 Cl. 4, 5 | ISO 27701 Cl. 5 | ISO 8000-61", | |
| "critical_warning": "⚠️ DO NOT PASS GATE IF: ISMS boundary scope excludes 3rd-party data pipelines or if Data Ownership is assigned to IT instead of Business Units.", | |
| "sub_domains": { | |
| "Architecture & Governance Principles": [ | |
| "Establish Architecture Board Charter, Voting Rules & Escalation Matrix", | |
| "Formulate 10-12 Core Enterprise Architecture Principles (TOGAF TRM aligned)", | |
| "Define Data Governance Operating Model (Centralized, Federated, or Hub-and-Spoke)", | |
| "Publish Data Stewardship Charter with assigned Data Owners per domain" | |
| ], | |
| "Security & Privacy Scope (ISO 27001 / 27701)": [ | |
| "Document ISMS Scope Statement & Context of Organization (ISO 27001 Cl. 4.1/4.2)", | |
| "Define PII Processing Boundary & Joint-Controller / Processor roles (ISO 27701)", | |
| "Formulate Information Security & Privacy Policies signed by C-Suite (Cl. 5.2)", | |
| "Establish Internal Audit & Compliance Cadence for ISMS/PIMS" | |
| ], | |
| "Data Quality Framework (ISO 8000)": [ | |
| "Adopt ISO 8000-61 Data Quality Management System (DQMS) Principles", | |
| "Define Enterprise Data Quality Dimensions (Completeness, Accuracy, Validity, Timeliness)", | |
| "Set Thresholds for Cost of Poor Data Quality (COPDQ) Tracking" | |
| ] | |
| }, | |
| "gate_deliverables": [ | |
| "Signed Architecture Board Charter", | |
| "Approved ISMS & PIMS Scope Document", | |
| "Data Governance Operating Model & RACI", | |
| "Tailored TOGAF ADM Architecture Framework" | |
| ] | |
| }, | |
| "Phase A: Architecture Vision & Business Case": { | |
| "framework_scope": "TOGAF Phase A | DAMA Ch. 2, 14 | ISO 27001 Cl. 6 | ISO 27701 Cl. 6", | |
| "critical_warning": "⚠️ DO NOT PASS GATE IF: Critical Data Elements (CDEs) are not identified or if the ROI calculation excludes compliance non-conformity fines.", | |
| "sub_domains": { | |
| "Vision & Value Realization": [ | |
| "Draft Request for Architecture Work & Architecture Vision Document", | |
| "Define Business Scenarios & High-Level Enterprise Capability Heatmap", | |
| "Establish Quantified ROI & Business Case Metrics (Cost Savings, Risk Reduction)", | |
| "Secure Executive Sponsor Sign-off (CEO/CFO/CIO)" | |
| ], | |
| "Critical Data Elements (CDEs) & Asset Identification": [ | |
| "Identify High-Value Critical Data Elements (CDEs) across Value Streams", | |
| "Conduct Initial Data Value & Impact Assessment for CDEs", | |
| "Define Baseline Data Flow Diagrams for Strategic Capabilities" | |
| ], | |
| "Initial Risk & Privacy Assessment": [ | |
| "Perform High-Level Information Security Risk Assessment (ISO 27001 Cl. 6.1.2)", | |
| "Conduct Privacy Threshold Assessment (PTA) to identify mandatory DPIA requirements", | |
| "Define Initial Threat Profile & Regulatory Landscape (GDPR, Local Privacy Laws)" | |
| ] | |
| }, | |
| "gate_deliverables": [ | |
| "Statement of Architecture Work", | |
| "Approved Architecture Vision Blueprint", | |
| "CDE Initial Inventory", | |
| "High-Level Risk & Privacy Impact Heatmap" | |
| ] | |
| }, | |
| "Phase B: Business Architecture & Governance": { | |
| "framework_scope": "TOGAF Phase B | DAMA Ch. 3, 8, 10 | ISO 27001 Annex A.5, A.8 | ISO 27701 Cl. 6.3-6.5", | |
| "critical_warning": "⚠️ DO NOT PASS GATE IF: CRUD Matrix contains orphaned data entities (Created without Read/Delete) or PII processing lacks lawful basis.", | |
| "sub_domains": { | |
