# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-09-05T22:18:48Z", "synthesisSha256": "789e44c2ef79f7515d552880e820895d1699bdb4deb90426a75527e4b85c366e", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-ACT-020", "registryId": "vr.wm-act-020", "name": "Cyber Incident", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "aggregate", "family": "World Models", "category": "Activities and processes", "industry": [ "Cross-industry" ], "domain": [ "ACT.CYB" ], "tags": [ "cyber", "incident", "act.cyb" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-act-020-cyber-incident/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-act-020", "model": { "registry_id": "vr.wm-act-020", "model_id": "WM-ACT-020", "name": "Cyber Incident", "entry_kind": "aggregate", "purpose": "Represent an occurrence or linked set of occurrences determined to have actually or imminently compromised protected digital systems, information, services or computer-controlled infrastructure, together with evolving evidence-backed scope, impact and resolution facts.", "scope_statement": "Owns incident identity, qualification, constituent-event grouping, chronology, affected-scope assertions, security effects, impact assessments, hypotheses, factual state, evidence indexes, disclosure controls and closure decisions while referencing response workflow and neighboring security objects.", "in_scope": [ "Incident identity, qualification authority, chronology, affected scope, security effects, impact and factual lifecycle", "Evidence-backed cause and attribution hypotheses, incident-owned assessments, external bindings and controlled projections", "Typed references to vulnerabilities, events, indicators, actors, systems, evidence and response cases" ], "out_of_scope": [ "Incident-response workflow, responder tasks, containment or recovery execution, notifications, playbooks and lessons-learned processes", "Vulnerability disclosure, scoring and remediation lifecycle or the lifecycle of threats, indicators, controls, assets, people and organizations", "Generic evidence custody, access enforcement, audit persistence and legal adjudication beyond incident-local bindings" ], "boundary_notes": [ { "neighbor": "Cyber event or alert", "distinction": "An event or alert is an observation or signal; a cyber incident is a qualified occurrence aggregate that meets a pinned definition and carries a governed declaration decision.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005" ] }, { "neighbor": "Cyber incident response", "distinction": "The incident represents what happened and what is currently known; response cases, tasks and mitigation or recovery execution are independently governed and linked by reference.", "source_refs": [ "SRC-001", "SRC-005" ] }, { "neighbor": "Vulnerability or exposure", "distinction": "A vulnerability or exposure may enable an incident, but its disclosure, scoring, affected-version and remediation lifecycle stays in WM-SFT-006 or another authoritative security model.", "source_refs": [ "SRC-003", "SRC-005" ] }, { "neighbor": "Personal-data breach or significant incident", "distinction": "These are regime-specific classifications of facts and impact; the incident stores a versioned determination binding but does not own the reporting workflow or legal conclusion lifecycle.", "source_refs": [ "SRC-006", "SRC-007" ] }, { "neighbor": "STIX Incident", "distinction": "STIX 2.1 provides a deliberately limited Incident extension point, so Vercy aligns exchange identity and markings without claiming that the STIX stub defines this full logical model.", "source_refs": [ "SRC-004" ] } ] }, "sources": [ { "id": "SRC-001", "title": "NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management", "organization": "National Institute of Standards and Technology", "url": "https://csrc.nist.gov/pubs/sp/800/61/r3/final", "version_or_date": "Final, April 2025", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T00:00:00Z", "relevance": "Provides the current NIST cybersecurity-incident definition and risk-management context while separating the incident from response activities." }, { "id": "SRC-002", "title": "Computer Security Incident glossary entry", "organization": "National Institute of Standards and Technology", "url": "https://csrc.nist.gov/glossary/term/Computer_Security_Incident", "version_or_date": "Current glossary entry accessed 2026-09-06", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T00:00:00Z", "relevance": "Records the occurrence-based definition, including actual or imminent jeopardy and policy or law violations." }, { "id": "SRC-003", "title": "RFC 7970: The Incident Object Description Exchange Format Version 2", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc7970.html", "version_or_date": "RFC 7970, November 2016", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T00:00:00Z", "relevance": "Defines incident identity, alternative IDs, status, times, assessment, history, event data, contacts, restrictions and exchange semantics." }, { "id": "SRC-004", "title": "STIX Version 2.1", "organization": "OASIS Open", "url": "https://docs.oasis-open.org/cti/stix/v2.1/os/stix-v2.1-os.html", "version_or_date": "OASIS Standard, 10 June 2021", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T00:00:00Z", "relevance": "Supplies CTI identity, versioning, marking and relationship rules, while explicitly declaring its Incident object a limited extension point." }, { "id": "SRC-005", "title": "CSIRT Services Framework Version 2.1", "organization": "Forum of Incident Response and Security Teams", "url": "https://www.first.org/standards/frameworks/csirts/csirt_services_framework_v2.1", "version_or_date": "Version 2.1", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-06T00:00:00Z", "relevance": "Distinguishes event qualification, incident analysis, scope, impact, correlation, evidence and response-service execution." }, { "id": "SRC-006", "title": "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union", "organization": "European Union", "url": "https://eur-lex.europa.eu/eli/dir/2022/2555/oj", "version_or_date": "Directive (EU) 2022/2555, 14 December 2022", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T00:00:00Z", "relevance": "Defines incident, near miss and large-scale incident and provides significance and reporting-information criteria for governed bindings." }, { "id": "SRC-007", "title": "Regulation (EU) 2016/679 General Data Protection Regulation", "organization": "European Union", "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj", "version_or_date": "Regulation (EU) 2016/679, consolidated official text accessed 2026-09-06", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T00:00:00Z", "relevance": "Defines personal-data breach and the facts, effects and remedial-action information that controllers must document." } ], "structure": { "bundles": [ { "id": "identity-and-determination", "name": "Identity and determination", "description": "Establishes the incident record, the qualification decision and identity continuity.", "rationale": "A potential event becomes a cyber incident only through evidence-backed qualification under a declared definition and authority.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-005" ], "layers": [ { "id": "incident-identity", "name": "Incident identity", "description": "Stable identity, aliases and cross-system correlation.", "source_refs": [ "SRC-003", "SRC-004" ], "findings": [ { "id": "authoritative-incident-identity", "name": "Authoritative incident identity", "description": "The master-system identifier, record authority, version and namespace of the incident aggregate.", "source_refs": [ "SRC-003", "SRC-004" ], "questions": [ { "id": "authoritative-incident-identity-q01", "text": "What is currently asserted about authoritative incident identity for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "identity", "answer_data": [ "Authoritative incident identity", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "authoritative-incident-identity-q02", "text": "Which source, observer or authority supports authoritative incident identity, at what event and observation times, and with what confidence?", "kind": "ownership", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "authoritative-incident-identity-q03", "text": "Which validation, contradiction or change rule can revise authoritative incident identity without destroying its history?", "kind": "security", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "authoritative-incident-identity-data", "name": "Authoritative incident identity assertion", "description": "Structured incident-local answer data for authoritative incident identity, including status, effective time and provenance where applicable.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-004" ] } ], "artifacts": [ { "id": "authoritative-incident-identity-artifact", "name": "Authoritative incident identity record", "description": "Versioned incident-owned record supporting authoritative incident identity with provenance and access marking.", "media_or_form": [ "structured incident record", "signed or controlled statement", "resolvable evidence index" ], "serial": true, "identity_strategy": "Authoritative incident master-system identifier first; otherwise a Dimension-governed UUID or ULID.", "source_refs": [ "SRC-003", "SRC-004" ] } ], "inline_only_rationale": null }, { "id": "aliases-and-correlation-keys", "name": "Aliases and correlation keys", "description": "Alternative incident identifiers, external references and bounded correlation keys used across organizations and tools.", "source_refs": [ "SRC-003", "SRC-004" ], "questions": [ { "id": "aliases-and-correlation-keys-q01", "text": "What is currently asserted about aliases and correlation keys for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "interoperability", "answer_data": [ "Aliases and correlation keys", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "aliases-and-correlation-keys-q02", "text": "Which source, observer or authority supports aliases and correlation keys, at what event and observation times, and with what confidence?", "kind": "constraint", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "aliases-and-correlation-keys-q03", "text": "Which validation, contradiction or change rule can revise aliases and correlation keys without destroying its history?", "kind": "definition", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "aliases-and-correlation-keys-data", "name": "Aliases and correlation keys assertion", "description": "Structured incident-local answer data for aliases and correlation keys, including status, effective time and provenance where applicable.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004" ] } ], "artifacts": [], "inline_only_rationale": "This finding stores only typed references and incident-local bindings; the referenced model owns the artifact payload and lifecycle." } ] }, { "id": "qualification-and-declaration", "name": "Qualification and declaration", "description": "The evidence-based transition from reported event to declared incident.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006" ], "findings": [ { "id": "incident-definition-binding", "name": "Incident definition binding", "description": "The pinned organizational, statutory or profile definition against which the occurrence is qualified.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ], "questions": [ { "id": "incident-definition-binding-q01", "text": "What is currently asserted about incident definition binding for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "classification", "answer_data": [ "Incident definition binding", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "incident-definition-binding-q02", "text": "Which source, observer or authority supports incident definition binding, at what event and observation times, and with what confidence?", "kind": "measurement", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "incident-definition-binding-q03", "text": "Which validation, contradiction or change rule can revise incident definition binding without destroying its history?", "kind": "temporal", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "incident-definition-binding-data", "name": "Incident definition binding assertion", "description": "Structured incident-local answer data for incident definition binding, including status, effective time and provenance where applicable.