World Models · Published

Cyber Incident

Represent an occurrence or linked set of occurrences determined to have actually or imminently compromised protected digital systems, information, services or computer-controlled infrastructure, together with evolving evidence-backed scope, impact and resolution facts.

AI YAMLAGENTS.mdResearch evidence
Published. Research assurance: reviewable-draft. The Codex-only synthesis is published under an explicit repository-owner provider waiver. It passed structural validation and a separate no-tools adversarial audit, but remains a reviewable draft until independent second-provider review and the holds below are closed.
Catalogue IDWM-ACT-020
Version0.3.0-research.1
Previous version-
Typeaggregate
ValidationPassed
Synthesis digestsha256:789e44c2ef79f751…
7Sources
7Bundles
16Layers
32Findings
96Questions
19Artifacts
Format-independent logical structure

Bundles → Layers → Findings → Questions + Artifacts

identity-and-determinationIdentity and determination3 layers

Establishes the incident record, the qualification decision and identity continuity.

incident-identityIncident identity2 findings

Stable identity, aliases and cross-system correlation.

authoritative-incident-identity

Authoritative incident identity

The master-system identifier, record authority, version and namespace of the incident aggregate.

Questions
  1. What is currently asserted about authoritative incident identity for this cyber incident, and is it confirmed, suspected, disputed or unknown?identity
    Expected answer
    • Authoritative incident identity
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports authoritative incident identity, at what event and observation times, and with what confidence?ownership
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise authoritative incident identity without destroying its history?security
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
Artifacts
  • Authoritative incident identity recordVersioned incident-owned record supporting authoritative incident identity with provenance and access marking.
aliases-and-correlation-keys

Aliases and correlation keys

Alternative incident identifiers, external references and bounded correlation keys used across organizations and tools.

Questions
  1. What is currently asserted about aliases and correlation keys for this cyber incident, and is it confirmed, suspected, disputed or unknown?interoperability
    Expected answer
    • Aliases and correlation keys
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports aliases and correlation keys, at what event and observation times, and with what confidence?constraint
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise aliases and correlation keys without destroying its history?definition
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
qualification-and-declarationQualification and declaration2 findings

The evidence-based transition from reported event to declared incident.

incident-definition-binding

Incident definition binding

The pinned organizational, statutory or profile definition against which the occurrence is qualified.

Questions
  1. What is currently asserted about incident definition binding for this cyber incident, and is it confirmed, suspected, disputed or unknown?classification
    Expected answer
    • Incident definition binding
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports incident definition binding, at what event and observation times, and with what confidence?measurement
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise incident definition binding without destroying its history?temporal
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
qualification-and-declaration-decision

Qualification and declaration decision

The determination, authority, rationale, confidence and effective time for declaring, rejecting or revoking incident status.

Questions
  1. What is currently asserted about qualification and declaration decision for this cyber incident, and is it confirmed, suspected, disputed or unknown?decision
    Expected answer
    • Qualification and declaration decision
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports qualification and declaration decision, at what event and observation times, and with what confidence?validation
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise qualification and declaration decision without destroying its history?process
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
Artifacts
  • Qualification and declaration decision recordVersioned incident-owned record supporting qualification and declaration decision with provenance and access marking.
identity-continuityIdentity continuity2 findings

Duplicate resolution, merge, split, supersession and reopening.

duplicate-merge-and-split

Duplicate, merge and split

Governed relations and rationale when reports or event groups are deduplicated, merged into one incident or split into several incidents.

Questions
  1. What is currently asserted about duplicate, merge and split for this cyber incident, and is it confirmed, suspected, disputed or unknown?relationship
    Expected answer
    • Duplicate, merge and split
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports duplicate, merge and split, at what event and observation times, and with what confidence?retention
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise duplicate, merge and split without destroying its history?privacy
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
Artifacts
  • Duplicate, merge and split recordVersioned incident-owned record supporting duplicate, merge and split with provenance and access marking.
supersession-and-reopening

Supersession and reopening

Identity-preserving rules for a corrected successor, revoked determination, recurring activity or reopened incident record.

Questions
  1. What is currently asserted about supersession and reopening for this cyber incident, and is it confirmed, suspected, disputed or unknown?lifecycle
    Expected answer
    • Supersession and reopening
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports supersession and reopening, at what event and observation times, and with what confidence?interoperability
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise supersession and reopening without destroying its history?identity
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
Artifacts
  • Supersession and reopening recordVersioned incident-owned record supporting supersession and reopening with provenance and access marking.
occurrence-and-chronologyOccurrence and chronology2 layers

Represents constituent events, ordering and the distinct clocks by which an incident becomes known.

constituent-eventsConstituent events2 findings

Incident membership and relationships among observed cyber events.

event-membership

Event membership

References to cyber events accepted, suspected or rejected as constituents of the incident, with membership rationale.