| "Capability & Business Process Mapping": [ | |
| "Model Target Business Capabilities (L1 to L3 Breakdown)", | |
| "Map Business Value Streams to Business Processes (BPMN 2.0)", | |
| "Construct Process-to-Data CRUD Matrix (Create, Read, Update, Delete)", | |
| "Map Organization Units to Business Capabilities" | |
| ], | |
| "Data Domain & Information Architecture": [ | |
| "Establish Enterprise Data Domain Boundary Map (Subject Areas)", | |
| "Assign Executive Data Domain Owners & Operational Data Stewards", | |
| "Catalog Data Assets & Assign Information Sensitivity Classification (ISO 27001 A.5.9)" | |
| ], | |
| "Privacy Processing Activity Register (ROPA)": [ | |
| "Compile Record of Processing Activities (ROPA / ISO 27701 Annex A/B)", | |
| "Document Lawful Basis for Processing per PII Data Flow (Consent, Contract, Legitimate Interest)", | |
| "Define Data Retention & Destruction Schedules per Business Entity" | |
| ] | |
| }, | |
| "gate_deliverables": [ | |
| "L1-L3 Business Capability Map", | |
| "Enterprise Process-Data CRUD Matrix", | |
| "Data Domain Boundary & Governance RACI", | |
| "ISO 27701 Compliant ROPA Register" | |
| ] | |
| }, | |
| "Phase C: Information Systems - Data Architecture": { | |
| "framework_scope": "TOGAF Phase C (Data) | DAMA Ch. 4, 5, 6, 9, 11 | ISO 8000-110 | ISO 27001 Annex A.8.10, A.8.11", | |
| "critical_warning": "⚠️ DO NOT PASS GATE IF: Logical Data Model lacks PII tagging at attribute level or ISO 8000 validation rules are not machine-executable.", | |
| "sub_domains": { | |
| "Data Modeling & Master Data Architecture": [ | |
| "Develop Conceptual Data Model (CDM) & Target Logical Data Model (LDM in 3NF/DV2.0)", | |
| "Design Dimensional Physical Data Models for Analytics (Star/Snowflake Schema)", | |
| "Define Master Data Management (MDM) Hub Patterns (Registry, Transactional, Hybrid)", | |
| "Establish Reference Data Governance & Hierarchy Management Rules" | |
| ], | |
| "Data Security, Privacy-by-Design & Masking": [ | |
| "Tag PII/SPII Attributes directly inside Data Dictionary metadata", | |
| "Specify Static & Dynamic Data Masking Rules for Non-Production & Analytics", | |
| "Define Field-Level & Column-Level Encryption Requirements (AES-256)", | |
| "Architect Subject Rights Request (SRR / Data Erasure/Right to be Forgotten) Workflows" | |
| ], | |
| "ISO 8000 Data Quality Specifications": [ | |
| "Publish ISO 8000-110 Portable Data Quality Rules (Syntax, Semantic, Conformity)", | |
| "Set Up Data Profiling Rules for Ingestion Pipelines", | |
| "Define Automated Quarantine & Error Remediation Workflows for Bad Data" | |
| ] | |
| }, | |
| "gate_deliverables": [ | |
| "Logical Data Model (LDM) & Data Dictionary", | |
| "MDM & Reference Data Architecture Specification", | |
| "Data Encryption & Masking Controls Document", | |
| "ISO 8000 Executable Data Quality Rules Catalog" | |
| ] | |
| }, | |
| "Phase C: Information Systems - Application Architecture": { | |
| "framework_scope": "TOGAF Phase C (App) | DAMA Ch. 6 | ISO 27001 Annex A.8.25-A.8.31 | ISO 27701", | |
| "critical_warning": "⚠️ DO NOT PASS GATE IF: APIs exposing PII lack OAuth2/OIDC token verification or rate-limiting/audit logging.", | |
| "sub_domains": { | |
| "Application Portfolio & Integration": [ | |
| "Catalog Target Application Portfolio (TIME Framework: Tolerate, Innovate, Migrate, Eliminate)", | |
| "Map Application-to-Application Interface & API Catalog (OpenAPI/Swagger)", | |