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ] } ], "artifacts": [], "inline_only_rationale": "This finding stores only typed references and incident-local bindings; the referenced model owns the artifact payload and lifecycle." }, { "id": "qualification-and-declaration-decision", "name": "Qualification and declaration decision", "description": "The determination, authority, rationale, confidence and effective time for declaring, rejecting or revoking incident status.", "source_refs": [ "SRC-001", "SRC-005" ], "questions": [ { "id": "qualification-and-declaration-decision-q01", "text": "What is currently asserted about qualification and declaration decision for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "decision", "answer_data": [ "Qualification and declaration decision", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "qualification-and-declaration-decision-q02", "text": "Which source, observer or authority supports qualification and declaration decision, at what event and observation times, and with what confidence?", "kind": "validation", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "qualification-and-declaration-decision-q03", "text": "Which validation, contradiction or change rule can revise qualification and declaration decision without destroying its history?", "kind": "process", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "qualification-and-declaration-decision-data", "name": "Qualification and declaration decision assertion", "description": "Structured incident-local answer data for qualification and declaration decision, including status, effective time and provenance where applicable.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005" ] } ], "artifacts": [ { "id": "qualification-and-declaration-decision-artifact", "name": "Qualification and declaration decision record", "description": "Versioned incident-owned record supporting qualification and declaration decision with provenance and access marking.", "media_or_form": [ "structured incident record", "signed or controlled statement", "resolvable evidence index" ], "serial": true, "identity_strategy": "Authoritative incident master-system identifier first; otherwise a Dimension-governed UUID or ULID.", "source_refs": [ "SRC-001", "SRC-005" ] } ], "inline_only_rationale": null } ] }, { "id": "identity-continuity", "name": "Identity continuity", "description": "Duplicate resolution, merge, split, supersession and reopening.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ], "findings": [ { "id": "duplicate-merge-and-split", "name": "Duplicate, merge and split", "description": "Governed relations and rationale when reports or event groups are deduplicated, merged into one incident or split into several incidents.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ], "questions": [ { "id": "duplicate-merge-and-split-q01", "text": "What is currently asserted about duplicate, merge and split for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "relationship", "answer_data": [ "Duplicate, merge and split", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "duplicate-merge-and-split-q02", "text": "Which source, observer or authority supports duplicate, merge and split, at what event and observation times, and with what confidence?", "kind": "retention", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "duplicate-merge-and-split-q03", "text": "Which validation, contradiction or change rule can revise duplicate, merge and split without destroying its history?", "kind": "privacy", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "duplicate-merge-and-split-data", "name": "Duplicate, merge and split assertion", "description": "Structured incident-local answer data for duplicate, merge and split, including status, effective time and provenance where applicable.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ] } ], "artifacts": [ { "id": "duplicate-merge-and-split-artifact", "name": "Duplicate, merge and split record", "description": "Versioned incident-owned record supporting duplicate, merge and split with provenance and access marking.", "media_or_form": [ "structured incident record", "signed or controlled statement", "resolvable evidence index" ], "serial": true, "identity_strategy": "Authoritative incident master-system identifier first; otherwise a Dimension-governed UUID or ULID.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "supersession-and-reopening", "name": "Supersession and reopening", "description": "Identity-preserving rules for a corrected successor, revoked determination, recurring activity or reopened incident record.", "source_refs": [ "SRC-003", "SRC-004" ], "questions": [ { "id": "supersession-and-reopening-q01", "text": "What is currently asserted about supersession and reopening for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "lifecycle", "answer_data": [ "Supersession and reopening", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "supersession-and-reopening-q02", "text": "Which source, observer or authority supports supersession and reopening, at what event and observation times, and with what confidence?", "kind": "interoperability", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "supersession-and-reopening-q03", "text": "Which validation, contradiction or change rule can revise supersession and reopening without destroying its history?", "kind": "identity", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "supersession-and-reopening-data", "name": "Supersession and reopening assertion", "description": "Structured incident-local answer data for supersession and reopening, including status, effective time and provenance where applicable.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004" ] } ], "artifacts": [ { "id": "supersession-and-reopening-artifact", "name": "Supersession and reopening record", "description": "Versioned incident-owned record supporting supersession and reopening with provenance and access marking.", "media_or_form": [ "structured incident record", "signed or controlled statement", "resolvable evidence index" ], "serial": true, "identity_strategy": "Authoritative incident master-system identifier first; otherwise a Dimension-governed UUID or ULID.", "source_refs": [ "SRC-003", "SRC-004" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "occurrence-and-chronology", "name": "Occurrence and chronology", "description": "Represents constituent events, ordering and the distinct clocks by which an incident becomes known.", "rationale": "Incident chronology is evidence about what occurred, not the action log of the response process.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ], "layers": [ { "id": "constituent-events", "name": "Constituent events", "description": "Incident membership and relationships among observed cyber events.", "source_refs": [ "SRC-003", "SRC-005" ], "findings": [ { "id": "event-membership", "name": "Event membership", "description": "References to cyber events accepted, suspected or rejected as constituents of the incident, with membership rationale.", "source_refs": [ "SRC-003", "SRC-005" ], "questions": [ { "id": "event-membership-q01", "text": "What is currently asserted about event membership for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "composition", "answer_data": [ "Event membership", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "event-membership-q02", "text": "Which source, observer or authority supports event membership, at what event and observation times, and with what confidence?", "kind": "identity", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "event-membership-q03", "text": "Which validation, contradiction or change rule can revise event membership without destroying its history?", "kind": "spatial", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "event-membership-data", "name": "Event membership assertion", "description": "Structured incident-local answer data for event membership, including status, effective time and provenance where applicable.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-005" ] } ], "artifacts": [], "inline_only_rationale": "This finding stores only typed references and incident-local bindings; the referenced model owns the artifact payload and lifecycle." }, { "id": "causal-and-sequence-relations", "name": "Causal and sequence relations", "description": "Observed ordering, concurrency, dependency and claimed causal links among incident events without promoting hypotheses to facts.", "source_refs": [ "SRC-003", "SRC-005" ], "questions": [ { "id": "causal-and-sequence-relations-q01", "text": "What is currently asserted about causal and sequence relations for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "relationship", "answer_data": [ "Causal and sequence relations", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "causal-and-sequence-relations-q02", "text": "Which source, observer or authority supports causal and sequence relations, at what event and observation times, and with what confidence?", "kind": "state", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "causal-and-sequence-relations-q03", "text": "Which validation, contradiction or change rule can revise causal and sequence relations without destroying its history?", "kind": "event", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "causal-and-sequence-relations-data", "name": "Causal and sequence relations assertion", "description": "Structured incident-local answer data for causal and sequence relations, including status, effective time and provenance where applicable.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-005" ] } ], "artifacts": [], "inline_only_rationale": "This finding stores only typed references and incident-local bindings; the referenced model owns the artifact payload and lifecycle." } ] }, { "id": "incident-time", "name": "Incident time", "description": "Occurrence, detection, observation, declaration and knowledge times.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006" ], "findings": [ { "id": "temporal-markers", "name": "Temporal markers", "description": "Distinct start, end, detection, report, declaration, recovery, observation and ingestion timestamps with uncertainty.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ], "questions": [ { "id": "temporal-markers-q01", "text": "What is currently asserted about temporal markers for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "temporal", "answer_data": [ "Temporal markers", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "temporal-markers-q02", "text": "Which source, observer or authority supports temporal markers, at what event and observation times, and with what confidence?", "kind": "spatial", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "temporal-markers-q03", "text": "Which validation, contradiction or change rule can revise temporal markers without destroying its history?", "kind": "retention", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "temporal-markers-data", "name": "Temporal markers assertion", "description": "Structured incident-local answer data for temporal markers, including status, effective time and provenance where applicable.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "temporal-markers-artifact", "name": "Temporal markers record", "description": "Versioned incident-owned record supporting temporal markers with provenance and access marking.", "media_or_form": [ "structured incident record", "signed or controlled statement", "resolvable evidence index" ], "serial": true, "identity_strategy": "Authoritative incident master-system identifier first; otherwise a Dimension-governed UUID or ULID.