{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-xct-019","code":"wm-xct-019-cyber-integrity","url":"https://ver.cy/models/wm-xct-019-cyber-integrity/","name":"Cyber Integrity","alternateNames":["S8"],"kind":"world-model","status":"published","version":"0.1.0-reviewable-draft","language":"en","classifiers":{"family":"World Models","category":"Cross-cutting context","entryKind":"mixin","plane":"","domain":["XCT.SEC"],"industry":["Cross-industry"],"navPath":"NAV.XCT.SEC","tags":["cyber","integrity","xct.sec"],"facets":{}},"whatItIs":"One host-attached security context with scoped applicability, threat relevance, baseline, assurance and response references. The mixin owns its assertions and revisions, not external asset, vulnerability, incident, risk or enforcement masters.","purpose":"Represent evidence-qualified cyber security context attached to an externally mastered system, device or endpoint.","scope":{"in":["Host and scope attachment with role-based accountability","Local vulnerability applicability and attributed priority context","Threat and observation interpretation with explicit uncertainty","Baseline applicability and received integrity or posture evidence","Treatment, incident and recovery references","Restricted projections, correction lineage and evidence continuity"],"out":["Creating public vulnerability or incident masters","Running scanners, exploiting weaknesses, producing attack instructions or operating protected systems","Patch installation, containment, recovery execution, incident declaration and regulatory notification","Generic ownership, consent, access enforcement, audit-trail or enterprise risk machinery","Physical measurement of the abstract attachment, universal security scores and certification"],"boundaries":[{"neighbor":"WM-SFT-002","distinction":"Software System / Business Application is a candidate host master; local attachment does not duplicate system inventory or lifecycle."},{"neighbor":"WM-OBJ-008","distinction":"Device / Sensor / Compute HW is an alternative host master; physical properties and device control stay external."},{"neighbor":"WM-SFT-018","distinction":"Network / Endpoint may provide a protected endpoint reference; address, reachability and topology authority stay external."},{"neighbor":"WM-SFT-001","distinction":"Software Product is a product reference, not a replacement for a concrete deployed host. Resolve legacy N4 ambiguity explicitly."},{"neighbor":"WM-SFT-006","distinction":"Vulnerability Record owns vulnerability identity, advisory lifecycle and public/private identifiers; carry scoped local applicability only."},{"neighbor":"WM-ACT-020","distinction":"Cyber Incident owns the incident record and declaration lifecycle; carry host association and attributed impact references only."},{"neighbor":"WM-ACT-042","distinction":"Incident Response owns operational response, containment and recovery execution; local functions cannot initiate these operations."},{"neighbor":"WM-XCT-027","distinction":"Risk / Control owns generic risk and control bindings and acceptance decisions; carry security-specific baseline and decision references."},{"neighbor":"WM-XCT-001","distinction":"Ownership / Stewardship supplies responsibility and delegation references; legal title and ownership transfer remain external."},{"neighbor":"WM-XCT-002","distinction":"Access Contract / Consent supplies scoped authorization; security evidence and TLP markings do not issue grants."},{"neighbor":"WM-XCT-004","distinction":"Access Audit retains authoritative access-event records; link evidence without owning audit-trail semantics."},{"neighbor":"WM-XCT-007","distinction":"Access Breach / Enforcement owns distinct access-violation cases; cyber compromise is not automatically an access-contract violation."},{"neighbor":"WM-SFT-017","distinction":"Telemetry / Operational Signal owns observations and collection context; local interpretation does not perform detection or redefine raw telemetry."},{"neighbor":"WM-XCT-035","distinction":"Retention / Disposition supplies retention and hold policy bindings; destruction execution remains in its authorized external process."},{"neighbor":"Legacy S8 and unreviewed supplement","distinction":"Treat legacy hierarchy and events as leads. Preserve weakness, threat, incident linkage and assurance concerns but move vulnerability and incident masters outward. Legacy M8/N4 labels conflict with current registry identities; bind by verified model ID and actual host kind. Legacy conformance labels and wildcard imports are not admitted."