Questions
  1. What is currently asserted about event membership for this cyber incident, and is it confirmed, suspected, disputed or unknown?composition
    Expected answer
    • Event membership
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports event membership, at what event and observation times, and with what confidence?identity
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise event membership without destroying its history?spatial
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
causal-and-sequence-relations

Causal and sequence relations

Observed ordering, concurrency, dependency and claimed causal links among incident events without promoting hypotheses to facts.

Questions
  1. What is currently asserted about causal and sequence relations for this cyber incident, and is it confirmed, suspected, disputed or unknown?relationship
    Expected answer
    • Causal and sequence relations
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports causal and sequence relations, at what event and observation times, and with what confidence?state
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise causal and sequence relations without destroying its history?event
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
incident-timeIncident time2 findings

Occurrence, detection, observation, declaration and knowledge times.

temporal-markers

Temporal markers

Distinct start, end, detection, report, declaration, recovery, observation and ingestion timestamps with uncertainty.

Questions
  1. What is currently asserted about temporal markers for this cyber incident, and is it confirmed, suspected, disputed or unknown?temporal
    Expected answer
    • Temporal markers
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports temporal markers, at what event and observation times, and with what confidence?spatial
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise temporal markers without destroying its history?retention
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
Artifacts
  • Temporal markers recordVersioned incident-owned record supporting temporal markers with provenance and access marking.
ongoing-imminent-and-recurring

Ongoing, imminent and recurring occurrence

Whether compromise is ongoing, imminent, intermittent or recurring, including the evidence and interval basis.

Questions
  1. What is currently asserted about ongoing, imminent and recurring occurrence for this cyber incident, and is it confirmed, suspected, disputed or unknown?state
    Expected answer
    • Ongoing, imminent and recurring occurrence
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports ongoing, imminent and recurring occurrence, at what event and observation times, and with what confidence?ownership
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise ongoing, imminent and recurring occurrence without destroying its history?classification
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
affected-scopeAffected scope2 layers

Describes direct and propagated reach using governed references and explicit assertion status.

affected-subjectsAffected subjects2 findings

Directly affected technical and organizational subjects.

affected-systems-services-and-networks

Affected systems, services and networks

References to systems, services, networks, accounts and computer-controlled infrastructure with role and affected interval.

Questions
  1. What is currently asserted about affected systems, services and networks for this cyber incident, and is it confirmed, suspected, disputed or unknown?relationship
    Expected answer
    • Affected systems, services and networks
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports affected systems, services and networks, at what event and observation times, and with what confidence?constraint
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise affected systems, services and networks without destroying its history?provenance
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
affected-information-identities-and-parties

Affected information, identities and parties

References and bounded counts for information, records, credentials, people and organizations affected or exposed.

Questions
  1. What is currently asserted about affected information, identities and parties for this cyber incident, and is it confirmed, suspected, disputed or unknown?privacy
    Expected answer
    • Affected information, identities and parties
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports affected information, identities and parties, at what event and observation times, and with what confidence?measurement
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise affected information, identities and parties without destroying its history?evidence
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
scope-reach-and-certaintyScope reach and certainty2 findings

Dependency propagation and changing confidence in affected-scope claims.

dependency-and-supply-chain-reach

Dependency and supply-chain reach

Potential or confirmed propagation through service, supplier, tenant, identity and data dependencies.

Questions
  1. What is currently asserted about dependency and supply-chain reach for this cyber incident, and is it confirmed, suspected, disputed or unknown?relationship
    Expected answer
    • Dependency and supply-chain reach
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports dependency and supply-chain reach, at what event and observation times, and with what confidence?validation
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise dependency and supply-chain reach without destroying its history?access
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
scope-assertion-status

Scope assertion status

Confirmed, suspected, disputed or disproven affected-scope assertions with assessor, method, confidence and history.

Questions
  1. What is currently asserted about scope assertion status for this cyber incident, and is it confirmed, suspected, disputed or unknown?quality
    Expected answer
    • Scope assertion status
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports scope assertion status, at what event and observation times, and with what confidence?retention
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise scope assertion status without destroying its history?composition
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
Artifacts
  • Scope assertion status recordVersioned incident-owned record supporting scope assertion status with provenance and access marking.
security-effect-and-impactSecurity effect and impact3 layers

Separates the security property affected from technical, operational, human and legal consequences.

security-effectsSecurity effects2 findings

Compromised security properties and policy or legal violations.

confidentiality-integrity-availability-authenticity

Confidentiality, integrity, availability and authenticity

Observed or threatened compromise of security properties, affected objects, degree and supporting evidence.