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "ongoing-imminent-and-recurring", "name": "Ongoing, imminent and recurring occurrence", "description": "Whether compromise is ongoing, imminent, intermittent or recurring, including the evidence and interval basis.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ], "questions": [ { "id": "ongoing-imminent-and-recurring-q01", "text": "What is currently asserted about ongoing, imminent and recurring occurrence for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "state", "answer_data": [ "Ongoing, imminent and recurring occurrence", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "ongoing-imminent-and-recurring-q02", "text": "Which source, observer or authority supports ongoing, imminent and recurring occurrence, at what event and observation times, and with what confidence?", "kind": "ownership", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "ongoing-imminent-and-recurring-q03", "text": "Which validation, contradiction or change rule can revise ongoing, imminent and recurring occurrence without destroying its history?", "kind": "classification", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "ongoing-imminent-and-recurring-data", "name": "Ongoing, imminent and recurring occurrence assertion", "description": "Structured incident-local answer data for ongoing, imminent and recurring occurrence, including status, effective time and provenance where applicable.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ] } ], "artifacts": [], "inline_only_rationale": "This finding stores only typed references and incident-local bindings; the referenced model owns the artifact payload and lifecycle." } ] } ] }, { "id": "affected-scope", "name": "Affected scope", "description": "Describes direct and propagated reach using governed references and explicit assertion status.", "rationale": "The incident owns scope assertions but not the lifecycle or direct properties of affected systems, people, organizations or information assets.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006", "SRC-007" ], "layers": [ { "id": "affected-subjects", "name": "Affected subjects", "description": "Directly affected technical and organizational subjects.", "source_refs": [ "SRC-003", "SRC-005", "SRC-007" ], "findings": [ { "id": "affected-systems-services-and-networks", "name": "Affected systems, services and networks", "description": "References to systems, services, networks, accounts and computer-controlled infrastructure with role and affected interval.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ], "questions": [ { "id": "affected-systems-services-and-networks-q01", "text": "What is currently asserted about affected systems, services and networks for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "relationship", "answer_data": [ "Affected systems, services and networks", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "affected-systems-services-and-networks-q02", "text": "Which source, observer or authority supports affected systems, services and networks, at what event and observation times, and with what confidence?", "kind": "constraint", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "affected-systems-services-and-networks-q03", "text": "Which validation, contradiction or change rule can revise affected systems, services and networks without destroying its history?", "kind": "provenance", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "affected-systems-services-and-networks-data", "name": "Affected systems, services and networks assertion", "description": "Structured incident-local answer data for affected systems, services and networks, including status, effective time and provenance where applicable.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ] } ], "artifacts": [], "inline_only_rationale": "This finding stores only typed references and incident-local bindings; the referenced model owns the artifact payload and lifecycle." }, { "id": "affected-information-identities-and-parties", "name": "Affected information, identities and parties", "description": "References and bounded counts for information, records, credentials, people and organizations affected or exposed.", "source_refs": [ "SRC-003", "SRC-005", "SRC-007" ], "questions": [ { "id": "affected-information-identities-and-parties-q01", "text": "What is currently asserted about affected information, identities and parties for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "privacy", "answer_data": [ "Affected information, identities and parties", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "affected-information-identities-and-parties-q02", "text": "Which source, observer or authority supports affected information, identities and parties, at what event and observation times, and with what confidence?", "kind": "measurement", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "affected-information-identities-and-parties-q03", "text": "Which validation, contradiction or change rule can revise affected information, identities and parties without destroying its history?", "kind": "evidence", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "affected-information-identities-and-parties-data", "name": "Affected information, identities and parties assertion", "description": "Structured incident-local answer data for affected information, identities and parties, including status, effective time and provenance where applicable.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-005", "SRC-007" ] } ], "artifacts": [], "inline_only_rationale": "This finding stores only typed references and incident-local bindings; the referenced model owns the artifact payload and lifecycle." } ] }, { "id": "scope-reach-and-certainty", "name": "Scope reach and certainty", "description": "Dependency propagation and changing confidence in affected-scope claims.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ], "findings": [ { "id": "dependency-and-supply-chain-reach", "name": "Dependency and supply-chain reach", "description": "Potential or confirmed propagation through service, supplier, tenant, identity and data dependencies.", "source_refs": [ "SRC-005", "SRC-006" ], "questions": [ { "id": "dependency-and-supply-chain-reach-q01", "text": "What is currently asserted about dependency and supply-chain reach for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "relationship", "answer_data": [ "Dependency and supply-chain reach", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "dependency-and-supply-chain-reach-q02", "text": "Which source, observer or authority supports dependency and supply-chain reach, at what event and observation times, and with what confidence?", "kind": "validation", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "dependency-and-supply-chain-reach-q03", "text": "Which validation, contradiction or change rule can revise dependency and supply-chain reach without destroying its history?", "kind": "access", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "dependency-and-supply-chain-reach-data", "name": "Dependency and supply-chain reach assertion", "description": "Structured incident-local answer data for dependency and supply-chain reach, including status, effective time and provenance where applicable.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-006" ] } ], "artifacts": [], "inline_only_rationale": "This finding stores only typed references and incident-local bindings; the referenced model owns the artifact payload and lifecycle." }, { "id": "scope-assertion-status", "name": "Scope assertion status", "description": "Confirmed, suspected, disputed or disproven affected-scope assertions with assessor, method, confidence and history.", "source_refs": [ "SRC-003", "SRC-005" ], "questions": [ { "id": "scope-assertion-status-q01", "text": "What is currently asserted about scope assertion status for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "quality", "answer_data": [ "Scope assertion status", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "scope-assertion-status-q02", "text": "Which source, observer or authority supports scope assertion status, at what event and observation times, and with what confidence?", "kind": "retention", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "scope-assertion-status-q03", "text": "Which validation, contradiction or change rule can revise scope assertion status without destroying its history?", "kind": "composition", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "scope-assertion-status-data", "name": "Scope assertion status assertion", "description": "Structured incident-local answer data for scope assertion status, including status, effective time and provenance where applicable.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "scope-assertion-status-artifact", "name": "Scope assertion status record", "description": "Versioned incident-owned record supporting scope assertion status with provenance and access marking.", "media_or_form": [ "structured incident record", "signed or controlled statement", "resolvable evidence index" ], "serial": true, "identity_strategy": "Authoritative incident master-system identifier first; otherwise a Dimension-governed UUID or ULID.", "source_refs": [ "SRC-003", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "security-effect-and-impact", "name": "Security effect and impact", "description": "Separates the security property affected from technical, operational, human and legal consequences.", "rationale": "Severity and regulatory significance are versioned assessments, not universal intrinsic properties of the incident.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-006", "SRC-007" ], "layers": [ { "id": "security-effects", "name": "Security effects", "description": "Compromised security properties and policy or legal violations.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-006" ], "findings": [ { "id": "confidentiality-integrity-availability-authenticity", "name": "Confidentiality, integrity, availability and authenticity", "description": "Observed or threatened compromise of security properties, affected objects, degree and supporting evidence.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ], "questions": [ { "id": "confidentiality-integrity-availability-authenticity-q01", "text": "What is currently asserted about confidentiality, integrity, availability and authenticity for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "security", "answer_data": [ "Confidentiality, integrity, availability and authenticity", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "confidentiality-integrity-availability-authenticity-q02", "text": "Which source, observer or authority supports confidentiality, integrity, availability and authenticity, at what event and observation times, and with what confidence?", "kind": "interoperability", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "confidentiality-integrity-availability-authenticity-q03", "text": "Which validation, contradiction or change rule can revise confidentiality, integrity, availability and authenticity without destroying its history?", "kind": "ownership", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "confidentiality-integrity-availability-authenticity-data", "name": "Confidentiality, integrity, availability and authenticity assertion", "description": "Structured incident-local answer data for confidentiality, integrity, availability and authenticity, including status, effective time and provenance where applicable.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ] } ], "artifacts": [ { "id": "confidentiality-integrity-availability-authenticity-artifact", "name": "Confidentiality, integrity, availability and authenticity record", "description": "Versioned incident-owned record supporting confidentiality, integrity, availability and authenticity with provenance and access marking.", "media_or_form": [ "structured incident record", "signed or controlled statement", "resolvable evidence index" ], "serial": true, "identity_strategy": "Authoritative incident master-system identifier first; otherwise a Dimension-governed UUID or ULID.