}]},"distinguishingFeatures":["Unlike WM-SFT-002: Software System / Business Application is a candidate host master; local attachment does not duplicate system inventory or lifecycle.","Unlike WM-OBJ-008: Device / Sensor / Compute HW is an alternative host master; physical properties and device control stay external.","Unlike WM-SFT-018: Network / Endpoint may provide a protected endpoint reference; address, reachability and topology authority stay external.","Unlike WM-SFT-001: Software Product is a product reference, not a replacement for a concrete deployed host. Resolve legacy N4 ambiguity explicitly.","Unlike WM-SFT-006: Vulnerability Record owns vulnerability identity, advisory lifecycle and public/private identifiers; carry scoped local applicability only.","Unlike WM-ACT-020: Cyber Incident owns the incident record and declaration lifecycle; carry host association and attributed impact references only.","Unlike WM-ACT-042: Incident Response owns operational response, containment and recovery execution; local functions cannot initiate these operations.","Unlike WM-XCT-027: Risk / Control owns generic risk and control bindings and acceptance decisions; carry security-specific baseline and decision references.","Unlike WM-XCT-001: Ownership / Stewardship supplies responsibility and delegation references; legal title and ownership transfer remain external.","Unlike WM-XCT-002: Access Contract / Consent supplies scoped authorization; security evidence and TLP markings do not issue grants.","Unlike WM-XCT-004: Access Audit retains authoritative access-event records; link evidence without owning audit-trail semantics.","Unlike WM-XCT-007: Access Breach / Enforcement owns distinct access-violation cases; cyber compromise is not automatically an access-contract violation.","Unlike WM-SFT-017: Telemetry / Operational Signal owns observations and collection context; local interpretation does not perform detection or redefine raw telemetry.","Unlike WM-XCT-035: Retention / Disposition supplies retention and hold policy bindings; destruction execution remains in its authorized external process.","Unlike Legacy S8 and unreviewed supplement: Treat legacy hierarchy and events as leads. Preserve weakness, threat, incident linkage and assurance concerns but move vulnerability and incident masters outward. Legacy M8/N4 labels conflict with current registry identities; bind by verified model ID and actual host kind. Legacy conformance labels and wildcard imports are not admitted."],"structure":{"bundles":[{"id":"bundle-attachment","name":"Attachment and authority","description":"Host-scoped context for attachment and authority.","layers":[{"id":"layer-host","name":"Protected subject binding","description":"Attach security context to one externally mastered system, device or endpoint at a declared scope and revision. Host identity, topology and inventory remain external.","findings":[{"id":"finding-scope","name":"Scoped security attachment","description":"Attach security context to one externally mastered system, device or endpoint at a declared scope and revision. Host identity, topology and inventory remain external.","questions":[{"text":"Which authoritative host and scope does this security attachment identify?","id":"question-scope-1","kind":"identity"},{"text":"Which inventory revision and component boundaries define the assessed subject?","id":"question-scope-2","kind":"composition"},{"text":"Which security objectives and criticality profile apply to that subject?","id":"question-scope-3","kind":"classification"},{"text":"When must this attachment be superseded after a host split, merger or retirement?","id":"question-scope-4","kind":"lifecycle"}]}]},{"id":"layer-mandate","name":"Stewardship mandate","description":"Bind accountable roles and delegated authority for these records. Coordination does not grant access to another tenant or permission to operate on a host.","findings":[{"id":"finding-authority","name":"Scoped accountability and authority","description":"Bind accountable roles and delegated authority for these records. Coordination does not grant access to another tenant or permission to operate on a host.","questions":[{"text":"Which role is accountable for the security context within the declared host scope?","id":"question-authority-1","kind":"ownership"},{"text":"What mandate permits an assessor to contribute or approve a posture assertion?","id":"question-authority-2","kind":"authority"},{"text":"What restrictions follow supplied evidence into a recipient view?","id":"question-authority-3","kind":"access"},{"text":"How is an expired or disputed delegation represented before further edits?","id":"question-authority-4","kind":"exception"}]}]}]},{"id":"bundle-exposure","name":"Weakness and exposure","description":"Host-scoped context for weakness and exposure.","layers":[{"id":"layer-applicability","name":"Applicability evidence","description":"Reference a vulnerability or private advisory and bind its assertion to a concrete host configuration. Conflicting, missing and under-investigation evidence remain explicit.","findings":[{"id":"finding-exposure","name":"Local vulnerability applicability","description":"Reference a vulnerability or private advisory and bind its assertion to a concrete host configuration. Conflicting, missing and under-investigation evidence remain explicit.","questions":[{"text":"Which vulnerability master and advisory revision support this applicability assertion?","id":"question-exposure-1","kind":"relationship"},{"text":"What inventory or configuration evidence establishes