Questions
  1. What is currently asserted about confidentiality, integrity, availability and authenticity for this cyber incident, and is it confirmed, suspected, disputed or unknown?security
    Expected answer
    • Confidentiality, integrity, availability and authenticity
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports confidentiality, integrity, availability and authenticity, at what event and observation times, and with what confidence?interoperability
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise confidentiality, integrity, availability and authenticity without destroying its history?ownership
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
Artifacts
  • Confidentiality, integrity, availability and authenticity recordVersioned incident-owned record supporting confidentiality, integrity, availability and authenticity with provenance and access marking.
policy-law-and-authority-effect

Policy, law and authority effect

The alleged or confirmed security-policy, acceptable-use, legal or lawful-authority condition implicated by the occurrence.

Questions
  1. What is currently asserted about policy, law and authority effect for this cyber incident, and is it confirmed, suspected, disputed or unknown?authority
    Expected answer
    • Policy, law and authority effect
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports policy, law and authority effect, at what event and observation times, and with what confidence?identity
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise policy, law and authority effect without destroying its history?evidence
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
impact-domainsImpact domains2 findings

Consequences beyond the immediate technical effect.

operational-safety-and-privacy-impact

Operational, safety and privacy impact

Service disruption, physical-safety implications and effects on rights or personal data, with actual versus potential status.

Questions
  1. What is currently asserted about operational, safety and privacy impact for this cyber incident, and is it confirmed, suspected, disputed or unknown?measurement
    Expected answer
    • Operational, safety and privacy impact
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports operational, safety and privacy impact, at what event and observation times, and with what confidence?relationship
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise operational, safety and privacy impact without destroying its history?exception
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
Artifacts
  • Operational, safety and privacy impact recordVersioned incident-owned record supporting operational, safety and privacy impact with provenance and access marking.
financial-societal-and-cross-border-impact

Financial, societal and cross-border impact

Material and non-material damage, financial loss, constituency reach and cross-border effect assertions.

Questions
  1. What is currently asserted about financial, societal and cross-border impact for this cyber incident, and is it confirmed, suspected, disputed or unknown?measurement
    Expected answer
    • Financial, societal and cross-border impact
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports financial, societal and cross-border impact, at what event and observation times, and with what confidence?temporal
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise financial, societal and cross-border impact without destroying its history?relationship
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
Artifacts
  • Financial, societal and cross-border impact recordVersioned incident-owned record supporting financial, societal and cross-border impact with provenance and access marking.
severity-and-significanceSeverity and significance2 findings

Profile-bound prioritization and regulatory classifications.

severity-assessment

Severity assessment

Severity or priority value together with scheme, version, assessor, inputs, confidence and effective time.

Questions
  1. What is currently asserted about severity assessment for this cyber incident, and is it confirmed, suspected, disputed or unknown?classification
    Expected answer
    • Severity assessment
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports severity assessment, at what event and observation times, and with what confidence?ownership
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise severity assessment without destroying its history?authority
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
Artifacts
  • Severity assessment recordVersioned incident-owned record supporting severity assessment with provenance and access marking.
regulatory-significance-bindings

Regulatory significance bindings

Jurisdiction and regime-specific determinations such as significant incident or personal-data breach, with threshold evidence and obligation reference.

Questions
  1. What is currently asserted about regulatory significance bindings for this cyber incident, and is it confirmed, suspected, disputed or unknown?requirement
    Expected answer
    • Regulatory significance bindings
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports regulatory significance bindings, at what event and observation times, and with what confidence?constraint
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise regulatory significance bindings without destroying its history?quality
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
Artifacts
  • Regulatory significance bindings recordVersioned incident-owned record supporting regulatory significance bindings with provenance and access marking.
mechanism-and-attributionMechanism and attribution2 layers

Records evidence-backed causal, exploit, technique and actor assertions without absorbing neighboring security-object lifecycles.

cause-and-exploitCause and exploit2 findings

Root-cause hypotheses and referenced weaknesses or exposures.

cause-and-enabling-condition-hypotheses

Cause and enabling-condition hypotheses

Competing root-cause, misconfiguration, failure, human-action and enabling-condition hypotheses with evidence and confidence.