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "policy-law-and-authority-effect", "name": "Policy, law and authority effect", "description": "The alleged or confirmed security-policy, acceptable-use, legal or lawful-authority condition implicated by the occurrence.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-007" ], "questions": [ { "id": "policy-law-and-authority-effect-q01", "text": "What is currently asserted about policy, law and authority effect for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "authority", "answer_data": [ "Policy, law and authority effect", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "policy-law-and-authority-effect-q02", "text": "Which source, observer or authority supports policy, law and authority effect, at what event and observation times, and with what confidence?", "kind": "identity", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "policy-law-and-authority-effect-q03", "text": "Which validation, contradiction or change rule can revise policy, law and authority effect without destroying its history?", "kind": "evidence", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "policy-law-and-authority-effect-data", "name": "Policy, law and authority effect assertion", "description": "Structured incident-local answer data for policy, law and authority effect, including status, effective time and provenance where applicable.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-007" ] } ], "artifacts": [], "inline_only_rationale": "This finding stores only typed references and incident-local bindings; the referenced model owns the artifact payload and lifecycle." } ] }, { "id": "impact-domains", "name": "Impact domains", "description": "Consequences beyond the immediate technical effect.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006", "SRC-007" ], "findings": [ { "id": "operational-safety-and-privacy-impact", "name": "Operational, safety and privacy impact", "description": "Service disruption, physical-safety implications and effects on rights or personal data, with actual versus potential status.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006", "SRC-007" ], "questions": [ { "id": "operational-safety-and-privacy-impact-q01", "text": "What is currently asserted about operational, safety and privacy impact for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "measurement", "answer_data": [ "Operational, safety and privacy impact", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "operational-safety-and-privacy-impact-q02", "text": "Which source, observer or authority supports operational, safety and privacy impact, at what event and observation times, and with what confidence?", "kind": "relationship", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "operational-safety-and-privacy-impact-q03", "text": "Which validation, contradiction or change rule can revise operational, safety and privacy impact without destroying its history?", "kind": "exception", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "operational-safety-and-privacy-impact-data", "name": "Operational, safety and privacy impact assertion", "description": "Structured incident-local answer data for operational, safety and privacy impact, including status, effective time and provenance where applicable.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-005", "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "operational-safety-and-privacy-impact-artifact", "name": "Operational, safety and privacy impact record", "description": "Versioned incident-owned record supporting operational, safety and privacy impact with provenance and access marking.", "media_or_form": [ "structured incident record", "signed or controlled statement", "resolvable evidence index" ], "serial": true, "identity_strategy": "Authoritative incident master-system identifier first; otherwise a Dimension-governed UUID or ULID.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null }, { "id": "financial-societal-and-cross-border-impact", "name": "Financial, societal and cross-border impact", "description": "Material and non-material damage, financial loss, constituency reach and cross-border effect assertions.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ], "questions": [ { "id": "financial-societal-and-cross-border-impact-q01", "text": "What is currently asserted about financial, societal and cross-border impact for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "measurement", "answer_data": [ "Financial, societal and cross-border impact", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "financial-societal-and-cross-border-impact-q02", "text": "Which source, observer or authority supports financial, societal and cross-border impact, at what event and observation times, and with what confidence?", "kind": "temporal", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "financial-societal-and-cross-border-impact-q03", "text": "Which validation, contradiction or change rule can revise financial, societal and cross-border impact without destroying its history?", "kind": "relationship", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "financial-societal-and-cross-border-impact-data", "name": "Financial, societal and cross-border impact assertion", "description": "Structured incident-local answer data for financial, societal and cross-border impact, including status, effective time and provenance where applicable.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "financial-societal-and-cross-border-impact-artifact", "name": "Financial, societal and cross-border impact record", "description": "Versioned incident-owned record supporting financial, societal and cross-border impact with provenance and access marking.", "media_or_form": [ "structured incident record", "signed or controlled statement", "resolvable evidence index" ], "serial": true, "identity_strategy": "Authoritative incident master-system identifier first; otherwise a Dimension-governed UUID or ULID.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "severity-and-significance", "name": "Severity and significance", "description": "Profile-bound prioritization and regulatory classifications.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006", "SRC-007" ], "findings": [ { "id": "severity-assessment", "name": "Severity assessment", "description": "Severity or priority value together with scheme, version, assessor, inputs, confidence and effective time.", "source_refs": [ "SRC-003", "SRC-005" ], "questions": [ { "id": "severity-assessment-q01", "text": "What is currently asserted about severity assessment for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "classification", "answer_data": [ "Severity assessment", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "severity-assessment-q02", "text": "Which source, observer or authority supports severity assessment, at what event and observation times, and with what confidence?", "kind": "ownership", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "severity-assessment-q03", "text": "Which validation, contradiction or change rule can revise severity assessment without destroying its history?", "kind": "authority", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "severity-assessment-data", "name": "Severity assessment assertion", "description": "Structured incident-local answer data for severity assessment, including status, effective time and provenance where applicable.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "severity-assessment-artifact", "name": "Severity assessment record", "description": "Versioned incident-owned record supporting severity assessment with provenance and access marking.", "media_or_form": [ "structured incident record", "signed or controlled statement", "resolvable evidence index" ], "serial": true, "identity_strategy": "Authoritative incident master-system identifier first; otherwise a Dimension-governed UUID or ULID.", "source_refs": [ "SRC-003", "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "regulatory-significance-bindings", "name": "Regulatory significance bindings", "description": "Jurisdiction and regime-specific determinations such as significant incident or personal-data breach, with threshold evidence and obligation reference.", "source_refs": [ "SRC-006", "SRC-007" ], "questions": [ { "id": "regulatory-significance-bindings-q01", "text": "What is currently asserted about regulatory significance bindings for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "requirement", "answer_data": [ "Regulatory significance bindings", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "regulatory-significance-bindings-q02", "text": "Which source, observer or authority supports regulatory significance bindings, at what event and observation times, and with what confidence?", "kind": "constraint", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "regulatory-significance-bindings-q03", "text": "Which validation, contradiction or change rule can revise regulatory significance bindings without destroying its history?", "kind": "quality", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "regulatory-significance-bindings-data", "name": "Regulatory significance bindings assertion", "description": "Structured incident-local answer data for regulatory significance bindings, including status, effective time and provenance where applicable.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "regulatory-significance-bindings-artifact", "name": "Regulatory significance bindings record", "description": "Versioned incident-owned record supporting regulatory significance bindings with provenance and access marking.", "media_or_form": [ "structured incident record", "signed or controlled statement", "resolvable evidence index" ], "serial": true, "identity_strategy": "Authoritative incident master-system identifier first; otherwise a Dimension-governed UUID or ULID.", "source_refs": [ "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "mechanism-and-attribution", "name": "Mechanism and attribution", "description": "Records evidence-backed causal, exploit, technique and actor assertions without absorbing neighboring security-object lifecycles.", "rationale": "Causation and attribution often remain contested and must retain alternatives, confidence and revision history.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ], "layers": [ { "id": "cause-and-exploit", "name": "Cause and exploit", "description": "Root-cause hypotheses and referenced weaknesses or exposures.", "source_refs": [ "SRC-003", "SRC-005" ], "findings": [ { "id": "cause-and-enabling-condition-hypotheses", "name": "Cause and enabling-condition hypotheses", "description": "Competing root-cause, misconfiguration, failure, human-action and enabling-condition hypotheses with evidence and confidence.", "source_refs": [ "SRC-003", "SRC-005" ], "questions": [ { "id": "cause-and-enabling-condition-hypotheses-q01", "text": "What is currently asserted about cause and enabling-condition hypotheses for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "provenance", "answer_data": [ "Cause and enabling-condition hypotheses", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "cause-and-enabling-condition-hypotheses-q02", "text": "Which source, observer or authority supports cause and enabling-condition hypotheses, at what event and observation times, and with what confidence?", "kind": "measurement", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "cause-and-enabling-condition-hypotheses-q03", "text": "Which validation, contradiction or change rule can revise cause and enabling-condition hypotheses without destroying its history?", "kind": "interoperability", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "cause-and-enabling-condition-hypotheses-data", "name": "Cause and enabling-condition hypotheses assertion", "description": "Structured incident-local answer data for cause and enabling-condition hypotheses, including status, effective time and provenance where applicable.