the affected product match?","id":"question-exposure-2","kind":"evidence"},{"text":"Is the local subject affected, not affected, fixed, under investigation or unknown?","id":"question-exposure-3","kind":"state"},{"text":"How are conflicting supplier statements or stale inventory prevented from becoming a confident clearance?","id":"question-exposure-4","kind":"validation"}]}]},{"id":"layer-priority","name":"Priority context","description":"Retain attributed severity inputs separately from an authorized local priority or risk-acceptance decision. A missing public identifier does not exclude a private vulnerability.","findings":[{"id":"finding-priority","name":"Severity and risk-decision context","description":"Retain attributed severity inputs separately from an authorized local priority or risk-acceptance decision. A missing public identifier does not exclude a private vulnerability.","questions":[{"text":"Which scoring version, vector and metric-group label accompany a cited severity value?","id":"question-priority-1","kind":"measurement"},{"text":"Which host impact and exposure assumptions inform the local treatment priority?","id":"question-priority-2","kind":"requirement"},{"text":"Which external decision approves the treatment priority or residual risk acceptance?","id":"question-priority-3","kind":"decision"},{"text":"When do changed conditions require reconsideration of the recorded priority?","id":"question-priority-4","kind":"temporal"}]}]}]},{"id":"bundle-threat","name":"Threat and observation","description":"Host-scoped context for threat and observation.","layers":[{"id":"layer-intelligence","name":"Threat relevance","description":"Record a scoped relevance assertion about externally identified threat information. Attribution is a claim with provenance and confidence, not an identity verdict.","findings":[{"id":"finding-relevance","name":"Attributed threat relevance","description":"Record a scoped relevance assertion about externally identified threat information. Attribution is a claim with provenance and confidence, not an identity verdict.","questions":[{"text":"Who asserted this threat relevance and which source object revision was used?","id":"question-relevance-1","kind":"provenance"},{"text":"How is a reported campaign or technique relevant to this host scope?","id":"question-relevance-2","kind":"relationship"},{"text":"What confidence was stated and what remains unspecified or contested?","id":"question-relevance-3","kind":"quality"},{"text":"What source revocation or correction invalidates the local relevance assertion?","id":"question-relevance-4","kind":"lifecycle"}]}]},{"id":"layer-signals","name":"Signal interpretation","description":"Link indicator definitions, observations and sightings without equating a match with compromise. Detection execution and raw telemetry retention remain outside the mixin.","findings":[{"id":"finding-signal","name":"Indicator and observation binding","description":"Link indicator definitions, observations and sightings without equating a match with compromise. Detection execution and raw telemetry retention remain outside the mixin.","questions":[{"text":"Which indicator revision is being related to which external observation?","id":"question-signal-1","kind":"identity"},{"text":"What observation interval and indicator validity bound this interpretation?","id":"question-signal-2","kind":"temporal"},{"text":"What false-positive explanation or collection gap qualifies the apparent match?","id":"question-signal-3","kind":"quality"},{"text":"Which sharing restrictions apply to the linked observable and any derived summary?","id":"question-signal-4","kind":"security"}]}]}]},{"id":"bundle-assurance","name":"Baseline and assurance","description":"Host-scoped context for baseline and assurance.","layers":[{"id":"layer-baseline","name":"Baseline binding","description":"Pin a selected baseline or outcome profile with local applicability and exclusions. Control catalogues, enterprise risks and formal acceptance decisions are separately mastered.","findings":[{"id":"finding-baseline","name":"Declared security baseline applicability","description":"Pin a selected baseline or outcome profile with local applicability and exclusions. Control catalogues, enterprise risks and formal acceptance decisions are separately mastered.","questions":[{"text":"Which versioned baseline or target profile applies to this host scope?","id":"question-baseline-1","kind":"requirement"},{"text":"Which baseline elements are excluded or inherited and on what recorded basis?","id":"question-baseline-2","kind":"constraint"},{"text":"Who approved this baseline binding and its next review point?","id":"question-baseline-3","kind":"authority"},{"text":"What mapping distinguishes a local control claim from an external framework outcome?","id":"question-baseline-4","kind":"interoperability"}]}]},{"id":"layer-evidence","name":"Integrity and posture evidence","description":"Bind received assessment or attestation results to their subject, verifier, policy and evidence interval. Cryptographic