# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-09-06T08:16:06Z", "synthesisSha256": "8d9fc51a480da7a5dc68db1efd23f32be98e01732bdaa2c6b0473370ed58ed72", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-ACT-043", "registryId": "vr.wm-act-043", "name": "Business Continuity / Recovery", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "aggregate", "family": "World Models", "category": "Activities and processes", "industry": [ "Cross-industry" ], "domain": [ "ACT.RESIL" ], "tags": [ "business", "continuity", "recovery", "act.resil" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-act-043-business-continuity-recovery/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-act-043", "model": { "registry_id": "vr.wm-act-043", "model_id": "WM-ACT-043", "name": "Business Continuity / Recovery", "entry_kind": "aggregate", "purpose": "Represent a governed continuity capability that identifies critical delivery, analyzes disruption impacts, releases strategies and plans, proves readiness through exercises, records activation and verifies recovery and reconstitution without absorbing the systems it coordinates.", "scope_statement": "Owns continuity-capability identity and lineage, scope profile, mandate and governance, BIA releases, priority and objective assertions, dependency views, strategy decisions, plan and procedure releases, readiness assertions, exercise design and evidence, activation decisions, continuity-mode observations, recovery verification, reconstitution, improvement, access, retention and interoperability. Organization, Product, Service, Activity, Incident, Incident Response, Risk, Person, Role, Facility, Asset, Information System, Dataset, Supplier, Contract, Communication and Audit masters remain external.", "in_scope": [ "Capability identity, governance, BIA, critical delivery, priorities, impact tolerances, recovery objectives, dependencies and strategy", "Versioned plans and procedures, people and resource readiness, supply-chain continuity, exercises, assurance and corrective action", "Activation, continuity mode, restoration, recovery verification, reconstitution, lifecycle, metrics, provenance, protected access and safe agents" ], "out_of_scope": [ "Independent organization, service, activity, incident, response, risk, resource, supplier, contract, communication or audit master lifecycles", "Treating targets as outcomes, plans as activations, invocations as execution, backups as verified recovery or exercises as proof of real-event success", "Executing emergency actions, operating infrastructure, interpreting all sector law, certifying ISO conformance or guaranteeing uninterrupted service" ], "boundary_notes": [ { "neighbor": "WM-ACT-008 Plan / Schedule candidate parent", "distinction": "Generic plan identity and scheduling scaffolding may be inherited, while continuity-specific BIA, strategy, readiness, exercise, activation and recovery semantics remain here; the registry parent is not an approved relation row.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ] }, { "neighbor": "WM-ACT-042 Incident Response candidate incoming reference", "distinction": "Incident Response may request plan invocation and retain its response case; this model owns plan releases, activation evidence, continuity mode, recovery verification and reconstitution without owning incident facts.", "source_refs": [ "SRC-010", "SRC-011" ] }, { "neighbor": "Incident, Crisis Management and Emergency Management", "distinction": "Those models own what happened, strategic crisis command or emergency response. This aggregate binds their references and owns continuity-capability state only.", "source_refs": [ "SRC-008", "SRC-011", "SRC-012" ] }, { "neighbor": "Organization, Product, Service and Activity", "distinction": "The capability records why referenced delivery is prioritized and at what bounded level, but external masters own identity and normal operational state.", "source_refs": [ "SRC-001", "SRC-003", "SRC-012", "SRC-013" ] }, { "neighbor": "People, facilities, assets, systems, data, suppliers and contracts", "distinction": "Readiness and dependency assertions reference authoritative masters; this model does not copy their inventories, custody, employment or contract lifecycles.", "source_refs": [ "SRC-005", "SRC-006", "SRC-009", "SRC-012", "SRC-013" ] } ] }, "sources": [ { "id": "SRC-001", "title": "ISO 22301:2019 Security and resilience: Business continuity management systems: Requirements", "organization": "International Organization for Standardization", "url": "https://www.iso.org/standard/75106.html", "version_or_date": "Edition 2, October 2019, with Amendment 1:2024; public catalogue material only", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T08:05:00Z", "relevance": "BCMS requirements frame for protecting against, preparing for, responding to and recovering from disruption while continuing products and services at predefined capacity." }, { "id": "SRC-002", "title": "ISO 22313:2020 Guidance on the use of ISO 22301", "organization": "International Organization for Standardization", "url": "https://www.iso.org/standard/75107.html", "version_or_date": "Edition 2, February 2020, confirmed 2025 and marked for revision; public abstract only", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T08:05:00Z", "relevance": "Guidance for implementing, maintaining and improving a BCMS appropriate to organizational context and complexity." }, { "id": "SRC-003", "title": "ISO/TS 22317:2021 Guidelines for business impact analysis", "organization": "International Organization for Standardization", "url": "https://www.iso.org/standard/79000.html", "version_or_date": "Edition 2, November 2021, confirmed 2025; public abstract and public preview contents", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T08:05:00Z", "relevance": "Formal BIA process covering scope, roles, priorities, prioritized activities, resources, dependencies, consolidation, approval and review without prescribing one uniform method." }, { "id": "SRC-004", "title": "ISO/TS 22331:2018 Guidelines for business continuity strategy", "organization": "International Organization for Standardization", "url": "https://www.iso.org/standard/50068.html", "version_or_date": "Edition 1, October 2018, confirmed 2022 and marked for revision; public abstract only", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T08:05:00Z", "relevance": "Business continuity strategy determination and selection across organization types." }, { "id": "SRC-005", "title": "ISO/TS 22318:2021 Guidelines for supply chain continuity management", "organization": "International Organization for Standardization", "url": "https://www.iso.org/standard/79001.html", "version_or_date": "Edition 2, December 2021, confirmed 2025; public abstract only", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T08:05:00Z", "relevance": "Extends continuity principles to upstream and downstream supplier relationships and continuity of supply and delivery." }, { "id": "SRC-006", "title": "ISO/TS 22330:2018 Guidelines for people aspects of business continuity", "organization": "International Organization for Standardization", "url": "https://www.iso.org/standard/50067.html", "version_or_date": "Edition 1, June 2018, under review in 2026; public abstract only", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T08:05:00Z", "relevance": "People preparation, needs, learning, incident response, disruption support, recovery and post-restoration support." }, { "id": "SRC-007", "title": "ISO 22398:2013 Guidelines for exercises", "organization": "International Organization for Standardization", "url": "https://www.iso.org/standard/50294.html", "version_or_date": "Edition 1, September 2013, confirmed 2022; public abstract only", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T08:05:00Z", "relevance": "Planning, conducting and improving exercise programmes and projects, adaptable to objectives, resources and constraints." }, { "id": "SRC-008", "title": "ISO 22361:2022 Crisis management guidelines", "organization": "International Organization for Standardization", "url": "https://www.iso.org/standard/50267.html", "version_or_date": "Edition 1, October 2022; public abstract only", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T08:05:00Z", "relevance": "Separates strategic crisis leadership, decision making and communication capability from business continuity plan ownership while exposing their interdependencies." }, { "id": "SRC-009", "title": "SP 800-34 Rev. 1 Contingency Planning Guide for Federal Information Systems", "organization": "National Institute of Standards and Technology", "url": "https://csrc.nist.gov/pubs/sp/800/34/r1/upd1/final", "version_or_date": "Revision 1, May 2010, updated November 2010", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T08:05:00Z", "relevance": "BIA, contingency requirements and priorities, plan development, recovery strategies, testing, training, maintenance and links to risk and system lifecycles." }, { "id": "SRC-010", "title": "SP 800-184 Guide for Cybersecurity Event Recovery", "organization": "National Institute of Standards and Technology", "url": "https://csrc.nist.gov/pubs/sp/800/184/final", "version_or_date": "Final, December 2016", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T08:05:00Z", "relevance": "Strategic and tactical recovery planning, playbooks, tests, improvement, resource prioritization, communications and recovery metrics." }, { "id": "SRC-011", "title": "The NIST Cybersecurity Framework 2.0", "organization": "National Institute of Standards and Technology", "url": "https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20", "version_or_date": "NIST CSWP 29, February 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T08:05:00Z", "relevance": "Recover outcomes distinguish selecting and performing actions, verifying backups and restored assets, confirming operating status, declaring recovery end and communicating progress." }, { "id": "SRC-012", "title": "Continuity Guidance Circular", "organization": "Federal Emergency Management Agency", "url": "https://www.fema.gov/sites/default/files/documents/fema_continuity-guidance-circular_082024.pdf", "version_or_date": "2018 Continuity Guidance Circular, 2024 update", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T08:05:00Z", "relevance": "Whole-community continuity capability including essential functions, succession, delegation, communications, facilities, records, people, devolution, exercises and reconstitution." }, { "id": "SRC-013", "title": "Regulation (EU) 2022/2554 on digital operational resilience for the financial sector", "organization": "European Union", "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554", "version_or_date": "DORA, adopted 14 December 2022, applicable from 17 January 2025", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T08:05:00Z", "relevance": "Sector-specific requirements for ICT business continuity policy, BIA, response and recovery plans, backups, restoration, annual tests, crisis communications and records." }, { "id": "SRC-014", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T08:05:00Z", "relevance": "Attributable plans, activities, entities, agents, derivation, revision, invalidation, generation and usage." }, { "id": "SRC-015", "title": "Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/info/rfc3339/", "version_or_date": "RFC 3339, July 2002", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T08:05:00Z", "relevance": "Unambiguous event timestamps with seconds and an explicit UTC relationship." } ], "structure": { "bundles": [ { "id": "capability-identity-governance-and-authority", "name": "Capability identity, governance and authority", "description": "Groups governed context for capability identity, governance and authority.", "rationale": "A stable continuity capability binds an accountable scope and released definition without becoming the organization or service master.", "source_refs": [ "SRC-001", "SRC-002", "SRC-008", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ], "layers": [ { "id": "capability-scope-profile-identity-and-lineage", "name": "Capability scope, profile, identity and lineage", "description": "Groups continuity context for capability scope, profile, identity and lineage.", "source_refs": [ "SRC-001", "SRC-002", "SRC-012", "SRC-014", "SRC-015" ], "findings": [ { "id": "continuity-capability-type-boundary-owner-and-distinguishing-criteria", "name": "Continuity capability type, boundary, owner and distinguishing criteria", "description": "Records continuity capability type, boundary, owner and distinguishing criteria as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-001", "SRC-002", "SRC-012", "SRC-014", "SRC-015" ], "questions": [ { "id": "continuity-capability-type-boundary-owner-and-distinguishing-criteria-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish continuity capability type, boundary, owner and distinguishing criteria?", "kind": "classification", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "continuity-capability-type-boundary-owner-and-distinguishing-criteria-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support continuity capability type, boundary, owner and distinguishing criteria?", "kind": "state", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "continuity-capability-type-boundary-owner-and-distinguishing-criteria-q03", "text": "How may continuity capability type, boundary, owner and distinguishing criteria be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "process", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "continuity-capability-type-boundary-owner-and-distinguishing-criteria-data", "name": "Continuity capability type, boundary, owner and distinguishing criteria data", "description": "Structured data for continuity capability type, boundary, owner and distinguishing criteria with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-012", "SRC-014", "SRC-015" ] } ], "artifacts": [ { "id": "continuity-capability-type-boundary-owner-and-distinguishing-criteria-record", "name": "Continuity capability type, boundary, owner and distinguishing criteria record", "description": "Versioned evidence-bearing continuity record for continuity capability type, boundary, owner and distinguishing criteria.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus continuity-capability-type-boundary-owner-and-distinguishing-criteria assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-012", "SRC-014", "SRC-015" ] } ], "inline_only_rationale": null }, { "id": "capability-identifier-definition-release-status-predecessor-successor-and-lineage", "name": "Capability identifier, definition release, status, predecessor, successor and lineage", "description": "Records capability identifier, definition release, status, predecessor, successor and lineage as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-001", "SRC-002", "SRC-012", "SRC-014", "SRC-015" ], "questions": [ { "id": "capability-identifier-definition-release-status-predecessor-successor-and-lineage-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish capability identifier, definition release, status, predecessor, successor and lineage?", "kind": "identity", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "capability-identifier-definition-release-status-predecessor-successor-and-lineage-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support capability identifier, definition release, status, predecessor, successor and lineage?", "kind": "ownership", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "capability-identifier-definition-release-status-predecessor-successor-and-lineage-q03", "text": "How may capability identifier, definition release, status, predecessor, successor and lineage be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "interoperability", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "capability-identifier-definition-release-status-predecessor-successor-and-lineage-data", "name": "Capability identifier, definition release, status, predecessor, successor and lineage data", "description": "Structured data for capability identifier, definition release, status, predecessor, successor and lineage with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-012", "SRC-014", "SRC-015" ] } ], "artifacts": [ { "id": "capability-identifier-definition-release-status-predecessor-successor-and-lineage-record", "name": "Capability identifier, definition release, status, predecessor, successor and lineage record", "description": "Versioned evidence-bearing continuity record for capability identifier, definition release, status, predecessor, successor and lineage.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus capability-identifier-definition-release-status-predecessor-successor-and-lineage assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-012", "SRC-014", "SRC-015" ] } ], "inline_only_rationale": null } ] }, { "id": "policy-mandate-obligations-roles-and-decision-rights", "name": "Policy, mandate, obligations, roles and decision rights", "description": "Groups continuity context for policy, mandate, obligations, roles and decision rights.", "source_refs": [ "SRC-001", "SRC-002", "SRC-008", "SRC-012", "SRC-013", "SRC-014" ], "findings": [ { "id": "policy-context-jurisdiction-interested-parties-obligations-and-assurance-basis", "name": "Policy, context, jurisdiction, interested parties, obligations and assurance basis", "description": "Records policy, context, jurisdiction, interested parties, obligations and assurance basis as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-001", "SRC-002", "SRC-008", "SRC-012", "SRC-013", "SRC-014" ], "questions": [ { "id": "policy-context-jurisdiction-interested-parties-obligations-and-assurance-basis-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish policy, context, jurisdiction, interested parties, obligations and assurance basis?", "kind": "authority", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "policy-context-jurisdiction-interested-parties-obligations-and-assurance-basis-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support policy, context, jurisdiction, interested parties, obligations and assurance basis?", "kind": "event", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "policy-context-jurisdiction-interested-parties-obligations-and-assurance-basis-q03", "text": "How may policy, context, jurisdiction, interested parties, obligations and assurance basis be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "spatial", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "policy-context-jurisdiction-interested-parties-obligations-and-assurance-basis-data", "name": "Policy, context, jurisdiction, interested parties, obligations and assurance basis data", "description": "Structured data for policy, context, jurisdiction, interested parties, obligations and assurance basis with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-008", "SRC-012", "SRC-013", "SRC-014" ] } ], "artifacts": [ { "id": "policy-context-jurisdiction-interested-parties-obligations-and-assurance-basis-record", "name": "Policy, context, jurisdiction, interested parties, obligations and assurance basis record", "description": "Versioned evidence-bearing continuity record for policy, context, jurisdiction, interested parties, obligations and assurance basis.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus policy-context-jurisdiction-interested-parties-obligations-and-assurance-basis assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-008", "SRC-012", "SRC-013", "SRC-014" ] } ], "inline_only_rationale": null }, { "id": "governance-owner-succession-delegation-escalation-approval-and-contestability", "name": "Governance owner, succession, delegation, escalation, approval and contestability", "description": "Records governance owner, succession, delegation, escalation, approval and contestability as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-001", "SRC-002", "SRC-008", "SRC-012", "SRC-013", "SRC-014" ], "questions": [ { "id": "governance-owner-succession-delegation-escalation-approval-and-contestability-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish governance owner, succession, delegation, escalation, approval and contestability?", "kind": "ownership", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "governance-owner-succession-delegation-escalation-approval-and-contestability-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support governance owner, succession, delegation, escalation, approval and contestability?", "kind": "security", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "governance-owner-succession-delegation-escalation-approval-and-contestability-q03", "text": "How may governance owner, succession, delegation, escalation, approval and contestability be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "validation", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "governance-owner-succession-delegation-escalation-approval-and-contestability-data", "name": "Governance owner, succession, delegation, escalation, approval and contestability data", "description": "Structured data for governance owner, succession, delegation, escalation, approval and contestability with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-008", "SRC-012", "SRC-013", "SRC-014" ] } ], "artifacts": [ { "id": "governance-owner-succession-delegation-escalation-approval-and-contestability-record", "name": "Governance owner, succession, delegation, escalation, approval and contestability record", "description": "Versioned evidence-bearing continuity record for governance owner, succession, delegation, escalation, approval and contestability.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus governance-owner-succession-delegation-escalation-approval-and-contestability assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-008", "SRC-012", "SRC-013", "SRC-014" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "impact-analysis-priorities-objectives-and-dependencies", "name": "Impact analysis, priorities, objectives and dependencies", "description": "Groups governed context for impact analysis, priorities, objectives and dependencies.", "rationale": "Source-qualified analysis separates impact tolerance and organizational priorities from promised or measured recovery outcomes.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013" ], "layers": [ { "id": "products-services-activities-impacts-and-tolerances", "name": "Products, services, activities, impacts and tolerances", "description": "Groups continuity context for products, services, activities, impacts and tolerances.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-009", "SRC-012", "SRC-013" ], "findings": [ { "id": "critical-product-service-and-prioritized-activity-reference", "name": "Critical product, service and prioritized activity reference", "description": "Records critical product, service and prioritized activity reference as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-009", "SRC-012", "SRC-013" ], "questions": [ { "id": "critical-product-service-and-prioritized-activity-reference-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish critical product, service and prioritized activity reference?", "kind": "relationship", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "critical-product-service-and-prioritized-activity-reference-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support critical product, service and prioritized activity reference?", "kind": "interoperability", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "critical-product-service-and-prioritized-activity-reference-q03", "text": "How may critical product, service and prioritized activity reference be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "classification", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "critical-product-service-and-prioritized-activity-reference-data", "name": "Critical product, service and prioritized activity reference data", "description": "Structured data for critical product, service and prioritized activity reference with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-009", "SRC-012", "SRC-013" ] } ], "artifacts": [ { "id": "critical-product-service-and-prioritized-activity-reference-record", "name": "Critical product, service and prioritized activity reference record", "description": "Versioned evidence-bearing continuity record for critical product, service and prioritized activity reference.