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "cause-and-enabling-condition-hypotheses-artifact", "name": "Cause and enabling-condition hypotheses record", "description": "Versioned incident-owned record supporting cause and enabling-condition hypotheses with provenance and access marking.", "media_or_form": [ "structured incident record", "signed or controlled statement", "resolvable evidence index" ], "serial": true, "identity_strategy": "Authoritative incident master-system identifier first; otherwise a Dimension-governed UUID or ULID.", "source_refs": [ "SRC-003", "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "vulnerability-and-exposure-references", "name": "Vulnerability and exposure references", "description": "References to exploited or suspected vulnerabilities and concrete exposures without owning disclosure, scoring or remediation state.", "source_refs": [ "SRC-003", "SRC-005" ], "questions": [ { "id": "vulnerability-and-exposure-references-q01", "text": "What is currently asserted about vulnerability and exposure references for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "relationship", "answer_data": [ "Vulnerability and exposure references", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "vulnerability-and-exposure-references-q02", "text": "Which source, observer or authority supports vulnerability and exposure references, at what event and observation times, and with what confidence?", "kind": "validation", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "vulnerability-and-exposure-references-q03", "text": "Which validation, contradiction or change rule can revise vulnerability and exposure references without destroying its history?", "kind": "state", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "vulnerability-and-exposure-references-data", "name": "Vulnerability and exposure references assertion", "description": "Structured incident-local answer data for vulnerability and exposure references, including status, effective time and provenance where applicable.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-005" ] } ], "artifacts": [], "inline_only_rationale": "This finding stores only typed references and incident-local bindings; the referenced model owns the artifact payload and lifecycle." } ] }, { "id": "technique-indicator-and-attribution", "name": "Technique, indicator and attribution", "description": "Observed mechanisms and bounded claims about responsible activity.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ], "findings": [ { "id": "technique-indicator-and-observable-references", "name": "Technique, indicator and observable references", "description": "References to attack patterns, indicators, observables, tools and infrastructure with observed role and time.", "source_refs": [ "SRC-003", "SRC-004" ], "questions": [ { "id": "technique-indicator-and-observable-references-q01", "text": "What is currently asserted about technique, indicator and observable references for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "evidence", "answer_data": [ "Technique, indicator and observable references", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "technique-indicator-and-observable-references-q02", "text": "Which source, observer or authority supports technique, indicator and observable references, at what event and observation times, and with what confidence?", "kind": "retention", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "technique-indicator-and-observable-references-q03", "text": "Which validation, contradiction or change rule can revise technique, indicator and observable references without destroying its history?", "kind": "requirement", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "technique-indicator-and-observable-references-data", "name": "Technique, indicator and observable references assertion", "description": "Structured incident-local answer data for technique, indicator and observable references, including status, effective time and provenance where applicable.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004" ] } ], "artifacts": [], "inline_only_rationale": "This finding stores only typed references and incident-local bindings; the referenced model owns the artifact payload and lifecycle." }, { "id": "actor-campaign-and-attribution-claims", "name": "Actor, campaign and attribution claims", "description": "Competing links to actors, campaigns or intrusion sets with source, analytic basis, confidence and disclosure marking.", "source_refs": [ "SRC-003", "SRC-004" ], "questions": [ { "id": "actor-campaign-and-attribution-claims-q01", "text": "What is currently asserted about actor, campaign and attribution claims for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "provenance", "answer_data": [ "Actor, campaign and attribution claims", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "actor-campaign-and-attribution-claims-q02", "text": "Which source, observer or authority supports actor, campaign and attribution claims, at what event and observation times, and with what confidence?", "kind": "interoperability", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "actor-campaign-and-attribution-claims-q03", "text": "Which validation, contradiction or change rule can revise actor, campaign and attribution claims without destroying its history?", "kind": "validation", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "actor-campaign-and-attribution-claims-data", "name": "Actor, campaign and attribution claims assertion", "description": "Structured incident-local answer data for actor, campaign and attribution claims, including status, effective time and provenance where applicable.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004" ] } ], "artifacts": [ { "id": "actor-campaign-and-attribution-claims-artifact", "name": "Actor, campaign and attribution claims record", "description": "Versioned incident-owned record supporting actor, campaign and attribution claims with provenance and access marking.", "media_or_form": [ "structured incident record", "signed or controlled statement", "resolvable evidence index" ], "serial": true, "identity_strategy": "Authoritative incident master-system identifier first; otherwise a Dimension-governed UUID or ULID.", "source_refs": [ "SRC-003", "SRC-004" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "evidence-provenance-and-governance", "name": "Evidence, provenance and governance", "description": "Makes observations, evidence references, epistemic status and controlled disclosure explicit.", "rationale": "Incident data is sensitive and mutable; agents must preserve source, evidence integrity, uncertainty, access and retention without duplicating external evidence or audit systems.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007" ], "layers": [ { "id": "observations-and-evidence", "name": "Observations and evidence", "description": "Source reports, technical observations and preserved evidence bindings.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ], "findings": [ { "id": "reports-observations-and-discovery", "name": "Reports, observations and discovery", "description": "Source reports, discovery methods, observations, sensor or analyst provenance, reliability and observation conditions.", "source_refs": [ "SRC-003", "SRC-005" ], "questions": [ { "id": "reports-observations-and-discovery-q01", "text": "What is currently asserted about reports, observations and discovery for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "provenance", "answer_data": [ "Reports, observations and discovery", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "reports-observations-and-discovery-q02", "text": "Which source, observer or authority supports reports, observations and discovery, at what event and observation times, and with what confidence?", "kind": "identity", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "reports-observations-and-discovery-q03", "text": "Which validation, contradiction or change rule can revise reports, observations and discovery without destroying its history?", "kind": "decision", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "reports-observations-and-discovery-data", "name": "Reports, observations and discovery assertion", "description": "Structured incident-local answer data for reports, observations and discovery, including status, effective time and provenance where applicable.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "reports-observations-and-discovery-artifact", "name": "Reports, observations and discovery record", "description": "Versioned incident-owned record supporting reports, observations and discovery with provenance and access marking.", "media_or_form": [ "structured incident record", "signed or controlled statement", "resolvable evidence index" ], "serial": true, "identity_strategy": "Authoritative incident master-system identifier first; otherwise a Dimension-governed UUID or ULID.", "source_refs": [ "SRC-003", "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "evidence-integrity-and-custody-references", "name": "Evidence integrity and custody references", "description": "References to forensic artifacts and custody records with digest, collector, preservation state and access boundary.", "source_refs": [ "SRC-003", "SRC-005" ], "questions": [ { "id": "evidence-integrity-and-custody-references-q01", "text": "What is currently asserted about evidence integrity and custody references for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "evidence", "answer_data": [ "Evidence integrity and custody references", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "evidence-integrity-and-custody-references-q02", "text": "Which source, observer or authority supports evidence integrity and custody references, at what event and observation times, and with what confidence?", "kind": "relationship", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "evidence-integrity-and-custody-references-q03", "text": "Which validation, contradiction or change rule can revise evidence integrity and custody references without destroying its history?", "kind": "lifecycle", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "evidence-integrity-and-custody-references-data", "name": "Evidence integrity and custody references assertion", "description": "Structured incident-local answer data for evidence integrity and custody references, including status, effective time and provenance where applicable.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-005" ] } ], "artifacts": [], "inline_only_rationale": "This finding stores only typed references and incident-local bindings; the referenced model owns the artifact payload and lifecycle." } ] }, { "id": "epistemic-and-disclosure-controls", "name": "Epistemic and disclosure controls", "description": "Truth status, markings, access, retention and projections.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-007" ], "findings": [ { "id": "fact-assessment-allegation-and-unknown", "name": "Fact, assessment, allegation and unknown", "description": "Explicit epistemic status for each material assertion, including contradiction sets and the authority able to resolve them.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ], "questions": [ { "id": "fact-assessment-allegation-and-unknown-q01", "text": "What is currently asserted about fact, assessment, allegation and unknown for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "quality", "answer_data": [ "Fact, assessment, allegation and unknown", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "fact-assessment-allegation-and-unknown-q02", "text": "Which source, observer or authority supports fact, assessment, allegation and unknown, at what event and observation times, and with what confidence?", "kind": "temporal", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "fact-assessment-allegation-and-unknown-q03", "text": "Which validation, contradiction or change rule can revise fact, assessment, allegation and unknown without destroying its history?", "kind": "constraint", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "fact-assessment-allegation-and-unknown-data", "name": "Fact, assessment, allegation and unknown assertion", "description": "Structured incident-local answer data for fact, assessment, allegation and unknown, including status, effective time and provenance where applicable.