validity or an integrity measurement does not prove total security.","findings":[{"id":"finding-assessment","name":"Bounded assessment and attestation results","description":"Bind received assessment or attestation results to their subject, verifier, policy and evidence interval. Cryptographic validity or an integrity measurement does not prove total security.","questions":[{"text":"Which assessment result, evidence reference and verifier support the recorded posture?","id":"question-assessment-1","kind":"evidence"},{"text":"Which appraisal policy and trust assumptions qualify an attestation result?","id":"question-assessment-2","kind":"validation"},{"text":"How old is each assessed claim and when does its acceptance expire?","id":"question-assessment-3","kind":"temporal"},{"text":"What scope, method and unknown coverage qualify any posture score or pass label?","id":"question-assessment-4","kind":"measurement"}]}]}]},{"id":"bundle-response","name":"Treatment and incident linkage","description":"Host-scoped context for treatment and incident linkage.","layers":[{"id":"layer-remediation","name":"Remediation evidence","description":"Keep planned treatment, reported execution and verification separate. Mitigation and accepted risk do not mean fixed; rollback or new configuration can invalidate verification.","findings":[{"id":"finding-treatment","name":"Treatment status and verification","description":"Keep planned treatment, reported execution and verification separate. Mitigation and accepted risk do not mean fixed; rollback or new configuration can invalidate verification.","questions":[{"text":"Which external change or treatment record addresses this local exposure?","id":"question-treatment-1","kind":"process"},{"text":"What was planned, reported applied and independently checked for this treatment?","id":"question-treatment-2","kind":"state"},{"text":"Which scoped verification result supports a claim that remediation succeeded?","id":"question-treatment-3","kind":"evidence"},{"text":"What unresolved failure, deferral or rollback prevents closing the exposure?","id":"question-treatment-4","kind":"exception"}]}]},{"id":"layer-incident","name":"Incident impact linkage","description":"Associate the host with a separately mastered cyber incident and record the provenance of impact and recovery assertions. Declaration, containment, notification and closure belong to authorized external workflows.","findings":[{"id":"finding-incident","name":"Incident and recovery context","description":"Associate the host with a separately mastered cyber incident and record the provenance of impact and recovery assertions. Declaration, containment, notification and closure belong to authorized external workflows.","questions":[{"text":"Which incident master and declaration evidence establish this host association?","id":"question-incident-1","kind":"event"},{"text":"Which impacts are confirmed, suspected or still unknown for this subject?","id":"question-incident-2","kind":"quality"},{"text":"What externally approved recovery evidence supports the current host posture?","id":"question-incident-3","kind":"evidence"},{"text":"Which response, communication or access-breach case needs a distinct linked record?","id":"question-incident-4","kind":"relationship"}]}]}]},{"id":"bundle-continuity","name":"Disclosure and record continuity","description":"Host-scoped context for disclosure and record continuity.","layers":[{"id":"layer-sharing","name":"Disclosure views","description":"Describe proposed audience-specific views of existing security records. A public advisory must not automatically expose private deployment facts; preparing a view does not authorize transmission.","findings":[{"id":"finding-disclosure","name":"Controlled security projections","description":"Describe proposed audience-specific views of existing security records. A public advisory must not automatically expose private deployment facts; preparing a view does not authorize transmission.","questions":[{"text":"Which identifiable systems or personal data must be suppressed from this audience view?","id":"question-disclosure-1","kind":"privacy"},{"text":"What source marking and additional permissions bound onward disclosure?","id":"question-disclosure-2","kind":"access"},{"text":"Who may approve release or lift an embargo for this particular projection?","id":"question-disclosure-3","kind":"authority"},{"text":"How is the derived view checked for residual identifiers and conflicting markings?","id":"question-disclosure-4","kind":"validation"}]}]},{"id":"layer-history","name":"Record continuity","description":"Preserve correction lineage, bounded evidence access and semantic loss notes across projections. The adopting retention policy controls payload disposal; an evidence digest cannot replace required review.","findings":[{"id":"finding-continuity","name":"Revision, retention and exchange","description":"Preserve correction lineage, bounded evidence access and semantic loss notes across projections. The adopting retention policy controls payload