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus critical-product-service-and-prioritized-activity-reference assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-009", "SRC-012", "SRC-013" ] } ], "inline_only_rationale": null }, { "id": "impact-category-severity-over-time-maximum-tolerable-disruption-and-justification", "name": "Impact category, severity over time, maximum tolerable disruption and justification", "description": "Records impact category, severity over time, maximum tolerable disruption and justification as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-009", "SRC-012", "SRC-013" ], "questions": [ { "id": "impact-category-severity-over-time-maximum-tolerable-disruption-and-justification-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish impact category, severity over time, maximum tolerable disruption and justification?", "kind": "measurement", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "impact-category-severity-over-time-maximum-tolerable-disruption-and-justification-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support impact category, severity over time, maximum tolerable disruption and justification?", "kind": "classification", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "impact-category-severity-over-time-maximum-tolerable-disruption-and-justification-q03", "text": "How may impact category, severity over time, maximum tolerable disruption and justification be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "constraint", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "impact-category-severity-over-time-maximum-tolerable-disruption-and-justification-data", "name": "Impact category, severity over time, maximum tolerable disruption and justification data", "description": "Structured data for impact category, severity over time, maximum tolerable disruption and justification with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-009", "SRC-012", "SRC-013" ] } ], "artifacts": [ { "id": "impact-category-severity-over-time-maximum-tolerable-disruption-and-justification-record", "name": "Impact category, severity over time, maximum tolerable disruption and justification record", "description": "Versioned evidence-bearing continuity record for impact category, severity over time, maximum tolerable disruption and justification.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus impact-category-severity-over-time-maximum-tolerable-disruption-and-justification assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-009", "SRC-012", "SRC-013" ] } ], "inline_only_rationale": null } ] }, { "id": "recovery-objectives-resources-and-interdependencies", "name": "Recovery objectives, resources and interdependencies", "description": "Groups continuity context for recovery objectives, resources and interdependencies.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-013" ], "findings": [ { "id": "recovery-time-data-loss-capacity-and-service-level-objective-assertion", "name": "Recovery time, data-loss, capacity and service-level objective assertion", "description": "Records recovery time, data-loss, capacity and service-level objective assertion as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-013" ], "questions": [ { "id": "recovery-time-data-loss-capacity-and-service-level-objective-assertion-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish recovery time, data-loss, capacity and service-level objective assertion?", "kind": "requirement", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "recovery-time-data-loss-capacity-and-service-level-objective-assertion-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support recovery time, data-loss, capacity and service-level objective assertion?", "kind": "temporal", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "recovery-time-data-loss-capacity-and-service-level-objective-assertion-q03", "text": "How may recovery time, data-loss, capacity and service-level objective assertion be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "exception", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "recovery-time-data-loss-capacity-and-service-level-objective-assertion-data", "name": "Recovery time, data-loss, capacity and service-level objective assertion data", "description": "Structured data for recovery time, data-loss, capacity and service-level objective assertion with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-013" ] } ], "artifacts": [ { "id": "recovery-time-data-loss-capacity-and-service-level-objective-assertion-record", "name": "Recovery time, data-loss, capacity and service-level objective assertion record", "description": "Versioned evidence-bearing continuity record for recovery time, data-loss, capacity and service-level objective assertion.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus recovery-time-data-loss-capacity-and-service-level-objective-assertion assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-013" ] } ], "inline_only_rationale": null }, { "id": "people-facility-technology-information-supplier-resource-dependency-and-single-point-risk", "name": "People, facility, technology, information, supplier, resource dependency and single-point risk", "description": "Records people, facility, technology, information, supplier, resource dependency and single-point risk as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-013" ], "questions": [ { "id": "people-facility-technology-information-supplier-resource-dependency-and-single-point-risk-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish people, facility, technology, information, supplier, resource dependency and single-point risk?", "kind": "composition", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "people-facility-technology-information-supplier-resource-dependency-and-single-point-risk-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support people, facility, technology, information, supplier, resource dependency and single-point risk?", "kind": "requirement", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "people-facility-technology-information-supplier-resource-dependency-and-single-point-risk-q03", "text": "How may people, facility, technology, information, supplier, resource dependency and single-point risk be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "temporal", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "people-facility-technology-information-supplier-resource-dependency-and-single-point-risk-data", "name": "People, facility, technology, information, supplier, resource dependency and single-point risk data", "description": "Structured data for people, facility, technology, information, supplier, resource dependency and single-point risk with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-013" ] } ], "artifacts": [ { "id": "people-facility-technology-information-supplier-resource-dependency-and-single-point-risk-record", "name": "People, facility, technology, information, supplier, resource dependency and single-point risk record", "description": "Versioned evidence-bearing continuity record for people, facility, technology, information, supplier, resource dependency and single-point risk.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus people-facility-technology-information-supplier-resource-dependency-and-single-point-risk assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-013" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "strategy-solutions-plans-and-procedures", "name": "Strategy, solutions, plans and procedures", "description": "Groups governed context for strategy, solutions, plans and procedures.", "rationale": "Versioned strategies and executable plan releases make tradeoffs, activation rules and dependencies explicit.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-015" ], "layers": [ { "id": "strategy-options-selection-and-solution-design", "name": "Strategy options, selection and solution design", "description": "Groups continuity context for strategy options, selection and solution design.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-009", "SRC-010", "SRC-012", "SRC-013" ], "findings": [ { "id": "continuity-strategy-option-feasibility-cost-risk-capacity-and-selection-rationale", "name": "Continuity strategy option, feasibility, cost, risk, capacity and selection rationale", "description": "Records continuity strategy option, feasibility, cost, risk, capacity and selection rationale as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-009", "SRC-010", "SRC-012", "SRC-013" ], "questions": [ { "id": "continuity-strategy-option-feasibility-cost-risk-capacity-and-selection-rationale-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish continuity strategy option, feasibility, cost, risk, capacity and selection rationale?", "kind": "decision", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "continuity-strategy-option-feasibility-cost-risk-capacity-and-selection-rationale-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support continuity strategy option, feasibility, cost, risk, capacity and selection rationale?", "kind": "evidence", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "continuity-strategy-option-feasibility-cost-risk-capacity-and-selection-rationale-q03", "text": "How may continuity strategy option, feasibility, cost, risk, capacity and selection rationale be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "quality", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "continuity-strategy-option-feasibility-cost-risk-capacity-and-selection-rationale-data", "name": "Continuity strategy option, feasibility, cost, risk, capacity and selection rationale data", "description": "Structured data for continuity strategy option, feasibility, cost, risk, capacity and selection rationale with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-009", "SRC-010", "SRC-012", "SRC-013" ] } ], "artifacts": [ { "id": "continuity-strategy-option-feasibility-cost-risk-capacity-and-selection-rationale-record", "name": "Continuity strategy option, feasibility, cost, risk, capacity and selection rationale record", "description": "Versioned evidence-bearing continuity record for continuity strategy option, feasibility, cost, risk, capacity and selection rationale.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus continuity-strategy-option-feasibility-cost-risk-capacity-and-selection-rationale assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-009", "SRC-010", "SRC-012", "SRC-013" ] } ], "inline_only_rationale": null }, { "id": "alternate-site-manual-workaround-redundancy-backup-substitution-and-supplier-solution", "name": "Alternate site, manual workaround, redundancy, backup, substitution and supplier solution", "description": "Records alternate site, manual workaround, redundancy, backup, substitution and supplier solution as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-009", "SRC-010", "SRC-012", "SRC-013" ], "questions": [ { "id": "alternate-site-manual-workaround-redundancy-backup-substitution-and-supplier-solution-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish alternate site, manual workaround, redundancy, backup, substitution and supplier solution?", "kind": "composition", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "alternate-site-manual-workaround-redundancy-backup-substitution-and-supplier-solution-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support alternate site, manual workaround, redundancy, backup, substitution and supplier solution?", "kind": "retention", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "alternate-site-manual-workaround-redundancy-backup-substitution-and-supplier-solution-q03", "text": "How may alternate site, manual workaround, redundancy, backup, substitution and supplier solution be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "identity", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "alternate-site-manual-workaround-redundancy-backup-substitution-and-supplier-solution-data", "name": "Alternate site, manual workaround, redundancy, backup, substitution and supplier solution data", "description": "Structured data for alternate site, manual workaround, redundancy, backup, substitution and supplier solution with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-009", "SRC-010", "SRC-012", "SRC-013" ] } ], "artifacts": [ { "id": "alternate-site-manual-workaround-redundancy-backup-substitution-and-supplier-solution-record", "name": "Alternate site, manual workaround, redundancy, backup, substitution and supplier solution record", "description": "Versioned evidence-bearing continuity record for alternate site, manual workaround, redundancy, backup, substitution and supplier solution.