Vulnerability, affectedness and remediation
Vulnerability description, affectedness assessment, priority and remediation confirmation. A discovered weakness is not identical to its exploitation.
Research draft, second pass
A second pass drafted this model: the structure a model of this thing needs, and what is known about it in the world. The line under this one says how the second half was obtained - researched against sources, or recalled without web access, in which case nothing here was read anywhere and every claim is a lead to verify. Unreviewed either way.
Bundle → Layer → Finding → Questions Missing, in the backlog
Not described yet. This gap is in the card backlog.
Note: Research contour: bundles not designed yet; questions are listed as open questions.
Classifiers Filled
- Family
- Enterprise profiles
- Category
- Enterprise subject
- Entry kind
- subject
- Domain
- EnterpriseTEC
- Industry
- Cross-industry
- Tags
- EM-TEC-07W2subjectVulnerabilityAffectednessAssessmentRemediationExploitEvidence
What it is Filled
Vulnerability description, affectedness assessment, priority and remediation confirmation. A discovered weakness is not identical to its exploitation.
Why it exists Filled
Vulnerability description, affectedness assessment, priority and remediation confirmation. A discovered weakness is not identical to its exploitation.
Distinguishing features Derived, awaiting review
- CVE is not the only admissible ID
- An assessment specifies a version and a context
- A closed ticket is not proof of remediation
What robots and AI may and may not do Derived, awaiting review
Must not
- Negative case: The presence of a CVE in a transitive dependency automatically means a confirmed incident.
Note: Negative case of the research brief, not yet a rule for agents.
Moral aspects Missing, in the backlog
Not described yet. This gap is in the card backlog.
Owners Filled
Steward
CTO / CIO / владелец сервиса
Master systems
- Каталог ПО
- Git
- CI/CD
- CMDB
- observability
Links to other meta-models Filled
neighbor
- EM-TEC-01
references
- WM-SFT-006 - conceptual-candidate
What else AI and robots need to interact with it Incomplete
Identity and identifiers required Derived, awaiting review
- Vulnerability
- AffectednessAssessment
- Remediation
- ExploitEvidence
Direct properties not applicable Not applicable
Not applicable
Enterprise record contour: physical properties belong to referenced world models.
Recognition required Missing, in the backlog
Not described yet. This gap is in the card backlog.
Capabilities and actions required Missing, in the backlog
Not described yet. This gap is in the card backlog.
Hazards and failure modes required Missing, in the backlog
Not described yet. This gap is in the card backlog.
Standards and interfaces required Missing, in the backlog
Not described yet. This gap is in the card backlog.
Context of use required Missing, in the backlog
Not described yet. This gap is in the card backlog.
Sources Filled
- AISMM/WM-SFT and ArchiMate: product, system and architecture
- CSDM: business application, service and runtime instance
- SPDX/OpenTelemetry/Google SRE: delivery, observation and reliability; choose by boundary
Open questions
- When is a component version actually affected?
- How to distinguish generic severity from contextual risk?
- How to prove a fix in production?
- Установить границу и решение reuse/extend/new по действующим спецификациям.
- Подтвердить semantic crosswalk, права и source mastership.
- Выбрать immutable refs; провести проверки fixtures до заявления о публикационной готовности.
Machine files
Provenance
enterprise research programme · published-partial
Built from: enterprise/models/em-tec-07/brief.json
Still in Russian: suggested owner, blocking decisions, vercy candidates. Translate in research/enterprise/i18n/units.en.json.