disposal; an evidence digest cannot replace required review.","questions":[{"text":"Which prior assertion does a correction supersede while preserving its original attribution?","id":"question-continuity-1","kind":"provenance"},{"text":"Which retention schedule or hold governs local security evidence and its references?","id":"question-continuity-2","kind":"retention"},{"text":"Which versioned exchange binding preserves identifiers, unknown states and markings?","id":"question-continuity-3","kind":"interoperability"},{"text":"What remains resolvable when a host or evidence payload is retired or lawfully erased?","id":"question-continuity-4","kind":"lifecycle"}]}]}]}]},"agentConduct":{"may":["Bind host context: Proposed local operation, not implemented. Creates only the local security attachment; ambiguous host binding is refused.","Record applicability assertion: Proposed local operation, not implemented. Records the submitted assessment; no automatic vulnerability detection or clearance.","Link threat interpretation: Proposed local operation, not implemented. Links existing evidence; does not run detection, attribute an actor as fact or declare compromise.","Record assurance evidence: Proposed local operation, not implemented. Records received evidence disposition; does not perform cryptographic attestation or certify security.","Reconcile treatment references: Proposed local operation, not implemented. Updates local references only; does not install, contain, recover or close an external incident.","Prepare restricted view: Proposed local operation, not implemented. Produces a local candidate view only; no transmission, permission expansion or embargo release."],"mustNot":["Return authorized summaries when payload access is denied.","Deny by default; grant least privilege by tenant, host, purpose, role and evidence sensitivity.","A visible finding never implies permission to fetch its artifacts."],"requiresHuman":[]},"ethics":{"considerations":["Versioned security, disclosure, privacy and retention policies with authority references","Resolve every candidate model ID and pin an accepted version before use; no compulsory child models are declared.","Source markings and embargo terms constrain onward use in addition to applicable permissions and privacy rules.","Disclosure and privacy reviewer","Generic ownership, consent, access enforcement, audit-trail or enterprise risk machinery","Access Contract / Consent supplies scoped authorization; security evidence and TLP markings do not issue grants."],"affectedParties":[]},"owners":{"steward":"Adopting system steward role and accountable security coordinator with scoped delegation","roles":[{"name":"System steward","responsibilities":["Accountable for host binding, scope and delegation."]},{"name":"Security analyst","responsibilities":["Submits evidence-qualified assertions and preserves uncertainty."]},{"name":"Security reviewer","responsibilities":["Reviews applicability, freshness and verification claims independently of their submitter where policy requires."]},{"name":"Response liaison","responsibilities":["Links authorized incident and recovery records without executing their workflows."]},{"name":"Disclosure and privacy reviewer","responsibilities":["Approves candidate recipient views and retention decisions within an explicit mandate."]}],"masterSystems":[]},"relations":[{"target":"WM-SFT-002","type":"references","note":"Software System / Business Application is a candidate host master; local attachment does not duplicate system inventory or lifecycle."},{"target":"WM-OBJ-008","type":"references","note":"Device / Sensor / Compute HW is an alternative host master; physical properties and device control stay external."},{"target":"WM-SFT-018","type":"references","note":"Network / Endpoint may provide a protected endpoint reference; address, reachability and topology authority stay external."},{"target":"WM-SFT-001","type":"references","note":"Software Product is a product reference, not a replacement for a concrete deployed host. Resolve legacy N4 ambiguity explicitly."},{"target":"WM-SFT-006","type":"references","note":"Vulnerability Record owns vulnerability identity, advisory lifecycle and public/private identifiers; carry scoped local applicability only."},{"target":"WM-ACT-020","type":"references","note":"Cyber Incident owns the incident record and declaration lifecycle; carry host association and attributed impact references only."},{"target":"WM-ACT-042","type":"references","note":"Incident Response owns operational response, containment and recovery execution; local functions cannot initiate these operations."},{"target":"WM-XCT-027","type":"references","note":"Risk / Control owns generic risk and control bindings and acceptance decisions; carry security-specific baseline and decision references."},{"target":"WM-XCT-001","type":"references","note":"Ownership / Stewardship supplies responsibility and delegation references; legal title and ownership transfer remain external."