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ] } ], "artifacts": [ { "id": "fact-assessment-allegation-and-unknown-artifact", "name": "Fact, assessment, allegation and unknown record", "description": "Versioned incident-owned record supporting fact, assessment, allegation and unknown with provenance and access marking.", "media_or_form": [ "structured incident record", "signed or controlled statement", "resolvable evidence index" ], "serial": true, "identity_strategy": "Authoritative incident master-system identifier first; otherwise a Dimension-governed UUID or ULID.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "disclosure-access-privacy-and-retention", "name": "Disclosure, access, privacy and retention", "description": "Information marking, permitted projection, privacy constraints, legal hold and retention or deletion binding.", "source_refs": [ "SRC-003", "SRC-004", "SRC-006", "SRC-007" ], "questions": [ { "id": "disclosure-access-privacy-and-retention-q01", "text": "What is currently asserted about disclosure, access, privacy and retention for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "access", "answer_data": [ "Disclosure, access, privacy and retention", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "disclosure-access-privacy-and-retention-q02", "text": "Which source, observer or authority supports disclosure, access, privacy and retention, at what event and observation times, and with what confidence?", "kind": "ownership", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "disclosure-access-privacy-and-retention-q03", "text": "Which validation, contradiction or change rule can revise disclosure, access, privacy and retention without destroying its history?", "kind": "security", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "disclosure-access-privacy-and-retention-data", "name": "Disclosure, access, privacy and retention assertion", "description": "Structured incident-local answer data for disclosure, access, privacy and retention, including status, effective time and provenance where applicable.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-004", "SRC-006", "SRC-007" ] } ], "artifacts": [ { "id": "disclosure-access-privacy-and-retention-artifact", "name": "Disclosure, access, privacy and retention record", "description": "Versioned incident-owned record supporting disclosure, access, privacy and retention with provenance and access marking.", "media_or_form": [ "structured incident record", "signed or controlled statement", "resolvable evidence index" ], "serial": true, "identity_strategy": "Authoritative incident master-system identifier first; otherwise a Dimension-governed UUID or ULID.", "source_refs": [ "SRC-003", "SRC-004", "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "state-resolution-and-federation", "name": "State, resolution and federation", "description": "Tracks incident-owned factual state and closure while connecting external response cases and exchange representations.", "rationale": "Incident state must stay distinct from responder workflow state and from legal or business claims that are owned elsewhere.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-006" ], "layers": [ { "id": "incident-state-and-resolution", "name": "Incident state and resolution", "description": "Current incident condition, impact cessation and residual exposure.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ], "findings": [ { "id": "incident-factual-state", "name": "Incident factual state", "description": "Profile-bound incident state, allowed transition, triggering evidence, actor and effective time, separate from response-task status.", "source_refs": [ "SRC-003", "SRC-005" ], "questions": [ { "id": "incident-factual-state-q01", "text": "What is currently asserted about incident factual state for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "state", "answer_data": [ "Incident factual state", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "incident-factual-state-q02", "text": "Which source, observer or authority supports incident factual state, at what event and observation times, and with what confidence?", "kind": "constraint", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "incident-factual-state-q03", "text": "Which validation, contradiction or change rule can revise incident factual state without destroying its history?", "kind": "definition", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "incident-factual-state-data", "name": "Incident factual state assertion", "description": "Structured incident-local answer data for incident factual state, including status, effective time and provenance where applicable.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "incident-factual-state-artifact", "name": "Incident factual state record", "description": "Versioned incident-owned record supporting incident factual state with provenance and access marking.", "media_or_form": [ "structured incident record", "signed or controlled statement", "resolvable evidence index" ], "serial": true, "identity_strategy": "Authoritative incident master-system identifier first; otherwise a Dimension-governed UUID or ULID.", "source_refs": [ "SRC-003", "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "impact-cessation-residual-exposure-and-recurrence", "name": "Impact cessation, residual exposure and recurrence", "description": "Evidence that harmful effects ceased or persist, remaining exposure, recurrence indicators and uncertainty.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ], "questions": [ { "id": "impact-cessation-residual-exposure-and-recurrence-q01", "text": "What is currently asserted about impact cessation, residual exposure and recurrence for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "validation", "answer_data": [ "Impact cessation, residual exposure and recurrence", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "impact-cessation-residual-exposure-and-recurrence-q02", "text": "Which source, observer or authority supports impact cessation, residual exposure and recurrence, at what event and observation times, and with what confidence?", "kind": "measurement", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "impact-cessation-residual-exposure-and-recurrence-q03", "text": "Which validation, contradiction or change rule can revise impact cessation, residual exposure and recurrence without destroying its history?", "kind": "temporal", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "impact-cessation-residual-exposure-and-recurrence-data", "name": "Impact cessation, residual exposure and recurrence assertion", "description": "Structured incident-local answer data for impact cessation, residual exposure and recurrence, including status, effective time and provenance where applicable.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "impact-cessation-residual-exposure-and-recurrence-artifact", "name": "Impact cessation, residual exposure and recurrence record", "description": "Versioned incident-owned record supporting impact cessation, residual exposure and recurrence with provenance and access marking.", "media_or_form": [ "structured incident record", "signed or controlled statement", "resolvable evidence index" ], "serial": true, "identity_strategy": "Authoritative incident master-system identifier first; otherwise a Dimension-governed UUID or ULID.", "source_refs": [ "SRC-001", "SRC-003", "SRC-005" ] } ], "inline_only_rationale": null } ] }, { "id": "closure-and-external-bindings", "name": "Closure and external bindings", "description": "Closure basis, response-case linkage and exchange mappings.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-006" ], "findings": [ { "id": "closure-reclassification-and-disposition", "name": "Closure, reclassification and disposition", "description": "The evidence-backed decision to close, revoke, reclassify or reopen the incident and its unresolved facts or obligations.", "source_refs": [ "SRC-003", "SRC-005" ], "questions": [ { "id": "closure-reclassification-and-disposition-q01", "text": "What is currently asserted about closure, reclassification and disposition for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "lifecycle", "answer_data": [ "Closure, reclassification and disposition", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "closure-reclassification-and-disposition-q02", "text": "Which source, observer or authority supports closure, reclassification and disposition, at what event and observation times, and with what confidence?", "kind": "validation", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "closure-reclassification-and-disposition-q03", "text": "Which validation, contradiction or change rule can revise closure, reclassification and disposition without destroying its history?", "kind": "process", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "closure-reclassification-and-disposition-data", "name": "Closure, reclassification and disposition assertion", "description": "Structured incident-local answer data for closure, reclassification and disposition, including status, effective time and provenance where applicable.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "closure-reclassification-and-disposition-artifact", "name": "Closure, reclassification and disposition record", "description": "Versioned incident-owned record supporting closure, reclassification and disposition with provenance and access marking.", "media_or_form": [ "structured incident record", "signed or controlled statement", "resolvable evidence index" ], "serial": true, "identity_strategy": "Authoritative incident master-system identifier first; otherwise a Dimension-governed UUID or ULID.", "source_refs": [ "SRC-003", "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "response-case-and-federation-bindings", "name": "Response-case and federation bindings", "description": "References to response cases, reporting workflows and external incident representations with mapping, projection and correlation rules.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-006" ], "questions": [ { "id": "response-case-and-federation-bindings-q01", "text": "What is currently asserted about response-case and federation bindings for this cyber incident, and is it confirmed, suspected, disputed or unknown?", "kind": "interoperability", "answer_data": [ "Response-case and federation bindings", "epistemic status", "applicable scope or explicit unknown" ] }, { "id": "response-case-and-federation-bindings-q02", "text": "Which source, observer or authority supports response-case and federation bindings, at what event and observation times, and with what confidence?", "kind": "retention", "answer_data": [ "source or authority reference", "event and observation timestamps", "confidence and evidence reference" ] }, { "id": "response-case-and-federation-bindings-q03", "text": "Which validation, contradiction or change rule can revise response-case and federation bindings without destroying its history?", "kind": "privacy", "answer_data": [ "validation or conflict rule", "authorized revision event", "predecessor, successor or counterclaim reference" ] } ], "data_elements": [ { "id": "response-case-and-federation-bindings-data", "name": "Response-case and federation bindings assertion", "description": "Structured incident-local answer data for response-case and federation bindings, including status, effective time and provenance where applicable.