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus alternate-site-manual-workaround-redundancy-backup-substitution-and-supplier-solution assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-005", "SRC-009", "SRC-010", "SRC-012", "SRC-013" ] } ], "inline_only_rationale": null } ] }, { "id": "plan-release-activation-tasks-coordination-and-communications", "name": "Plan release, activation, tasks, coordination and communications", "description": "Groups continuity context for plan release, activation, tasks, coordination and communications.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-015" ], "findings": [ { "id": "plan-profile-release-applicability-trigger-threshold-authority-and-deactivation-criteria", "name": "Plan profile, release, applicability, trigger, threshold, authority and deactivation criteria", "description": "Records plan profile, release, applicability, trigger, threshold, authority and deactivation criteria as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-015" ], "questions": [ { "id": "plan-profile-release-applicability-trigger-threshold-authority-and-deactivation-criteria-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish plan profile, release, applicability, trigger, threshold, authority and deactivation criteria?", "kind": "lifecycle", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "plan-profile-release-applicability-trigger-threshold-authority-and-deactivation-criteria-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support plan profile, release, applicability, trigger, threshold, authority and deactivation criteria?", "kind": "other", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "plan-profile-release-applicability-trigger-threshold-authority-and-deactivation-criteria-q03", "text": "How may plan profile, release, applicability, trigger, threshold, authority and deactivation criteria be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "requirement", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "plan-profile-release-applicability-trigger-threshold-authority-and-deactivation-criteria-data", "name": "Plan profile, release, applicability, trigger, threshold, authority and deactivation criteria data", "description": "Structured data for plan profile, release, applicability, trigger, threshold, authority and deactivation criteria with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-015" ] } ], "artifacts": [ { "id": "plan-profile-release-applicability-trigger-threshold-authority-and-deactivation-criteria-record", "name": "Plan profile, release, applicability, trigger, threshold, authority and deactivation criteria record", "description": "Versioned evidence-bearing continuity record for plan profile, release, applicability, trigger, threshold, authority and deactivation criteria.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus plan-profile-release-applicability-trigger-threshold-authority-and-deactivation-criteria assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-015" ] } ], "inline_only_rationale": null }, { "id": "procedure-step-role-dependency-resource-contact-message-channel-and-escalation", "name": "Procedure step, role, dependency, resource, contact, message, channel and escalation", "description": "Records procedure step, role, dependency, resource, contact, message, channel and escalation as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-015" ], "questions": [ { "id": "procedure-step-role-dependency-resource-contact-message-channel-and-escalation-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish procedure step, role, dependency, resource, contact, message, channel and escalation?", "kind": "process", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "procedure-step-role-dependency-resource-contact-message-channel-and-escalation-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support procedure step, role, dependency, resource, contact, message, channel and escalation?", "kind": "relationship", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "procedure-step-role-dependency-resource-contact-message-channel-and-escalation-q03", "text": "How may procedure step, role, dependency, resource, contact, message, channel and escalation be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "access", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "procedure-step-role-dependency-resource-contact-message-channel-and-escalation-data", "name": "Procedure step, role, dependency, resource, contact, message, channel and escalation data", "description": "Structured data for procedure step, role, dependency, resource, contact, message, channel and escalation with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-015" ] } ], "artifacts": [ { "id": "procedure-step-role-dependency-resource-contact-message-channel-and-escalation-record", "name": "Procedure step, role, dependency, resource, contact, message, channel and escalation record", "description": "Versioned evidence-bearing continuity record for procedure step, role, dependency, resource, contact, message, channel and escalation.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus procedure-step-role-dependency-resource-contact-message-channel-and-escalation assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-015" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "people-resources-supply-chain-and-operational-readiness", "name": "People, resources, supply chain and operational readiness", "description": "Groups governed context for people, resources, supply chain and operational readiness.", "rationale": "Continuity depends on competent people and verified resources whose external master identities and custody remain separate.", "source_refs": [ "SRC-001", "SRC-005", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014" ], "layers": [ { "id": "people-competence-facilities-systems-records-and-recovery-assets", "name": "People, competence, facilities, systems, records and recovery assets", "description": "Groups continuity context for people, competence, facilities, systems, records and recovery assets.", "source_refs": [ "SRC-001", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013" ], "findings": [ { "id": "role-team-contact-succession-delegation-training-awareness-and-welfare-readiness", "name": "Role, team, contact, succession, delegation, training, awareness and welfare readiness", "description": "Records role, team, contact, succession, delegation, training, awareness and welfare readiness as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-001", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013" ], "questions": [ { "id": "role-team-contact-succession-delegation-training-awareness-and-welfare-readiness-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish role, team, contact, succession, delegation, training, awareness and welfare readiness?", "kind": "quality", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "role-team-contact-succession-delegation-training-awareness-and-welfare-readiness-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support role, team, contact, succession, delegation, training, awareness and welfare readiness?", "kind": "provenance", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "role-team-contact-succession-delegation-training-awareness-and-welfare-readiness-q03", "text": "How may role, team, contact, succession, delegation, training, awareness and welfare readiness be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "lifecycle", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "role-team-contact-succession-delegation-training-awareness-and-welfare-readiness-data", "name": "Role, team, contact, succession, delegation, training, awareness and welfare readiness data", "description": "Structured data for role, team, contact, succession, delegation, training, awareness and welfare readiness with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013" ] } ], "artifacts": [ { "id": "role-team-contact-succession-delegation-training-awareness-and-welfare-readiness-record", "name": "Role, team, contact, succession, delegation, training, awareness and welfare readiness record", "description": "Versioned evidence-bearing continuity record for role, team, contact, succession, delegation, training, awareness and welfare readiness.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus role-team-contact-succession-delegation-training-awareness-and-welfare-readiness assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-001", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013" ] } ], "inline_only_rationale": null }, { "id": "facility-system-data-record-backup-tool-stock-and-minimum-resource-readiness", "name": "Facility, system, data, record, backup, tool, stock and minimum-resource readiness", "description": "Records facility, system, data, record, backup, tool, stock and minimum-resource readiness as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-001", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013" ], "questions": [ { "id": "facility-system-data-record-backup-tool-stock-and-minimum-resource-readiness-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish facility, system, data, record, backup, tool, stock and minimum-resource readiness?", "kind": "validation", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "facility-system-data-record-backup-tool-stock-and-minimum-resource-readiness-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support facility, system, data, record, backup, tool, stock and minimum-resource readiness?", "kind": "process", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "facility-system-data-record-backup-tool-stock-and-minimum-resource-readiness-q03", "text": "How may facility, system, data, record, backup, tool, stock and minimum-resource readiness be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "evidence", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "facility-system-data-record-backup-tool-stock-and-minimum-resource-readiness-data", "name": "Facility, system, data, record, backup, tool, stock and minimum-resource readiness data", "description": "Structured data for facility, system, data, record, backup, tool, stock and minimum-resource readiness with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013" ] } ], "artifacts": [ { "id": "facility-system-data-record-backup-tool-stock-and-minimum-resource-readiness-record", "name": "Facility, system, data, record, backup, tool, stock and minimum-resource readiness record", "description": "Versioned evidence-bearing continuity record for facility, system, data, record, backup, tool, stock and minimum-resource readiness.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus facility-system-data-record-backup-tool-stock-and-minimum-resource-readiness assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-001", "SRC-006", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013" ] } ], "inline_only_rationale": null } ] }, { "id": "supplier-contract-reciprocal-and-external-dependency-readiness", "name": "Supplier, contract, reciprocal and external-dependency readiness", "description": "Groups continuity context for supplier, contract, reciprocal and external-dependency readiness.