Questions
  1. What is currently asserted about cause and enabling-condition hypotheses for this cyber incident, and is it confirmed, suspected, disputed or unknown?provenance
    Expected answer
    • Cause and enabling-condition hypotheses
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports cause and enabling-condition hypotheses, at what event and observation times, and with what confidence?measurement
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise cause and enabling-condition hypotheses without destroying its history?interoperability
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
Artifacts
  • Cause and enabling-condition hypotheses recordVersioned incident-owned record supporting cause and enabling-condition hypotheses with provenance and access marking.
vulnerability-and-exposure-references

Vulnerability and exposure references

References to exploited or suspected vulnerabilities and concrete exposures without owning disclosure, scoring or remediation state.

Questions
  1. What is currently asserted about vulnerability and exposure references for this cyber incident, and is it confirmed, suspected, disputed or unknown?relationship
    Expected answer
    • Vulnerability and exposure references
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports vulnerability and exposure references, at what event and observation times, and with what confidence?validation
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise vulnerability and exposure references without destroying its history?state
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
technique-indicator-and-attributionTechnique, indicator and attribution2 findings

Observed mechanisms and bounded claims about responsible activity.

technique-indicator-and-observable-references

Technique, indicator and observable references

References to attack patterns, indicators, observables, tools and infrastructure with observed role and time.

Questions
  1. What is currently asserted about technique, indicator and observable references for this cyber incident, and is it confirmed, suspected, disputed or unknown?evidence
    Expected answer
    • Technique, indicator and observable references
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports technique, indicator and observable references, at what event and observation times, and with what confidence?retention
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise technique, indicator and observable references without destroying its history?requirement
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
actor-campaign-and-attribution-claims

Actor, campaign and attribution claims

Competing links to actors, campaigns or intrusion sets with source, analytic basis, confidence and disclosure marking.

Questions
  1. What is currently asserted about actor, campaign and attribution claims for this cyber incident, and is it confirmed, suspected, disputed or unknown?provenance
    Expected answer
    • Actor, campaign and attribution claims
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports actor, campaign and attribution claims, at what event and observation times, and with what confidence?interoperability
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise actor, campaign and attribution claims without destroying its history?validation
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
Artifacts
  • Actor, campaign and attribution claims recordVersioned incident-owned record supporting actor, campaign and attribution claims with provenance and access marking.
evidence-provenance-and-governanceEvidence, provenance and governance2 layers

Makes observations, evidence references, epistemic status and controlled disclosure explicit.

observations-and-evidenceObservations and evidence2 findings

Source reports, technical observations and preserved evidence bindings.

reports-observations-and-discovery

Reports, observations and discovery

Source reports, discovery methods, observations, sensor or analyst provenance, reliability and observation conditions.

Questions
  1. What is currently asserted about reports, observations and discovery for this cyber incident, and is it confirmed, suspected, disputed or unknown?provenance
    Expected answer
    • Reports, observations and discovery
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports reports, observations and discovery, at what event and observation times, and with what confidence?identity
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise reports, observations and discovery without destroying its history?decision
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
Artifacts
  • Reports, observations and discovery recordVersioned incident-owned record supporting reports, observations and discovery with provenance and access marking.
evidence-integrity-and-custody-references

Evidence integrity and custody references

References to forensic artifacts and custody records with digest, collector, preservation state and access boundary.

Questions
  1. What is currently asserted about evidence integrity and custody references for this cyber incident, and is it confirmed, suspected, disputed or unknown?evidence
    Expected answer
    • Evidence integrity and custody references
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports evidence integrity and custody references, at what event and observation times, and with what confidence?relationship
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise evidence integrity and custody references without destroying its history?lifecycle
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
epistemic-and-disclosure-controlsEpistemic and disclosure controls2 findings

Truth status, markings, access, retention and projections.

fact-assessment-allegation-and-unknown

Fact, assessment, allegation and unknown

Explicit epistemic status for each material assertion, including contradiction sets and the authority able to resolve them.

Questions
  1. What is currently asserted about fact, assessment, allegation and unknown for this cyber incident, and is it confirmed, suspected, disputed or unknown?quality
    Expected answer
    • Fact, assessment, allegation and unknown
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports fact, assessment, allegation and unknown, at what event and observation times, and with what confidence?temporal
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise fact, assessment, allegation and unknown without destroying its history?constraint
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
Artifacts
  • Fact, assessment, allegation and unknown recordVersioned incident-owned record supporting fact, assessment, allegation and unknown with provenance and access marking.
disclosure-access-privacy-and-retention

Disclosure, access, privacy and retention

Information marking, permitted projection, privacy constraints, legal hold and retention or deletion binding.