| "Define System Integration Patterns (Event-Driven, Batch ETL, RESTful APIs, Mesh)", | |
| "Establish Legacy Decommissioning Strategy & Data Archival Plan" | |
| ], | |
| "Secure Application Development & API Governance": [ | |
| "Define Secure Software Development Lifecycle (SSDLC) Rules (ISO 27001 A.8.25)", | |
| "Implement API Gateway Architecture with Rate Limiting, Mutual TLS, and OAuth2.0/OIDC", | |
| "Mandate OWASP Top 10 Mitigation Controls in Application Architecture Specification", | |
| "Architect System Audit Logging for Security Operations (SIEM Integration)" | |
| ] | |
| }, | |
| "gate_deliverables": [ | |
| "Target Application Communication & Interface Diagram", | |
| "Application Portfolio Rationalization Matrix", | |
| "API Security & Integration Architecture Standard", | |
| "System Audit & Logging Architecture Plan" | |
| ] | |
| }, | |
| "Phase D: Technology Architecture & Infrastructure": { | |
| "framework_scope": "TOGAF Phase D | DAMA Ch. 4, 6 | ISO 27001 Annex A.8.20-A.8.24 | ISO 27701", | |
| "critical_warning": "⚠️ DO NOT PASS GATE IF: Cloud Data Stores lack Customer-Managed Encryption Keys (CMEK) or lack automated vulnerability scanning.", | |
| "sub_domains": { | |
| "Platform & Infrastructure Design": [ | |
| "Design Multi-Cloud / Hybrid Cloud Network Architecture (VPCs, Subnets, Transit Gateways)", | |
| "Architect Data Platform Tech Stack (Data Warehouse, Data Lakehouse, Feature Stores)", | |
| "Establish High Availability (HA), Disaster Recovery (DR), and RPO/RTO Metrics", | |
| "Specify Hardware, Compute, and Container Orchestration Standards (Kubernetes)" | |
| ], | |
| "Security Infrastructure & Identity Governance": [ | |
| "Design Zero Trust Network Architecture & Micro-segmentation Controls", | |
| "Architect Identity & Access Management (IAM), RBAC, ABAC, and PAM Solutions", | |
| "Evaluate & Select Consent Management Platforms (CMP) & Data Catalog Tools", | |
| "Mandate Infrastructure-as-Code (IaC) Security Scanning Pipelines" | |
| ] | |
| }, | |
| "gate_deliverables": [ | |
| "Target Infrastructure & Cloud Topology Architecture Diagram", | |
| "Tech Stack Selection Scorecards & Architecture Decision Records (ADRs)", | |
| "Disaster Recovery & Business Continuity Plan Specification", | |
| "Zero Trust Network & IAM Architecture Blueprint" | |
| ] | |
| }, | |
| "Phase E & F: Opportunities, Solutions & Migration Planning": { | |
| "framework_scope": "TOGAF Phase E & F | DAMA Ch. 1, 2 | ISO 27001 Cl. 6.2 | ISO 27701", | |
| "critical_warning": "⚠️ DO NOT PASS GATE IF: Statement of Applicability (SoA) lacks formal justification for excluded controls or Transition Architectures create security gaps.", | |
| "sub_domains": { | |
| "Gap Analysis & Roadmap Formulation": [ | |
| "Synthesize Baseline vs Target Gap Analysis across Business, Data, App, and Tech", | |
| "Group Gaps into Strategic Work Packages & Define Dependencies", | |
| "Construct Transition Architectures (Transition v1 [6mo], v2 [18mo], Target v3 [36mo])", | |
| "Develop Integrated Master Implementation Roadmap Gantt" | |
| ], | |
| "Statement of Applicability (SoA) & Cost-Benefit": [ | |
| "Finalize ISO 27001 / 27701 Statement of Applicability (SoA) with explicit Inclusion/Exclusion Justifications", | |
| "Conduct Total Cost of Ownership (TCO) & Value Realization Analysis per Transition", | |
| "Perform Business Continuity & Data Migration Risk Assessments" | |
| ] | |