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-012", "SRC-013", "SRC-014" ], "findings": [ { "id": "supplier-service-contract-obligation-contact-capacity-location-and-concentration-binding", "name": "Supplier, service, contract, obligation, contact, capacity, location and concentration binding", "description": "Records supplier, service, contract, obligation, contact, capacity, location and concentration binding as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-012", "SRC-013", "SRC-014" ], "questions": [ { "id": "supplier-service-contract-obligation-contact-capacity-location-and-concentration-binding-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish supplier, service, contract, obligation, contact, capacity, location and concentration binding?", "kind": "relationship", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "supplier-service-contract-obligation-contact-capacity-location-and-concentration-binding-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support supplier, service, contract, obligation, contact, capacity, location and concentration binding?", "kind": "validation", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "supplier-service-contract-obligation-contact-capacity-location-and-concentration-binding-q03", "text": "How may supplier, service, contract, obligation, contact, capacity, location and concentration binding be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "definition", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "supplier-service-contract-obligation-contact-capacity-location-and-concentration-binding-data", "name": "Supplier, service, contract, obligation, contact, capacity, location and concentration binding data", "description": "Structured data for supplier, service, contract, obligation, contact, capacity, location and concentration binding with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-012", "SRC-013", "SRC-014" ] } ], "artifacts": [ { "id": "supplier-service-contract-obligation-contact-capacity-location-and-concentration-binding-record", "name": "Supplier, service, contract, obligation, contact, capacity, location and concentration binding record", "description": "Versioned evidence-bearing continuity record for supplier, service, contract, obligation, contact, capacity, location and concentration binding.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus supplier-service-contract-obligation-contact-capacity-location-and-concentration-binding assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-012", "SRC-013", "SRC-014" ] } ], "inline_only_rationale": null }, { "id": "alternate-source-reciprocal-agreement-failover-test-assurance-exception-and-escalation", "name": "Alternate source, reciprocal agreement, failover test, assurance, exception and escalation", "description": "Records alternate source, reciprocal agreement, failover test, assurance, exception and escalation as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-012", "SRC-013", "SRC-014" ], "questions": [ { "id": "alternate-source-reciprocal-agreement-failover-test-assurance-exception-and-escalation-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish alternate source, reciprocal agreement, failover test, assurance, exception and escalation?", "kind": "exception", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "alternate-source-reciprocal-agreement-failover-test-assurance-exception-and-escalation-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support alternate source, reciprocal agreement, failover test, assurance, exception and escalation?", "kind": "interoperability", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "alternate-source-reciprocal-agreement-failover-test-assurance-exception-and-escalation-q03", "text": "How may alternate source, reciprocal agreement, failover test, assurance, exception and escalation be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "authority", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "alternate-source-reciprocal-agreement-failover-test-assurance-exception-and-escalation-data", "name": "Alternate source, reciprocal agreement, failover test, assurance, exception and escalation data", "description": "Structured data for alternate source, reciprocal agreement, failover test, assurance, exception and escalation with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-012", "SRC-013", "SRC-014" ] } ], "artifacts": [ { "id": "alternate-source-reciprocal-agreement-failover-test-assurance-exception-and-escalation-record", "name": "Alternate source, reciprocal agreement, failover test, assurance, exception and escalation record", "description": "Versioned evidence-bearing continuity record for alternate source, reciprocal agreement, failover test, assurance, exception and escalation.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus alternate-source-reciprocal-agreement-failover-test-assurance-exception-and-escalation assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-001", "SRC-005", "SRC-009", "SRC-012", "SRC-013", "SRC-014" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "exercises-assurance-corrective-action-and-improvement", "name": "Exercises, assurance, corrective action and improvement", "description": "Groups governed context for exercises, assurance, corrective action and improvement.", "rationale": "Exercises produce bounded evidence, not proof that every real disruption can be recovered.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ], "layers": [ { "id": "exercise-programme-scenario-objectives-participants-and-controls", "name": "Exercise programme, scenario, objectives, participants and controls", "description": "Groups continuity context for exercise programme, scenario, objectives, participants and controls.", "source_refs": [ "SRC-001", "SRC-006", "SRC-007", "SRC-009", "SRC-010", "SRC-012", "SRC-013", "SRC-015" ], "findings": [ { "id": "exercise-type-scope-objective-scenario-assumption-inject-and-success-criterion", "name": "Exercise type, scope, objective, scenario, assumption, inject and success criterion", "description": "Records exercise type, scope, objective, scenario, assumption, inject and success criterion as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-001", "SRC-006", "SRC-007", "SRC-009", "SRC-010", "SRC-012", "SRC-013", "SRC-015" ], "questions": [ { "id": "exercise-type-scope-objective-scenario-assumption-inject-and-success-criterion-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish exercise type, scope, objective, scenario, assumption, inject and success criterion?", "kind": "definition", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "exercise-type-scope-objective-scenario-assumption-inject-and-success-criterion-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support exercise type, scope, objective, scenario, assumption, inject and success criterion?", "kind": "identity", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "exercise-type-scope-objective-scenario-assumption-inject-and-success-criterion-q03", "text": "How may exercise type, scope, objective, scenario, assumption, inject and success criterion be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "retention", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "exercise-type-scope-objective-scenario-assumption-inject-and-success-criterion-data", "name": "Exercise type, scope, objective, scenario, assumption, inject and success criterion data", "description": "Structured data for exercise type, scope, objective, scenario, assumption, inject and success criterion with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-006", "SRC-007", "SRC-009", "SRC-010", "SRC-012", "SRC-013", "SRC-015" ] } ], "artifacts": [ { "id": "exercise-type-scope-objective-scenario-assumption-inject-and-success-criterion-record", "name": "Exercise type, scope, objective, scenario, assumption, inject and success criterion record", "description": "Versioned evidence-bearing continuity record for exercise type, scope, objective, scenario, assumption, inject and success criterion.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus exercise-type-scope-objective-scenario-assumption-inject-and-success-criterion assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-001", "SRC-006", "SRC-007", "SRC-009", "SRC-010", "SRC-012", "SRC-013", "SRC-015" ] } ], "inline_only_rationale": null }, { "id": "participant-role-observer-safety-control-environment-schedule-and-conduct-event", "name": "Participant, role, observer, safety control, environment, schedule and conduct event", "description": "Records participant, role, observer, safety control, environment, schedule and conduct event as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-001", "SRC-006", "SRC-007", "SRC-009", "SRC-010", "SRC-012", "SRC-013", "SRC-015" ], "questions": [ { "id": "participant-role-observer-safety-control-environment-schedule-and-conduct-event-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish participant, role, observer, safety control, environment, schedule and conduct event?", "kind": "event", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "participant-role-observer-safety-control-environment-schedule-and-conduct-event-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support participant, role, observer, safety control, environment, schedule and conduct event?", "kind": "lifecycle", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "participant-role-observer-safety-control-environment-schedule-and-conduct-event-q03", "text": "How may participant, role, observer, safety control, environment, schedule and conduct event be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "state", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "participant-role-observer-safety-control-environment-schedule-and-conduct-event-data", "name": "Participant, role, observer, safety control, environment, schedule and conduct event data", "description": "Structured data for participant, role, observer, safety control, environment, schedule and conduct event with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-006", "SRC-007", "SRC-009", "SRC-010", "SRC-012", "SRC-013", "SRC-015" ] } ], "artifacts": [ { "id": "participant-role-observer-safety-control-environment-schedule-and-conduct-event-record", "name": "Participant, role, observer, safety control, environment, schedule and conduct event record", "description": "Versioned evidence-bearing continuity record for participant, role, observer, safety control, environment, schedule and conduct event.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus participant-role-observer-safety-control-environment-schedule-and-conduct-event assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-001", "SRC-006", "SRC-007", "SRC-009", "SRC-010", "SRC-012", "SRC-013", "SRC-015" ] } ], "inline_only_rationale": null } ] }, { "id": "evaluation-findings-actions-verification-and-learning", "name": "Evaluation, findings, actions, verification and learning", "description": "Groups continuity context for evaluation, findings, actions, verification and learning.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ], "findings": [ { "id": "observation-evidence-criterion-result-gap-strength-limit-and-confidence", "name": "Observation, evidence, criterion, result, gap, strength, limit and confidence", "description": "Records observation, evidence, criterion, result, gap, strength, limit and confidence as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ], "questions": [ { "id": "observation-evidence-criterion-result-gap-strength-limit-and-confidence-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish observation, evidence, criterion, result, gap, strength, limit and confidence?", "kind": "evidence", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "observation-evidence-criterion-result-gap-strength-limit-and-confidence-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support observation, evidence, criterion, result, gap, strength, limit and confidence?", "kind": "authority", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "observation-evidence-criterion-result-gap-strength-limit-and-confidence-q03", "text": "How may observation, evidence, criterion, result, gap, strength, limit and confidence be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "measurement", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "observation-evidence-criterion-result-gap-strength-limit-and-confidence-data", "name": "Observation, evidence, criterion, result, gap, strength, limit and confidence data", "description": "Structured data for observation, evidence, criterion, result, gap, strength, limit and confidence with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ] } ], "artifacts": [ { "id": "observation-evidence-criterion-result-gap-strength-limit-and-confidence-record", "name": "Observation, evidence, criterion, result, gap, strength, limit and confidence record", "description": "Versioned evidence-bearing continuity record for observation, evidence, criterion, result, gap, strength, limit and confidence.