Questions
  1. What is currently asserted about disclosure, access, privacy and retention for this cyber incident, and is it confirmed, suspected, disputed or unknown?access
    Expected answer
    • Disclosure, access, privacy and retention
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports disclosure, access, privacy and retention, at what event and observation times, and with what confidence?ownership
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise disclosure, access, privacy and retention without destroying its history?security
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
Artifacts
  • Disclosure, access, privacy and retention recordVersioned incident-owned record supporting disclosure, access, privacy and retention with provenance and access marking.
state-resolution-and-federationState, resolution and federation2 layers

Tracks incident-owned factual state and closure while connecting external response cases and exchange representations.

incident-state-and-resolutionIncident state and resolution2 findings

Current incident condition, impact cessation and residual exposure.

incident-factual-state

Incident factual state

Profile-bound incident state, allowed transition, triggering evidence, actor and effective time, separate from response-task status.

Questions
  1. What is currently asserted about incident factual state for this cyber incident, and is it confirmed, suspected, disputed or unknown?state
    Expected answer
    • Incident factual state
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports incident factual state, at what event and observation times, and with what confidence?constraint
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise incident factual state without destroying its history?definition
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
Artifacts
  • Incident factual state recordVersioned incident-owned record supporting incident factual state with provenance and access marking.
impact-cessation-residual-exposure-and-recurrence

Impact cessation, residual exposure and recurrence

Evidence that harmful effects ceased or persist, remaining exposure, recurrence indicators and uncertainty.

Questions
  1. What is currently asserted about impact cessation, residual exposure and recurrence for this cyber incident, and is it confirmed, suspected, disputed or unknown?validation
    Expected answer
    • Impact cessation, residual exposure and recurrence
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports impact cessation, residual exposure and recurrence, at what event and observation times, and with what confidence?measurement
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise impact cessation, residual exposure and recurrence without destroying its history?temporal
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
Artifacts
  • Impact cessation, residual exposure and recurrence recordVersioned incident-owned record supporting impact cessation, residual exposure and recurrence with provenance and access marking.
closure-and-external-bindingsClosure and external bindings2 findings

Closure basis, response-case linkage and exchange mappings.

closure-reclassification-and-disposition

Closure, reclassification and disposition

The evidence-backed decision to close, revoke, reclassify or reopen the incident and its unresolved facts or obligations.

Questions
  1. What is currently asserted about closure, reclassification and disposition for this cyber incident, and is it confirmed, suspected, disputed or unknown?lifecycle
    Expected answer
    • Closure, reclassification and disposition
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports closure, reclassification and disposition, at what event and observation times, and with what confidence?validation
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise closure, reclassification and disposition without destroying its history?process
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference
Artifacts
  • Closure, reclassification and disposition recordVersioned incident-owned record supporting closure, reclassification and disposition with provenance and access marking.
response-case-and-federation-bindings

Response-case and federation bindings

References to response cases, reporting workflows and external incident representations with mapping, projection and correlation rules.

Questions
  1. What is currently asserted about response-case and federation bindings for this cyber incident, and is it confirmed, suspected, disputed or unknown?interoperability
    Expected answer
    • Response-case and federation bindings
    • epistemic status
    • applicable scope or explicit unknown
  2. Which source, observer or authority supports response-case and federation bindings, at what event and observation times, and with what confidence?retention
    Expected answer
    • source or authority reference
    • event and observation timestamps
    • confidence and evidence reference
  3. Which validation, contradiction or change rule can revise response-case and federation bindings without destroying its history?privacy
    Expected answer
    • validation or conflict rule
    • authorized revision event
    • predecessor, successor or counterclaim reference

Publication holds

  • Claude and Grok timed out during their bounded attempts, so independent external review is absent and explicitly waived for this published reviewable draft.
  • Clause-level mappings, exact external schema versions and implementation profiles remain unverified for canonical conformance even though the cited official source URLs were reachable during Codex research.
  • The candidate registry COMPOSE edge to WM-ACT-042 conflicts with the incident-response separation rationale and must be reconciled to REFERENCE in the shared relation ledger.
  • Sector and jurisdiction profiles must validate state vocabularies, severity and significance thresholds, reporting duties, closure rules and retention periods before operational enforcement.
  • Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft.

Deferred research

  • Validate the logical structure against current CSIRT, SOC, cloud, operational-technology, healthcare, financial-sector and public-authority incident profiles.
  • Create clause-level crosswalks for IODEF Version 2, STIX incident extensions, national NIS2 implementations and regulator reporting schemas.
  • Pin sibling model identifiers and cardinality contracts for events, observations, evidence, affected assets, CTI objects, legal obligations and response cases.
  • Review generated question wording with incident handlers, forensic specialists, privacy officers and operational-risk owners.