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-006" ] } ], "artifacts": [], "inline_only_rationale": "This finding stores only typed references and incident-local bindings; the referenced model owns the artifact payload and lifecycle." } ] } ] } ] }, "functions": [ { "id": "register-potential-incident", "name": "Register potential incident", "description": "Create a non-confirmed incident candidate from a report or event cluster without claiming qualification.", "inputs": [ "report or event references", "receiving authority" ], "outputs": [ "potential incident record" ], "preconditions": [ "authorized intake purpose exists" ], "effects": [ "candidate identity and provenance are recorded" ], "source_refs": [ "SRC-003", "SRC-005" ] }, { "id": "qualify-and-declare-incident", "name": "Qualify and declare incident", "description": "Evaluate the candidate against a pinned definition and record the authorized determination.", "inputs": [ "candidate record", "evidence", "definition binding" ], "outputs": [ "qualification decision", "declared incident revision" ], "preconditions": [ "qualified authority and evidence are available" ], "effects": [ "incident status is confirmed, rejected or remains uncertain with rationale" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-006" ] }, { "id": "link-constituent-event", "name": "Link constituent event", "description": "Add or remove a typed event membership assertion with evidence and historical trace.", "inputs": [ "incident", "event reference", "membership rationale" ], "outputs": [ "event membership revision" ], "preconditions": [ "incident and event identities resolve" ], "effects": [ "incident chronology and scope can be recomputed" ], "source_refs": [ "SRC-003", "SRC-005" ] }, { "id": "merge-or-split-incident", "name": "Merge or split incident", "description": "Resolve duplicate or over-grouped incident identities without losing prior references.", "inputs": [ "incident identities", "correlation evidence", "authority" ], "outputs": [ "merge or split decision", "successor identity relations" ], "preconditions": [ "identity authority and conflict policy permit the decision" ], "effects": [ "aliases and predecessor records remain resolvable" ], "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ] }, { "id": "revise-affected-scope", "name": "Revise affected scope", "description": "Add, confirm, dispute or remove an affected-scope assertion as knowledge changes.", "inputs": [ "incident", "subject references", "scope evidence" ], "outputs": [ "scope assessment revision" ], "preconditions": [ "source and observation time are available" ], "effects": [ "current and historical scope assertions remain distinguishable" ], "source_refs": [ "SRC-003", "SRC-005", "SRC-006", "SRC-007" ] }, { "id": "assess-impact-and-significance", "name": "Assess impact and significance", "description": "Record technical and nontechnical impact, severity and profile-specific significance without universalizing a score.", "inputs": [ "incident", "impact evidence", "assessment profiles" ], "outputs": [ "impact assessment", "significance bindings" ], "preconditions": [ "assessor authority and scheme versions resolve" ], "effects": [ "actual and potential impacts remain separately traceable" ], "source_refs": [ "SRC-003", "SRC-005", "SRC-006", "SRC-007" ] }, { "id": "record-causal-or-attribution-hypothesis", "name": "Record causal or attribution hypothesis", "description": "Add an evidence-backed, confidence-bearing explanation or attribution without promoting it to fact.", "inputs": [ "incident", "hypothesis", "supporting and contradicting evidence" ], "outputs": [ "versioned hypothesis assertion" ], "preconditions": [ "epistemic status is explicit" ], "effects": [ "competing explanations remain visible" ], "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ] }, { "id": "transition-incident-factual-state", "name": "Transition incident factual state", "description": "Change the incident-owned condition under a pinned state profile and triggering evidence.", "inputs": [ "incident", "current state", "proposed state", "evidence" ], "outputs": [ "state transition record" ], "preconditions": [ "transition and actor are authorized" ], "effects": [ "incident state changes without changing response-task state" ], "source_refs": [ "SRC-003", "SRC-005" ] }, { "id": "bind-response-case", "name": "Bind response case", "description": "Reference the independently governed incident-response case that handles this incident.", "inputs": [ "incident", "response case reference" ], "outputs": [ "typed incident-to-response binding" ], "preconditions": [ "both identities resolve and disclosure policy allows the link" ], "effects": [ "handling workflow stays outside the incident aggregate" ], "source_refs": [ "SRC-001", "SRC-005" ] }, { "id": "issue-incident-projection", "name": "Issue incident projection", "description": "Produce a minimum authorized view for coordination, reporting or threat-intelligence exchange.", "inputs": [ "incident revision", "recipient and purpose", "projection policy" ], "outputs": [ "digest-pinned incident projection" ], "preconditions": [ "access and disclosure decision permits release" ], "effects": [ "sensitive fields are minimized and projection provenance is recorded" ], "source_refs": [ "SRC-003", "SRC-004", "SRC-006", "SRC-007" ] } ], "composition": [ { "target": "WM-SFT-006 Vulnerability Record", "relation": "REFERENCE", "purpose": "Binds exploited or suspected vulnerabilities and exposures without copying vulnerability lifecycle, scoring or remediation state.", "required": false, "source_refs": [ "SRC-003", "SRC-005" ] }, { "target": "WM-ACT-042 Incident Response", "relation": "REFERENCE", "purpose": "Links the independently governed handling case and keeps response execution outside the incident factual aggregate.", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] }, { "target": "Cyber event, observation and evidence models", "relation": "REFERENCE", "purpose": "Groups incident-local membership and provenance assertions while external records own raw event and evidence lifecycles.", "required": true, "source_refs": [ "SRC-003", "SRC-005" ] }, { "target": "System, service, network, information, identity, person and organization models", "relation": "REFERENCE", "purpose": "Expresses affected scope through authoritative identities without duplicating direct properties or mastership.", "required": true, "source_refs": [ "SRC-003", "SRC-005", "SRC-006", "SRC-007" ] }, { "target": "Threat actor, campaign, attack pattern, indicator and observable models", "relation": "REFERENCE", "purpose": "Carries evidence-backed incident-local attribution and mechanism links without owning CTI object lifecycles.", "required": false, "source_refs": [ "SRC-003", "SRC-004" ] }, { "target": "NIST SP 800-61 Rev. 3 and FIRST CSIRT Services Framework", "relation": "ALIGN", "purpose": "Aligns qualification, analysis and response boundaries without treating guidance as a storage schema.", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] }, { "target": "IODEF Version 2 and STIX Version 2.1", "relation": "ALIGN", "purpose": "Supports explicit, potentially lossy exchange mappings with version and marking preservation.", "required": false, "source_refs": [ "SRC-003", "SRC-004" ] }, { "target": "NIS2 and GDPR obligation profiles", "relation": "REFERENCE", "purpose": "Binds regime-specific classification and reporting obligations while keeping legal workflow outside the incident model.", "required": false, "source_refs": [ "SRC-006", "SRC-007" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Declare the Dimension owner, incident record authority, constituency, stewards and declaration or closure delegation.", "Declare the incident namespace, authoritative case or incident master system, event and evidence repositories and clock policy.", "Publish model, object, event and relation registries plus applicable disclosure, privacy, retention and legal-hold policies.", "Pin incident-definition, state, severity, reporting and jurisdiction profiles used for each governed determination." ], "namespace_guidance": "Mint incident identifiers only in the adopting Dimension's governed namespace; preserve external CSIRT, regulator and partner IDs as typed aliases with authority and correlation history.", "registry_links": [ "https://ver.cy/models/", "https://ver.cy/model-agent-protocol.md", "Dimension-local incident, event, evidence and policy registries" ] }, "canon_and_patch": { "canonicalization_rules": [ "Canonicalize by registry ID, model version, incident master ID, immutable revision and explicit source authority; do not collapse contested assertions.", "Keep incident factual state separate from response workflow state, reporting status and vulnerability remediation state." ], "patch_rules": [ "Additive extensions use a Dimension-owned namespace and declare target node, incident profile, source, rationale and access impact.", "Breaking changes require a new version, migration map, compatibility declaration and continued resolution of prior incident revisions." ], "compatibility_rules": [ "Consumers may ignore unknown additive fields only when identity, marking, evidence, authority and temporal meaning remain intact.", "IODEF, STIX, regulator and partner mappings must pin version and declare omitted, transformed or redacted values." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system incident identifier and immutable revision identifier.", "Governed globally resolvable incident IRI or federation identifier.", "Adopting-Dimension UUID or ULID when no authoritative external identifier exists." ], "timestamp_rule": "Record event timestamps in RFC 3339 with seconds and an explicit UTC offset or Z; keep occurrence, detection, observation, declaration, effective and ingestion times distinct.", "serial_naming_rule": "Name serial artifacts as {incident-id}--{artifact-kind}--{revision-or-event-id}; never use a date, filename or hash alone as incident identity.", "integrity_rule": "Store digest, media type, byte length, issuer or collector, capture method, provenance, access marking and immutable version reference for each retained serial artifact." }, "policies": [ "The adopting Dimension declares who may register, qualify, merge, split, assess, disclose, reclassify, close and reopen an incident.", "Every material statement is labelled fact, observation, assessment, hypothesis, allegation, contradiction or unknown with source and knowledge time.", "Collection, correlation and disclosure minimize personal, operational and security-sensitive data and preserve source sharing restrictions.", "Response execution, regulatory notification, access enforcement, evidence custody and audit persistence are delegated to their owning systems and referenced.", "Automated agents may update low-risk incident-local assertions only within explicit delegation and must propose or confirm high-impact disclosure, closure and destructive actions." ], "crud": { "read": [ "Resolve model and profile versions, owner policy, information markings and external master systems; return only a minimum authorized projection and preserve purpose constraints." ], "create": [ "Create a potential incident with master identity, provenance and unknowns; require a separate authorized qualification decision before representing it as confirmed." ], "update": [ "Append immutable assertion or decision revisions with actor, authority, reason, event and observation times; validate references, contradictions, state and access before and after mutation." ], "delete": [ "Apply retention, legal hold and deletion policy; tombstone or use approved cryptographic erasure for incident-owned records while external evidence and audit systems retain their own governed copies and references do not cascade." ] }, "roles": [ { "name": "Dimension owner", "responsibilities": [ "Own incident namespace, mastership, profile selection, delegation, access and retention policy." ] }, { "name": "Incident authority", "responsibilities": [ "Qualify, declare, merge, split, reclassify, close or reopen incidents within mandate." ] }, { "name": "Incident analyst", "responsibilities": [ "Maintain chronology, scope, impact, hypotheses, confidence and supporting references without overstating certainty." ] }, { "name": "Evidence custodian", "responsibilities": [ "Preserve external evidence identity, integrity, custody and access references without transferring mastership into the incident record." ] }, { "name": "Response coordinator", "responsibilities": [ "Bind the independently governed response case and communicate factual updates without editing evidence authority." ] }, { "name": "Privacy or legal reviewer", "responsibilities": [ "Evaluate personal-data, regulatory, disclosure, retention and legal-hold bindings." ] }, { "name": "Auditor", "responsibilities": [ "Review decisions, provenance, changes, access and unresolved contradictions without rewriting operational truth." ] } ], "access": { "default_rule": "Deny mutation and sensitive disclosure unless the active Dimension, role, purpose, incident class and information marking grant the action; expose the minimum necessary projection.