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus observation-evidence-criterion-result-gap-strength-limit-and-confidence assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ] } ], "inline_only_rationale": null }, { "id": "corrective-action-owner-priority-deadline-verification-effectiveness-and-plan-revision", "name": "Corrective action, owner, priority, deadline, verification, effectiveness and plan revision", "description": "Records corrective action, owner, priority, deadline, verification, effectiveness and plan revision as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ], "questions": [ { "id": "corrective-action-owner-priority-deadline-verification-effectiveness-and-plan-revision-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish corrective action, owner, priority, deadline, verification, effectiveness and plan revision?", "kind": "quality", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "corrective-action-owner-priority-deadline-verification-effectiveness-and-plan-revision-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support corrective action, owner, priority, deadline, verification, effectiveness and plan revision?", "kind": "measurement", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "corrective-action-owner-priority-deadline-verification-effectiveness-and-plan-revision-q03", "text": "How may corrective action, owner, priority, deadline, verification, effectiveness and plan revision be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "other", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "corrective-action-owner-priority-deadline-verification-effectiveness-and-plan-revision-data", "name": "Corrective action, owner, priority, deadline, verification, effectiveness and plan revision data", "description": "Structured data for corrective action, owner, priority, deadline, verification, effectiveness and plan revision with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ] } ], "artifacts": [ { "id": "corrective-action-owner-priority-deadline-verification-effectiveness-and-plan-revision-record", "name": "Corrective action, owner, priority, deadline, verification, effectiveness and plan revision record", "description": "Versioned evidence-bearing continuity record for corrective action, owner, priority, deadline, verification, effectiveness and plan revision.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus corrective-action-owner-priority-deadline-verification-effectiveness-and-plan-revision assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "activation-continuity-recovery-reconstitution-and-lifecycle", "name": "Activation, continuity, recovery, reconstitution and lifecycle", "description": "Groups governed context for activation, continuity, recovery, reconstitution and lifecycle.", "rationale": "Operational evidence distinguishes invocation, continuity mode, restoration, recovery verification, reconstitution and normal operation.", "source_refs": [ "SRC-001", "SRC-002", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ], "layers": [ { "id": "disruption-activation-continuity-mode-and-service-delivery", "name": "Disruption, activation, continuity mode and service delivery", "description": "Groups continuity context for disruption, activation, continuity mode and service delivery.", "source_refs": [ "SRC-001", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ], "findings": [ { "id": "incident-disruption-reference-activation-decision-parameters-scope-and-acknowledgement", "name": "Incident or disruption reference, activation decision, parameters, scope and acknowledgement", "description": "Records incident or disruption reference, activation decision, parameters, scope and acknowledgement as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-001", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ], "questions": [ { "id": "incident-disruption-reference-activation-decision-parameters-scope-and-acknowledgement-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish incident or disruption reference, activation decision, parameters, scope and acknowledgement?", "kind": "event", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "incident-disruption-reference-activation-decision-parameters-scope-and-acknowledgement-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support incident or disruption reference, activation decision, parameters, scope and acknowledgement?", "kind": "privacy", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "incident-disruption-reference-activation-decision-parameters-scope-and-acknowledgement-q03", "text": "How may incident or disruption reference, activation decision, parameters, scope and acknowledgement be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "ownership", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "incident-disruption-reference-activation-decision-parameters-scope-and-acknowledgement-data", "name": "Incident or disruption reference, activation decision, parameters, scope and acknowledgement data", "description": "Structured data for incident or disruption reference, activation decision, parameters, scope and acknowledgement with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ] } ], "artifacts": [ { "id": "incident-disruption-reference-activation-decision-parameters-scope-and-acknowledgement-record", "name": "Incident or disruption reference, activation decision, parameters, scope and acknowledgement record", "description": "Versioned evidence-bearing continuity record for incident or disruption reference, activation decision, parameters, scope and acknowledgement.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus incident-disruption-reference-activation-decision-parameters-scope-and-acknowledgement assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-001", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ] } ], "inline_only_rationale": null }, { "id": "continuity-task-workaround-resource-consumption-capacity-service-level-issue-and-communication", "name": "Continuity task, workaround, resource consumption, capacity, service level, issue and communication", "description": "Records continuity task, workaround, resource consumption, capacity, service level, issue and communication as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-001", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ], "questions": [ { "id": "continuity-task-workaround-resource-consumption-capacity-service-level-issue-and-communication-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish continuity task, workaround, resource consumption, capacity, service level, issue and communication?", "kind": "state", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "continuity-task-workaround-resource-consumption-capacity-service-level-issue-and-communication-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support continuity task, workaround, resource consumption, capacity, service level, issue and communication?", "kind": "decision", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "continuity-task-workaround-resource-consumption-capacity-service-level-issue-and-communication-q03", "text": "How may continuity task, workaround, resource consumption, capacity, service level, issue and communication be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "privacy", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "continuity-task-workaround-resource-consumption-capacity-service-level-issue-and-communication-data", "name": "Continuity task, workaround, resource consumption, capacity, service level, issue and communication data", "description": "Structured data for continuity task, workaround, resource consumption, capacity, service level, issue and communication with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ] } ], "artifacts": [ { "id": "continuity-task-workaround-resource-consumption-capacity-service-level-issue-and-communication-record", "name": "Continuity task, workaround, resource consumption, capacity, service level, issue and communication record", "description": "Versioned evidence-bearing continuity record for continuity task, workaround, resource consumption, capacity, service level, issue and communication.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus continuity-task-workaround-resource-consumption-capacity-service-level-issue-and-communication assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-001", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ] } ], "inline_only_rationale": null } ] }, { "id": "restoration-recovery-reconstitution-closure-and-record-lifecycle", "name": "Restoration, recovery, reconstitution, closure and record lifecycle", "description": "Groups continuity context for restoration, recovery, reconstitution, closure and record lifecycle.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ], "findings": [ { "id": "recovery-action-backup-integrity-restored-asset-service-verification-and-residual-risk", "name": "Recovery action, backup integrity, restored asset, service verification and residual risk", "description": "Records recovery action, backup integrity, restored asset, service verification and residual risk as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ], "questions": [ { "id": "recovery-action-backup-integrity-restored-asset-service-verification-and-residual-risk-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish recovery action, backup integrity, restored asset, service verification and residual risk?", "kind": "validation", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "recovery-action-backup-integrity-restored-asset-service-verification-and-residual-risk-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support recovery action, backup integrity, restored asset, service verification and residual risk?", "kind": "composition", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "recovery-action-backup-integrity-restored-asset-service-verification-and-residual-risk-q03", "text": "How may recovery action, backup integrity, restored asset, service verification and residual risk be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "relationship", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "recovery-action-backup-integrity-restored-asset-service-verification-and-residual-risk-data", "name": "Recovery action, backup integrity, restored asset, service verification and residual risk data", "description": "Structured data for recovery action, backup integrity, restored asset, service verification and residual risk with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ] } ], "artifacts": [ { "id": "recovery-action-backup-integrity-restored-asset-service-verification-and-residual-risk-record", "name": "Recovery action, backup integrity, restored asset, service verification and residual risk record", "description": "Versioned evidence-bearing continuity record for recovery action, backup integrity, restored asset, service verification and residual risk.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus recovery-action-backup-integrity-restored-asset-service-verification-and-residual-risk assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ] } ], "inline_only_rationale": null }, { "id": "reconstitution-return-to-normal-recovery-end-outcome-metric-correction-retention-and-disposition", "name": "Reconstitution, return to normal, recovery end, outcome metric, correction, retention and disposition", "description": "Records reconstitution, return to normal, recovery end, outcome metric, correction, retention and disposition as source-qualified continuity context while preserving external master ownership and distinguishing target, request, execution and verification.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ], "questions": [ { "id": "reconstitution-return-to-normal-recovery-end-outcome-metric-correction-retention-and-disposition-q01", "text": "What continuity-capability identities, classes, roles, versions, values and explicit unknowns establish reconstitution, return to normal, recovery end, outcome metric, correction, retention and disposition?", "kind": "retention", "answer_data": [ "identities and classifications", "roles, versions and values", "explicit unknowns" ] }, { "id": "reconstitution-return-to-normal-recovery-end-outcome-metric-correction-retention-and-disposition-q02", "text": "Which authority, source, method, evidence, event time, knowledge time, confidence and limits support reconstitution, return to normal, recovery end, outcome metric, correction, retention and disposition?", "kind": "spatial", "answer_data": [ "authority and source", "method and evidence", "times, confidence and limits" ] }, { "id": "reconstitution-return-to-normal-recovery-end-outcome-metric-correction-retention-and-disposition-q03", "text": "How may reconstitution, return to normal, recovery end, outcome metric, correction, retention and disposition be validated, exercised, activated, challenged, corrected, related, retained or disposed without losing history?", "kind": "event", "answer_data": [ "validation, exercise and activation", "challenge and correction", "relations, retention and disposition" ] } ], "data_elements": [ { "id": "reconstitution-return-to-normal-recovery-end-outcome-metric-correction-retention-and-disposition-data", "name": "Reconstitution, return to normal, recovery end, outcome metric, correction, retention and disposition data", "description": "Structured data for reconstitution, return to normal, recovery end, outcome metric, correction, retention and disposition with authority, time, state, evidence and access marking.