| }, | |
| "gate_deliverables": [ | |
| "Consolidated EA Gap Analysis Matrix", | |
| "Transition Architecture Specifications (v1, v2, Target)", | |
| "Approved Statement of Applicability (SoA)", | |
| "Master Implementation Roadmap & Budget Plan" | |
| ] | |
| }, | |
| "Phase G & H: Implementation Governance & Change Management": { | |
| "framework_scope": "TOGAF Phase G & H | DAMA Ch. 1, 13 | ISO 27001 Cl. 8, 9, 10 | ISO 8000-61", | |
| "critical_warning": "⚠️ DO NOT PASS GATE IF: Non-conforming implementations are deployed without formal, time-bound Architecture Board Waivers.", | |
| "sub_domains": { | |
| "Implementation Oversight & Compliance Audits": [ | |
| "Execute Architecture Contracts with Software Delivery & Cloud Engineering Teams", | |
| "Conduct Architecture Compliance Reviews prior to Production Releases", | |
| "Enforce Architecture Variance & Waiver Management Process", | |
| "Review Penetration Testing, Vulnerability Scans & ISO 27001 Internal Audits" | |
| ], | |
| "Change Management & Continuous Monitoring": [ | |
| "Track Data Quality Scorecards (ISO 8000) against SLAs in Live Production", | |
| "Monitor Regulatory Changes (Privacy/AI Acts) & Re-evaluate Threat Models", | |
| "Measure EA Business Value Realization & Capability Maturity Trajectory", | |
| "Trigger ADM Cycle Iteration upon Major Business Strategy Shift or Tech Obsolescence" | |
| ] | |
| }, | |
| "gate_deliverables": [ | |
| "Signed Architecture Contracts", | |
| "Compliance Audit Reports & Waiver Logs", | |
| "Live Data Quality & ISMS Monitoring Dashboards", | |
| "Annual Architecture Maturity Re-assessment Report" | |
| ] | |
| } | |
| } | |
| # Helper functions | |
| def get_all_tasks_for_phase(phase_name): | |
| data = DETAILED_PHASES[phase_name] | |
| flat_list = [] | |
| for tasks in data["sub_domains"].values(): | |
| flat_list.extend(tasks) | |
| return flat_list | |
| def load_phase_data(phase_name): | |
| data = DETAILED_PHASES[phase_name] | |
| return ( | |
| f"## {phase_name}", | |
| f"**Framework Alignment:** `{data['framework_scope']}`", | |
| f"### {data['critical_warning']}", | |
| data["gate_deliverables"] | |
| ) | |
| def generate_audit_report(phase_name, completed_tasks, auditor_notes, gate_status): | |
| data = DETAILED_PHASES[phase_name] | |
| total_tasks = sum(len(tasks) for tasks in data["sub_domains"].values()) | |
| completed_count = len(completed_tasks) if completed_tasks else 0 | |
| completion_pct = (completed_count / total_tasks) * 100 if total_tasks > 0 else 0 | |
| timestamp = datetime.now().strftime("%Y-%m-%d %H:%M:%S") | |
| report = f""" | |
| # 📋 ARCHITECTURE GATE AUDIT REPORT | |
| **Generated On:** `{timestamp}` | |
| **Phase Evaluated:** `{phase_name}` | |
| **Auditor Decision:** **{gate_status}** | |
| --- | |
| ### 1. Compliance Metric | |
| - **Verified Deliverables / Tasks:** {completed_count} / {total_tasks} | |
| - **Completion Percentage:** `{completion_pct:.1f}%` | |
| - **Mandatory Deliverables Required:** {", ".join(data['gate_deliverables'])} | |
| ### 2. Critical Warning Verification | |
| > {data['critical_warning']} | |
| ### 3. Verified Task Checklist Items | |
| """ | |
| if completed_tasks: | |
| for item in completed_tasks: | |
| report += f"\n- [x] {item}" | |
| else: | |
| report += "\n*No tasks explicitly marked as verified in checklist.*" | |
| report += f""" | |
| ### 4. Consultant Findings & Non-Conformance Log | |
| ```text | |