},{"target":"WM-XCT-002","type":"references","note":"Access Contract / Consent supplies scoped authorization; security evidence and TLP markings do not issue grants."},{"target":"WM-XCT-004","type":"references","note":"Access Audit retains authoritative access-event records; link evidence without owning audit-trail semantics."},{"target":"WM-XCT-007","type":"references","note":"Access Breach / Enforcement owns distinct access-violation cases; cyber compromise is not automatically an access-contract violation."},{"target":"WM-SFT-017","type":"references","note":"Telemetry / Operational Signal owns observations and collection context; local interpretation does not perform detection or redefine raw telemetry."},{"target":"WM-XCT-035","type":"references","note":"Retention / Disposition supplies retention and hold policy bindings; destruction execution remains in its authorized external process."},{"target":"NIST CSF 2.0","type":"aligned","note":"Conceptual mapping to selected outcomes and profiles; no blanket conformance or certification."},{"target":"OASIS CSAF 2.0","type":"aligned","note":"Advisory and product-status mapping only; pin errata and validate an actual exchange before claiming conformance."},{"target":"STIX 2.1","type":"aligned","note":"Selected threat, observation and marking concepts only; no lossless implementation claimed."},{"target":"CVSS 4.0","type":"aligned","note":"Carry attributed severity vectors and metric-group labels; no score calculator or risk engine."},{"target":"TLP 2.0","type":"aligned","note":"Record sharing restrictions without replacing applicable access or legal rules."},{"target":"RFC 9334","type":"aligned","note":"Conceptual separation of received evidence and results from appraisal and enforcement; no attestation protocol implementation."},{"target":"WM-SFT-002","type":"neighbor","note":"Software System / Business Application is a candidate host master; local attachment does not duplicate system inventory or lifecycle."},{"target":"WM-OBJ-008","type":"neighbor","note":"Device / Sensor / Compute HW is an alternative host master; physical properties and device control stay external."},{"target":"WM-SFT-018","type":"neighbor","note":"Network / Endpoint may provide a protected endpoint reference; address, reachability and topology authority stay external."},{"target":"WM-SFT-001","type":"neighbor","note":"Software Product is a product reference, not a replacement for a concrete deployed host. Resolve legacy N4 ambiguity explicitly."},{"target":"WM-SFT-006","type":"neighbor","note":"Vulnerability Record owns vulnerability identity, advisory lifecycle and public/private identifiers; carry scoped local applicability only."},{"target":"WM-ACT-020","type":"neighbor","note":"Cyber Incident owns the incident record and declaration lifecycle; carry host association and attributed impact references only."},{"target":"WM-ACT-042","type":"neighbor","note":"Incident Response owns operational response, containment and recovery execution; local functions cannot initiate these operations."},{"target":"WM-XCT-027","type":"neighbor","note":"Risk / Control owns generic risk and control bindings and acceptance decisions; carry security-specific baseline and decision references."},{"target":"WM-XCT-001","type":"neighbor","note":"Ownership / Stewardship supplies responsibility and delegation references; legal title and ownership transfer remain external."},{"target":"WM-XCT-002","type":"neighbor","note":"Access Contract / Consent supplies scoped authorization; security evidence and TLP markings do not issue grants."},{"target":"WM-XCT-004","type":"neighbor","note":"Access Audit retains authoritative access-event records; link evidence without owning audit-trail semantics."},{"target":"WM-XCT-007","type":"neighbor","note":"Access Breach / Enforcement owns distinct access-violation cases; cyber compromise is not automatically an access-contract violation."},{"target":"WM-SFT-017","type":"neighbor","note":"Telemetry / Operational Signal owns observations and collection context; local interpretation does not perform detection or redefine raw telemetry."},{"target":"WM-XCT-035","type":"neighbor","note":"Retention / Disposition supplies retention and hold policy bindings; destruction execution remains in its authorized external process."},{"target":"Legacy S8 and unreviewed supplement","type":"neighbor","note":"Treat legacy hierarchy and events as leads. Preserve weakness, threat, incident linkage and assurance concerns but move vulnerability and incident masters outward. Legacy M8/N4 labels conflict with current registry identities; bind by verified model ID and actual host kind. Legacy conformance labels and wildcard imports are not admitted."