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ] } ], "artifacts": [ { "id": "reconstitution-return-to-normal-recovery-end-outcome-metric-correction-retention-and-disposition-record", "name": "Reconstitution, return to normal, recovery end, outcome metric, correction, retention and disposition record", "description": "Versioned evidence-bearing continuity record for reconstitution, return to normal, recovery end, outcome metric, correction, retention and disposition.", "media_or_form": [ "logical continuity assertion", "plan, event, evidence, decision or outcome record" ], "serial": true, "identity_strategy": "Continuity capability ID plus reconstitution-return-to-normal-recovery-end-outcome-metric-correction-retention-and-disposition assertion or event ID; title, date, timestamp and digest never identify the capability alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013", "SRC-014", "SRC-015" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "register-continuity-capability", "name": "Register continuity capability", "description": "Governed operation to register continuity capability with attributable evidence and no hidden master-system mutation.", "inputs": [ "mandate", "scope", "owner", "profile" ], "outputs": [ "capability root" ], "preconditions": [ "identity, boundary and authority pass" ], "effects": [ "bounded capability exists" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-012", "SRC-014" ] }, { "id": "perform-business-impact-analysis", "name": "Perform business impact analysis", "description": "Governed operation to perform business impact analysis with attributable evidence and no hidden master-system mutation.", "inputs": [ "services", "activities", "impact criteria", "dependencies" ], "outputs": [ "approved BIA release" ], "preconditions": [ "scope, method, evidence and approver pass" ], "effects": [ "priorities and tolerances become explicit assertions" ], "source_refs": [ "SRC-003", "SRC-009", "SRC-012", "SRC-013" ] }, { "id": "set-recovery-objectives-and-select-strategy", "name": "Set recovery objectives and select strategy", "description": "Governed operation to set recovery objectives and select strategy with attributable evidence and no hidden master-system mutation.", "inputs": [ "BIA release", "risk and resource refs", "options" ], "outputs": [ "approved strategy release" ], "preconditions": [ "feasibility, tradeoff and authority pass" ], "effects": [ "targets and selected solutions are recorded without promising outcomes" ], "source_refs": [ "SRC-004", "SRC-009", "SRC-010", "SRC-013" ] }, { "id": "release-continuity-plan", "name": "Release continuity plan", "description": "Governed operation to release continuity plan with attributable evidence and no hidden master-system mutation.", "inputs": [ "strategy", "roles", "procedures", "activation criteria" ], "outputs": [ "immutable plan release" ], "preconditions": [ "dependencies, contacts, authority and validation pass" ], "effects": [ "an invocable versioned plan exists" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-012" ] }, { "id": "assess-operational-readiness", "name": "Assess operational readiness", "description": "Governed operation to assess operational readiness with attributable evidence and no hidden master-system mutation.", "inputs": [ "plan", "people", "resources", "supplier assurances" ], "outputs": [ "readiness assessment" ], "preconditions": [ "evidence freshness and access pass" ], "effects": [ "gaps and explicit unknowns are visible" ], "source_refs": [ "SRC-005", "SRC-006", "SRC-009", "SRC-012", "SRC-013" ] }, { "id": "conduct-and-evaluate-exercise", "name": "Conduct and evaluate exercise", "description": "Governed operation to conduct and evaluate exercise with attributable evidence and no hidden master-system mutation.", "inputs": [ "exercise design", "scenario", "participants", "criteria" ], "outputs": [ "exercise evidence and evaluation" ], "preconditions": [ "safety, authority and observation method pass" ], "effects": [ "bounded observations and gaps are recorded" ], "source_refs": [ "SRC-007", "SRC-009", "SRC-010", "SRC-012" ] }, { "id": "activate-continuity-plan", "name": "Activate continuity plan", "description": "Governed operation to activate continuity plan with attributable evidence and no hidden master-system mutation.", "inputs": [ "plan release", "disruption reference", "authority", "parameters" ], "outputs": [ "activation event and work release" ], "preconditions": [ "trigger, scope, delegation and confirmation pass" ], "effects": [ "continuity work starts without mutating the incident master" ], "source_refs": [ "SRC-001", "SRC-008", "SRC-011", "SRC-012", "SRC-013" ] }, { "id": "coordinate-continuity-and-recovery", "name": "Coordinate continuity and recovery", "description": "Governed operation to coordinate continuity and recovery with attributable evidence and no hidden master-system mutation.", "inputs": [ "activation", "tasks", "resources", "observations" ], "outputs": [ "execution and verification evidence" ], "preconditions": [ "priority, safety, integrity and communication pass" ], "effects": [ "service capacity and restoration state are attributable" ], "source_refs": [ "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013" ] }, { "id": "reconstitute-close-and-improve", "name": "Reconstitute, close and improve", "description": "Governed operation to reconstitute, close and improve with attributable evidence and no hidden master-system mutation.", "inputs": [ "recovery evidence", "return criteria", "residual risk", "lessons" ], "outputs": [ "closure event and improvement actions" ], "preconditions": [ "service verification, acceptance and evidence pass" ], "effects": [ "normal-operation claim and successor changes remain reviewable" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-010", "SRC-011", "SRC-012" ] }, { "id": "project-retain-and-audit", "name": "Project, retain and audit", "description": "Governed operation to project, retain and audit with attributable evidence and no hidden master-system mutation.", "inputs": [ "capability revision", "target profile", "purpose", "policy" ], "outputs": [ "projection or disposition event" ], "preconditions": [ "mapping loss, hold, idempotency and post-check pass" ], "effects": [ "context remains interoperable and accountable" ], "source_refs": [ "SRC-013", "SRC-014", "SRC-015" ] } ], "composition": [ { "target": "WM-ACT-008 Plan / Schedule", "relation": "CHILD", "purpose": "Candidate inheritance of generic plan identity, release and schedule scaffolding; no approved edge exists.", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ] }, { "target": "WM-ACT-042 Incident Response", "relation": "REFERENCE", "purpose": "Candidate incoming reference for invoking a released continuity or recovery plan without lifecycle cascade.", "required": false, "source_refs": [ "SRC-010", "SRC-011" ] }, { "target": "Organization, Product, Service, Activity, Person, Role, Facility, Asset, System, Dataset, Supplier and Contract models", "relation": "REFERENCE", "purpose": "Bind critical delivery, resources and dependencies while authoritative masters retain identity and lifecycle.", "required": true, "source_refs": [ "SRC-003", "SRC-005", "SRC-006", "SRC-009", "SRC-012", "SRC-013" ] }, { "target": "Incident, Incident Response, Risk, Crisis, Communication, Record and Audit models", "relation": "REFERENCE", "purpose": "Bind disruption, risk, command, communications and evidence without absorbing their records.", "required": false, "source_refs": [ "SRC-008", "SRC-010", "SRC-011", "SRC-012", "SRC-014" ] }, { "target": "ISO 22301 family, NIST contingency and recovery guidance, FEMA Continuity Guidance Circular and DORA", "relation": "ALIGN", "purpose": "Project version-pinned continuity, technology-recovery, public-sector and financial-sector views with declared loss and scope.", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-009", "SRC-010", "SRC-011", "SRC-012", "SRC-013" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Dimension owner and continuity mandate", "Organization, service, activity, incident, risk, resource, supplier, communication, record and policy registries", "Master mappings for critical products, services, activities, people, roles, facilities, systems, information, suppliers, contracts and incidents", "BIA, target-setting, strategy, plan release, activation, exercise, recovery, privacy, retention and agent policies" ], "namespace_guidance": "Mint capability, analysis-release, strategy-release, plan-release, exercise, activation, observation, verification and closure IDs; preserve every external master identifier.", "registry_links": [ "https://ver.cy/models/", "https://ver.cy/model-agent-protocol.md" ] }, "canon_and_patch": { "canonicalization_rules": [ "Canonicalize by authoritative master system, capability ID, scope profile and lineage head, never title, organization name or date.", "Keep analytic tolerance, approved objective, planned state, invoked state, observed execution, verified recovery and normal-operation declaration distinct." ], "patch_rules": [ "Extensions declare scope, jurisdiction, authority, impact, dependency, lifecycle, safety and interoperability effects.", "Released analyses, strategies, plans, exercises and evidence are immutable; corrections create successors.", "Never silently change criticality, target, authority, dependency, outcome, time or retention." ], "compatibility_rules": [ "Ignore additive fields only when identity, scope, authority, objectives, dependencies, release, lifecycle, evidence and provenance survive.", "Standards projections pin editions and declare information loss." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system continuity-capability or plan identifier qualified by source and profile.", "Governed globally resolvable capability IRI.", "Dimension UUID when neither preceding identifier exists." ], "timestamp_rule": "Use RFC 3339 timestamps with seconds and explicit offset or Z; separate effective, planned, trigger, decision, activation, task, observation, restoration, verification, closure, ingestion and knowledge times.", "serial_naming_rule": "Use {capability-id}--{release-activation-or-exercise-id}--{artifact-kind}--{assertion-or-event-id}.", "integrity_rule": "Store digest, media type, capability and release binding, source versions, actor, event and knowledge times, access marking and provenance." }, "policies": [ "The continuity capability is not an Organization, Product, Service, Activity, Incident, Incident Response, Risk, Person, Role, Facility, Asset, System, Dataset, Supplier, Contract, Communication or Audit master.", "Impact tolerance, objective, plan, invocation, execution, restoration, verification and return to normal remain separate.", "Capability ownership never transfers or cascades ownership of referenced masters.", "Agents cannot activate plans, disclose protected continuity data, accept residual risk or dispose records without delegated authority." ], "crud": { "read": [ "Resolve access purpose, capability profile, policies, latest released analyses, strategies and plans, master references, readiness, exercises, activations, evidence, exceptions and holds." ], "create": [ "Bind stable capability identity, boundary, owner, mandate, profile and authoritative master mappings before analyses or plans." ], "update": [ "Append successor releases and lifecycle events with authority, reason, event time, knowledge time and expected revision." ], "delete": [ "Apply continuity, security, privacy, legal-hold and records policy; retire the capability separately and never cascade to external masters." ] }, "roles": [ { "name": "Continuity capability owner", "responsibilities": [ "Own scope, mandate, resources and lifecycle." ] }, { "name": "Business impact and strategy steward", "responsibilities": [ "Own analysis method, priorities, objectives and strategy evidence." ] }, { "name": "Plan and procedure steward", "responsibilities": [ "Own plan releases, contacts, tasks and dependencies." ] }, { "name": "Service and activity owner", "responsibilities": [ "Own referenced service priorities, requirements and restoration acceptance." ] }, { "name": "Resource and supplier steward", "responsibilities": [ "Own readiness assertions and external master references." ] }, { "name": "Exercise and assurance lead", "responsibilities": [ "Own scenarios, observations, evaluation and corrective actions." ] }, { "name": "Activation and recovery authority", "responsibilities": [ "Authorize invocation, continuity mode, recovery and reconstitution decisions." ] }, { "name": "Records, privacy and security steward", "responsibilities": [ "Own protected views, holds, retention, disclosure and auditability." ] } ], "access": { "default_rule": "Deny continuity plans, vulnerabilities, alternate locations, contacts, supplier weaknesses, recovery assets, credentials and incident-linked evidence unless a purpose-bound policy permits the minimum necessary view.