| {auditor_notes if auditor_notes.strip() else "No consultant notes recorded."} | |
| ``` | |
| Sign-off Certification: This report serves as an architecture governance audit record under TOGAF v10 / ISO 27001 ISMS guidelines. | |
| """ | |
| return report # <-- FIX 1: properly indented inside the function | |
| # ============================================================================== | |
| # 2. GRADIO INTERFACE LAYOUT | |
| # ============================================================================== | |
| with gr.Blocks(title="EA Governance Consultant Helper") as demo: | |
| gr.Markdown( | |
| """ | |
| # 🏛️ Enterprise Architecture & Governance Audit Tool | |
| ### Deep Granularity Guide for TOGAF v10 | DAMA-DMBOK2 | ISO 27001 / 27701 / 8000 | |
| *This tool helps consultants remember every critical sub-domain control and generate formal audit reports.* | |
| """ | |
| ) | |
| with gr.Row(): | |
| phase_selector = gr.Dropdown( | |
| choices=list(DETAILED_PHASES.keys()), | |
| value=list(DETAILED_PHASES.keys())[0], | |
| label="Select ADM Phase for Audit", | |
| interactive=True | |
| ) | |
| gr.Markdown("---") | |
| with gr.Row(): | |
| with gr.Column(scale=3): | |
| phase_title = gr.Markdown() | |
| framework_scope = gr.Markdown() | |
| critical_warning = gr.Markdown() | |
| gr.Markdown("### 🔍 Granular Verification Checklist") | |
| task_checkboxes = gr.CheckboxGroup( | |
| choices=get_all_tasks_for_phase(list(DETAILED_PHASES.keys())[0]), | |
| label="Check off each verified artifact/control during audit:", | |
| interactive=True | |
| ) | |
| with gr.Column(scale=2): | |
| gr.Markdown("### 📦 Required Gate Deliverables") | |
| deliverables_box = gr.JSON(label="Mandatory Artifact Sign-offs") | |
| gr.Markdown("---") | |
| gr.Markdown("### ✍️ Consultant Gate Audit Sign-Off") | |
| gate_decision = gr.Radio( | |
| choices=["APPROVED (PASS GATE)", "CONDITIONAL APPROVAL (WAIVER REQUIRED)", "REJECTED (FAIL GATE)"], | |
| value="CONDITIONAL APPROVAL (WAIVER REQUIRED)", | |
| label="Phase Gate Decision" | |
| ) | |
| consultant_notes = gr.Textbox( | |
| lines=6, | |
| placeholder="Enter non-conformances, identified architectural debt, missing ISO controls, or mandatory remediation steps...", | |
| label="Auditor Findings & Non-Conformance Log" | |
| ) | |
| audit_btn = gr.Button("Generate Formal Audit Record", variant="primary") | |
| gr.Markdown("---") | |
| audit_output_display = gr.Markdown() | |
| # Event Handlers | |
| def on_phase_change(phase_name): | |
| title, scope, warning, deliverables = load_phase_data(phase_name) | |
| new_tasks = get_all_tasks_for_phase(phase_name) | |
| return title, scope, warning, gr.CheckboxGroup(choices=new_tasks, value=[]), deliverables, "" | |
| phase_selector.change( | |
| on_phase_change, | |
| inputs=[phase_selector], | |
| outputs=[phase_title, framework_scope, critical_warning, task_checkboxes, deliverables_box, audit_output_display] | |
| ) | |
| audit_btn.click( | |
| generate_audit_report, | |
| inputs=[phase_selector, task_checkboxes, consultant_notes, gate_decision], | |
| outputs=[audit_output_display] | |
| ) | |
| demo.load( | |
| on_phase_change, | |
| inputs=[phase_selector], | |
| outputs=[phase_title, framework_scope, critical_warning, task_checkboxes, deliverables_box, audit_output_display] | |
| ) | |
| pass | |
| if __name__ == "__main__": # <-- FIX 2: correct dunder syntax | |
| demo.launch(theme=gr.themes.Soft(primary_hue="sky")) |