}],"interaction":{"identity":{"applicability":"required","items":["Authoritative master-system identifier","Governed global identifier or IRI","UUID or ULID assigned by the adopting Dimension"]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":[]},"capabilities":{"applicability":"required","items":["Bind host context: Proposed local operation, not implemented. Creates only the local security attachment; ambiguous host binding is refused.","Record applicability assertion: Proposed local operation, not implemented. Records the submitted assessment; no automatic vulnerability detection or clearance.","Link threat interpretation: Proposed local operation, not implemented. Links existing evidence; does not run detection, attribute an actor as fact or declare compromise.","Record assurance evidence: Proposed local operation, not implemented. Records received evidence disposition; does not perform cryptographic attestation or certify security.","Reconcile treatment references: Proposed local operation, not implemented. Updates local references only; does not install, contain, recover or close an external incident.","Prepare restricted view: Proposed local operation, not implemented. Produces a local candidate view only; no transmission, permission expansion or embargo release."]},"hazards":{"applicability":"optional","items":[]},"interfaces":{"applicability":"required","items":["The NIST Cybersecurity Framework (CSF) 2.0"]},"context":{"applicability":"required","items":["Cited sources provide technical guidance and exchange concepts, not a universal legal regime.","Adopting jurisdiction and sector determine reporting duties, evidence retention and authority.","NIST guidance is used as a conceptual source without importing federal mandates."]}},"sources":[{"title":"The NIST Cybersecurity Framework (CSF) 2.0","url":"https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf","note":"National Institute of Standards and Technology"},{"title":"Common Security Advisory Framework Version 2.0","url":"https://docs.oasis-open.org/csaf/csaf/v2.0/os/csaf-v2.0-os.html","note":"OASIS Open"},{"title":"Common Vulnerability Scoring System version 4.0: Specification Document","url":"https://www.first.org/cvss/v4.0/specification-document","note":"Forum of Incident Response and Security Teams"},{"title":"STIX Version 2.1","url":"https://docs.oasis-open.org/cti/stix/v2.1/os/stix-v2.1-os.html","note":"OASIS Open"},{"title":"Traffic Light Protocol (TLP): Standards Definitions and Usage Guidance","url":"https://www.first.org/tlp/","note":"Forum of Incident Response and Security Teams"},{"title":"Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile","url":"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r3.pdf","note":"National Institute of Standards and Technology"},{"title":"Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology","url":"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-40r4.pdf","note":"National Institute of Standards and Technology"},{"title":"Remote ATtestation procedureS (RATS) Architecture","url":"https://www.rfc-editor.org/rfc/rfc9334.html","note":"Internet Engineering Task Force"}],"openQuestions":["Restore independent external review before canonical or publishable-draft promotion.","Complete source reachability, version and errata checks with substantive claim review, including a pinned CSAF errata policy.","Develop adopting profiles and executable cases for ambiguous hosts, conflicting advisories, stale attestation, indicator false positives, rollback, withheld evidence, privacy and lawful erasure.","Reconcile and pin external model versions and legacy host identities with the coordinator before instance migration.","Independent external review absent under the single-provider waiver.","Direct HTTP checks not attempted under owner-reported sandbox restriction; selected browser readings do not verify all errata or current versions.","Nested instance schemas, stable neighbor version pins, exchange conformance and executable adversarial fixtures remain incomplete.","Jurisdictional obligations, disclosure licensing, operational safety and specialized sector profiles require adopting expert review."],"resources":{"spec":"/models/wm-xct-019-cyber-integrity/spec.yaml","agents":"/models/wm-xct-019-cyber-integrity/AGENTS.md","source":"https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-xct-019"},"provenance":{"origin":"world-models research","builtFrom":["models/wm-xct-019-cyber-integrity/spec.yaml"],"providers":["Codex"],"researchStatus":"reviewable-draft","generatedAt":"2026-10-06T13:49:54Z","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"filled","purpose":"filled","distinguishingFeatures":"derived","structure":"filled","agentConduct":"derived","ethics":"derived","owners":"filled","relations":"filled","interaction.identity":"filled","interaction.properties":"not-applicable","interaction.recognition":"missing","interaction.capabilities":"filled","interaction.hazards":"missing","interaction.interfaces":"derived","interaction.context":"filled","sources":"filled"},"notes":{"distinguishingFeatures":"Derived from boundary notes against neighbouring models.","agentConduct":"Derived from functions, policies, CRUD and access rules; prohibitions were not authored for agents as such.","ethics":"Sentences mentioning harm, privacy, consent or similar, collected from the specification.","interaction.properties":"Institutional or informational subject: no invented physical properties."},"score":0.75}}