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Emergency access must be time-limited, purpose-bound, attributable, independently reviewed and unable to bypass immutable history, evidence integrity or legal hold." ], "audit_requirements": [ "Log actor, role, purpose, incident and revision identity, action, decision, policy version, RFC 3339 timestamp with offset, affected scope and outcome for each privileged mutation or disclosure." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Read the nearest Dimension-owner AGENTS.md, incident mandate and disclosure policies.", "Read this model AGENTS.md, then the pinned spec.yaml and every required incident, evidence, response and policy profile before mutation." ] } }, "coverage": { "claim": "A source-grounded reviewable draft of the Cyber Incident aggregate across NIST, IETF, OASIS, FIRST and European Union perspectives, without a claim of universal legal, sector or implementation-profile completeness.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Master identity, aliases, versioning, correlation and merge or split continuity are explicit." }, { "dimension": "lifecycle", "status": "covered", "notes": "Qualification, declaration, state, reclassification, closure, supersession and reopening preserve history." }, { "dimension": "relationships", "status": "covered", "notes": "Constituent events, affected subjects, vulnerabilities, CTI objects, evidence and response cases are typed references." }, { "dimension": "temporal", "status": "covered", "notes": "Occurrence, detection, observation, declaration, reporting, effective, recovery and ingestion times are separated." }, { "dimension": "provenance", "status": "covered", "notes": "Sources, observers, methods, confidence, contradictions and evidence bindings are carried per assertion." }, { "dimension": "ownership", "status": "covered", "notes": "Dimension owner, incident authority, analyst, evidence custodian and external master systems have distinct responsibilities." }, { "dimension": "validation", "status": "covered", "notes": "Qualification, reference, transition, evidence, conflict, profile and pre or post mutation validation are explicit." }, { "dimension": "access", "status": "covered", "notes": "Default deny, granular scopes, projection minimization, markings, emergency exception and audit are defined." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Retention, legal hold, tombstone, approved erasure and non-cascading external reference rules are explicit." }, { "dimension": "interoperability", "status": "covered", "notes": "IODEF, STIX, NIS2, GDPR and partner mappings require pinned versions and loss declarations." }, { "dimension": "classification and recognition", "status": "covered", "notes": "Definition binding, qualification evidence, false-positive boundary, severity and significance schemes are represented." }, { "dimension": "direct properties", "status": "not-applicable", "notes": "The incident is an abstract occurrence aggregate; physical properties belong to referenced affected objects, while incident-owned descriptive and temporal properties remain modeled." }, { "dimension": "behavior and possible actions", "status": "covered", "notes": "Ongoing or recurring occurrence, factual transitions and agent record operations are separated from response actions and authorization policy." }, { "dimension": "impact and scope", "status": "covered", "notes": "Technical, operational, safety, privacy, financial, societal and cross-border effects use evidence-bearing assertions." } ], "known_omissions": [ "Sector, organization and jurisdiction profiles must supply exact event, incident-state, severity, significance, reporting and closure vocabularies.", "The exact identifiers and dependency contracts for event, evidence, affected-object, threat-intelligence, legal-obligation and response-case sibling models remain to be pinned as the catalogue matures.", "Clause-level mappings to IODEF, STIX extensions, national NIS2 implementations and regulator reporting schemas remain profile work." ], "conflicts": [ "The candidate registry edge says COMPOSE WM-ACT-042 while its rationale requires incident and response-process separation; this draft uses a REFERENCE binding and leaves the ledger correction for registry reconciliation.", "Cyber-incident definitions vary across lawful-authority, policy-violation, authenticity, near-miss and personal-data-breach boundaries, so every qualification pins its governing definition rather than claiming one universal threshold.", "STIX 2.1 explicitly defines Incident as a stub, so it cannot by itself support the richer Vercy structure and is treated only as an alignment and extension boundary." ], "regional_assumptions": [ "NIS2 and GDPR bindings apply only where the relevant European Union law and local implementation govern the incident; no universal reporting deadline or legal conclusion is assumed.", "NIST terminology is used as an authoritative profile, not as a claim that United States legal definitions apply globally." ], "adversarial_checks": [ "Reject alerts, anomalous events, near misses and unqualified reports represented as confirmed incidents without a declaration decision and pinned definition.", "Reject incident state transitions that silently assert response-task completion, successful containment, legal compliance or proof of recovery.", "Reject copied vulnerability, asset, identity, CTI, evidence, response or notification lifecycles when an authoritative typed reference is sufficient.", "Reject source-free attribution, causal certainty, universal severity scores, overwritten contradictions and timestamps without seconds and explicit offset.", "Reject disclosure, closure, deletion, merge or split decisions that lack authority, purpose, access review and preserved provenance." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "aggregate", "status": "accepted", "rationale": "The record-plane label standalone-mm is separate from subject kind. A cyber incident can group multiple events and evolving, versioned assertions under one governed identity, so aggregate is more defensible than treating it as one immutable event." }, "decisions": [ { "concept": "Event and alert boundary", "disposition": "accepted", "rationale": "The model requires an evidence-backed qualification and declaration decision before a report, anomaly, alert or event cluster can be represented as a confirmed cyber incident." }, { "concept": "Incident versus response process", "disposition": "accepted", "rationale": "Incident-owned facts describe what happened and what is known; responder tasks, containment, recovery, notification and lessons-learned workflows remain in the independently governed WM-ACT-042 model." }, { "concept": "Candidate COMPOSE edge to WM-ACT-042", "disposition": "rejected in favor of REFERENCE", "rationale": "The ledger's instance semantics say the incident is handled by a response case and its rationale requires process separation. A reference preserves that boundary, while COMPOSE would imply importing or owning response semantics." }, { "concept": "Vulnerability and exposure lifecycle", "disposition": "rejected as incident-owned", "rationale": "An incident may cite an exploited or suspected weakness, but vulnerability disclosure, scoring, affected-version and remediation state belong to WM-SFT-006 or another security master system." }, { "concept": "STIX 2.1 Incident alignment", "disposition": "accepted as limited alignment", "rationale": "STIX 2.1 explicitly calls Incident a stub extension point, so its identity, versioning, marking and relationship semantics are useful without presenting the stub as evidence for the entire Vercy structure." }, { "concept": "Regulatory classifications", "disposition": "accepted as profile bindings", "rationale": "NIS2 significant-incident and GDPR personal-data-breach determinations are versioned jurisdictional assessments with evidence and obligation references, not universal intrinsic incident classes." }, { "concept": "Incident factual state", "disposition": "accepted with profile-specific vocabulary", "rationale": "The incident needs evidence-bearing state and transition history, but one universal code list would conflate organization, sector, exchange and response-workflow semantics." }, { "concept": "Fact, assessment, allegation and unknown", "disposition": "accepted", "rationale": "Cyber scope, impact, causation and attribution change over time and may conflict. Explicit epistemic status and preserved counterclaims prevent agents from turning hypotheses into facts." }, { "concept": "Physical direct properties", "disposition": "not applicable to the incident aggregate", "rationale": "A cyber incident is an abstract occurrence aggregate. Physical properties belong to referenced affected objects, while incident-local security effects, times, scope and assessments remain native." }, { "concept": "Evidence artifacts and custody", "disposition": "accepted as incident-owned indexes and external references", "rationale": "The incident may own signed decisions, assessments and an evidence index, while raw forensic artifacts and custody records remain under their authoritative repositories and access controls." }, { "concept": "Question coverage", "disposition": "accepted as reviewable draft", "rationale": "Every finding asks for current assertion status, source and temporal provenance, and change or contradiction handling. Systematic wording aids machine completion but still needs later sector-profile editorial review." } ], "publicationHolds": [ "Claude and Grok timed out during their bounded attempts, so independent external review is absent and explicitly waived for this published reviewable draft.", "Clause-level mappings, exact external schema versions and implementation profiles remain unverified for canonical conformance even though the cited official source URLs were reachable during Codex research.", "The candidate registry COMPOSE edge to WM-ACT-042 conflicts with the incident-response separation rationale and must be reconciled to REFERENCE in the shared relation ledger.", "Sector and jurisdiction profiles must validate state vocabularies, severity and significance thresholds, reporting duties, closure rules and retention periods before operational enforcement.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Validate the logical structure against current CSIRT, SOC, cloud, operational-technology, healthcare, financial-sector and public-authority incident profiles.", "Create clause-level crosswalks for IODEF Version 2, STIX incident extensions, national NIS2 implementations and regulator reporting schemas.", "Pin sibling model identifiers and cardinality contracts for events, observations, evidence, affected assets, CTI objects, legal obligations and response cases.", "Review generated question wording with incident handlers, forensic specialists, privacy officers and operational-risk owners." ] }, "statistics": { "sources": 7, "bundles": 7, "layers": 16, "findings": 32, "questions": 96, "artifacts": 19, "functions": 10 } }