GCBoK - The Normative Reference Work for Git-native Compliance
GitCover is not a tool for compliance enthusiasts. It is infrastructure for everyone who wants to get compliance done - as affordable, as secure, and as verifiable as possible.
The GitCover Body of Knowledge (GCBoK) is a normative reference work that canonizes terms, concepts, and architecture principles for Git-native Compliance. It is comparable to PMBOK (Project Management), SWEBOK (Software Engineering), and DMBOK (Data Management) - but with its own conceptual framework.
Positioning
| Feature | Value |
|---|---|
| Type | Body of Knowledge (BoK) - normative |
| Pattern | ISO/IEC 24773 (BoK structure as a basis for certification schemes) |
| Sponsor | GitCover Commons gUG (GCC) - non-profit |
| License | Intended: CC BY-SA 4.0 |
| Versioning | Git (git.gitcover.org) - Git-native self-referential |
| URL | gcbok.org (Production) |
Overview of Chapters (Axes 1–14)
| Art. | Title (DE) | Title (EN) | Core Question |
|---|---|---|---|
| 01 | Fundamentals: Git-native Compliance Paradigm | Fundamentals: Git-native Compliance Paradigm | What is the fundamental architecture paradigm? |
| 02 | Concepts: V7GUID, Evidence Chains, Cryptographic Evidence | Concepts: V7GUID, Evidence Chains, Cryptographic Evidence | How do the conceptual building blocks work? |
| 03 | Components: The GitCover Stack (GCDMS, GCPN, GCUCB, GCEP, GCSync, GCAL) | Components: The GitCover Stack | How is the technical stack structured? |
| 04 | Techniques: OSCAL, OPA, GPG, uuidV7, Gitea as IdP | Techniques: OSCAL, OPA, GPG, uuidV7, Gitea as IdP | Which techniques does GitCover use? |
| 05 | Procedures: Onboarding, Audit-Readiness, GoBD, Annual Accounts, NIS2, Risk Analysis, AI Integration | Procedures: Onboarding, Audit-Readiness, GoBD, Annual Accounts, NIS2, Risk Analysis, AI Integration | How does one proceed in practice? |
| 06 | Templates: OSCAL Catalog, OPA Policy, V7GUID Schema, DMS Container | Templates: OSCAL Catalog, OPA Policy, V7GUID Schema, DMS Container | Which templates are available? |
| 07 | Governance: Statutes, Community Rules, Amendment Procedures, Versioning | Governance: Statutes, Community Rules, Amendment Procedures, Versioning | How is the project governed? |
| 08 | IP Rights: Patent Family and Utility Models | IP Rights: Patent Family and Utility Models | Which IP rights exist? |
| 09 | Research Projects: BSFZ-recognised R&D Project GitCover.IdP | Research Projects: BSFZ-recognised R&D Project GitCover.IdP | How is the research project structured? |
| 10 | Roadmap: Three Phases until 2027 and Positioning | Roadmap: Three Phases until 2027 and Positioning | How does the project evolve? |
| 11 | Publisher and Sponsor: GitCover Commons gUG (GCC) | Publisher and Sponsor: GitCover Commons gUG (GCC) | Who is behind the GCBoK? |
| 12 | Sources & Community | Sources & Community | Where can sources and community be found? |
| 13 | Namespace vs. V7GUID Identity: Why GitCover is not an Identity Medium | Namespace vs. V7GUID Identity: Why GitCover is not an Identity Medium | How does GitCover differ from identity media? |
| 14 | Certification: Certification Scheme and ISO/IEC 24773 Conformance (Planned) | Certification: Certification Scheme and ISO/IEC 24773 Conformance (Planned) | How is certification based on GCBoK envisioned? |
Context
The GCBoK main work is divided into 14 axes (chapters) that form the normative reference work for Git-native Compliance. Each axis is a standalone document with DE/EN/VI variants.
Status: All 14 chapters created (DE/EN/VI) — Chapter 14 is preliminary (Phase 3 planning).