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Declared activation, regulator, auditor, emergency responder, supplier or court access must cite authority, be time-limited, scoped and logged." ], "audit_requirements": [ "Log actor, agent, role, purpose, capability, operation, authority, policy, RFC 3339 time, affected fields, source revision and outcome without unnecessary protected content." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Read Dimension continuity, risk, incident, safety, security, privacy, records and agent policies.", "Read this model and linked organization, service, activity, plan, incident, resource, supplier, communication and audit models before mutation." ] } }, "coverage": { "claim": "WM-ACT-043 covers continuity-capability aggregate identity, governance, business impact analysis, recovery objectives, strategy selection, versioned plan and procedure releases, role and resource readiness, supply-chain continuity, exercise design and evaluation, activation authority, continuity-mode operations, recovery actions, restoration verification, reconstitution and return to normal, lifecycle events, and safe-access policies. Excludes independent organization, service, activity, incident, risk, resource, supplier, contract, communication or audit master lifecycles. Known scope gaps: sector-specific profiles, jurisdiction-specific essential-function classifications, clause-level ISO conformance, approved registry edges to WM-ACT-008 and WM-ACT-042, and independent external review after one 120-second timeout each from Claude Sonnet and Grok 4.6.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Identity is explicit; candidate relations, paywalled ISO clauses and sector profiles remain held where applicable." }, { "dimension": "classification and definition", "status": "covered", "notes": "Classification and definition is explicit; candidate relations, paywalled ISO clauses and sector profiles remain held where applicable." }, { "dimension": "direct properties", "status": "covered", "notes": "Direct properties is explicit; candidate relations, paywalled ISO clauses and sector profiles remain held where applicable." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Recognition and observation is explicit; candidate relations, paywalled ISO clauses and sector profiles remain held where applicable." }, { "dimension": "capabilities and possible actions", "status": "covered", "notes": "Capabilities and possible actions is explicit; candidate relations, paywalled ISO clauses and sector profiles remain held where applicable." }, { "dimension": "composition", "status": "gap", "notes": "Composition is explicit; candidate relations, paywalled ISO clauses and sector profiles remain held where applicable." }, { "dimension": "lifecycle", "status": "covered", "notes": "Lifecycle is explicit; candidate relations, paywalled ISO clauses and sector profiles remain held where applicable." }, { "dimension": "relationships", "status": "covered", "notes": "Relationships is explicit; candidate relations, paywalled ISO clauses and sector profiles remain held where applicable." }, { "dimension": "temporal", "status": "covered", "notes": "Temporal is explicit; candidate relations, paywalled ISO clauses and sector profiles remain held where applicable." }, { "dimension": "spatial", "status": "covered", "notes": "Spatial is explicit; candidate relations, paywalled ISO clauses and sector profiles remain held where applicable." }, { "dimension": "provenance", "status": "covered", "notes": "Provenance is explicit; candidate relations, paywalled ISO clauses and sector profiles remain held where applicable." }, { "dimension": "ownership and stewardship", "status": "covered", "notes": "Ownership and stewardship is explicit; candidate relations, paywalled ISO clauses and sector profiles remain held where applicable." }, { "dimension": "validation and quality", "status": "covered", "notes": "Validation and quality is explicit; candidate relations, paywalled ISO clauses and sector profiles remain held where applicable." }, { "dimension": "access and privacy", "status": "covered", "notes": "Access and privacy is explicit; candidate relations, paywalled ISO clauses and sector profiles remain held where applicable." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Retention and deletion is explicit; candidate relations, paywalled ISO clauses and sector profiles remain held where applicable." }, { "dimension": "interoperability", "status": "gap", "notes": "Interoperability is explicit; candidate relations, paywalled ISO clauses and sector profiles remain held where applicable." } ], "known_omissions": [ "Claude and Grok each timed out on one bounded attempt; no independent external result was admitted.", "The Plan / Schedule parent and incoming Incident Response reference are candidate registry relations, not approved edges.", "ISO sources were limited to public catalogue abstracts and preview content; no clause-level or certification conformance is claimed.", "FEMA is a United States continuity profile and DORA is an EU financial-sector regulation; neither is universal.", "Health, safety, civil protection, financial, telecom, energy, government, humanitarian and other sector continuity duties require separate profiles." ], "conflicts": [ "Maximum tolerable disruption, recovery objectives, contractual commitments and observed recovery times are not interchangeable.", "Continuity, incident response, crisis management, disaster recovery, emergency management and organizational resilience overlap but retain different roots and authorities.", "Rapid activation can conflict with safety, evidence preservation, privacy, security, supplier constraints and authorization." ], "regional_assumptions": [ "Essential function, critical service and important business service classifications depend on the adopting authority and jurisdiction.", "Government devolution and succession constructs are optional profiles outside applicable public-sector mandates.", "DORA requirements apply only within its regulated scope and effective legal context." ], "adversarial_checks": [ "Reject a capability without stable identity, scope profile, owner, mandate, master bindings and lineage head.", "Reject criticality without method and authority, targets represented as outcomes, invocation represented as execution, backup existence represented as verified restorability or exercise success represented as real-event capability.", "Reject restoration represented as return to normal or incident closure represented as recovery completion.", "Reject corrections that overwrite analyses, targets, strategies, plans, exercises, activation events, observations, verification or closure history.", "Reject autonomous activation, protected disclosure, residual-risk acceptance or disposal outside delegated authority." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "aggregate", "status": "accepted", "rationale": "Entry kind 'aggregate' per the subject-model schema is sound. The continuity capability coordinates BIA, strategy, plans, readiness, exercises, activation events, recovery actions and reconstitution while Organization, Product, Service, Activity, Incident, Crisis, People, Facility, Asset, System, Data, Supplier, Contract, Communication and Audit masters retain independent identity and lifecycle. The model owns continuity-capability lineage, scope, mandate, analysis and plan releases, activation evidence, recovery verification and disposition without absorbing those masters. The frozen record-plane classifier remains standalone-mm." }, "decisions": [ { "concept": "Frozen entry kind vs. subject-model entry kind", "disposition": "accepted", "rationale": "Frozen registry value 'standalone-mm' classifies the record plane. Subject-model entry kind 'aggregate' identifies a continuity root that owns coordinated continuity state without absorbing external master lifecycles. A candidate Plan / Schedule parent is recorded separately and does not change either classification." }, { "concept": "Aggregate composition and non-absorption of external masters", "disposition": "accepted", "rationale": "The model explicitly excludes independent organization, service, activity, incident, response, risk, resource, supplier, contract, communication and audit master lifecycles. Five boundary notes distinguish continuity-capability state from adjacent masters with source support. Policies state that capability ownership never transfers or cascades ownership of referenced masters." }, { "concept": "Source authority and public-access limitation", "disposition": "accepted", "rationale": "Fifteen official sources are cited. ISO evidence is limited to public catalogue abstracts and public preview content, while NIST, FEMA, EU, RFC and W3C material is publicly accessible. No clause-level ISO or certification conformance is claimed. FEMA and DORA are jurisdiction- or sector-bounded profiles." }, { "concept": "Live URL and version verification", "disposition": "accepted", "rationale": "All fifteen official URLs were live-checked on 6 September 2026 during source-grounded research, and edition or date information is recorded. RFC 3339 and PROV-O use stable standards URLs. ISO catalogue pages, NIST publication pages, FEMA's dated PDF and the CELEX identifier preserve source identity, while later link drift remains a normal maintenance concern." }, { "concept": "Immutability of released artifacts and correction strategy", "disposition": "accepted", "rationale": "Patch rules explicitly state: 'Released analyses, strategies, plans, exercises and evidence are immutable; corrections create successors.' This prevents silent overwrites of continuity safety-critical artifacts. Serial naming rule enforces deterministic identity: {capability-id}--{release-activation-or-exercise-id}--{artifact-kind}--{assertion-or-event-id}. RFC 3339 timestamps separate effective, planned, trigger, decision, activation, task, observation, restoration, verification, closure, ingestion, and knowledge times. Adversarial checks reject autonomous mutations outside delegated authority. This strategy is sound." }, { "concept": "Governance owner, succession, and delegation", "disposition": "accepted", "rationale": "Finding 'governance-owner-succession-delegation-escalation-approval-and-contestability' addresses who owns the capability, who succeeds, who may delegate, when escalation occurs, who approves changes, and contestation procedures. Eight steward roles distribute authority without concentrating activation or residual-risk acceptance. Service-layer policies state: 'Agents cannot activate plans, disclose protected continuity data, accept residual risk or dispose records without delegated authority.' Governance structure documented; operationalization (who signs delegation, evidence required, escalation SLAs) deferred to policy binding and runbooks." }, { "concept": "Access default-deny and purpose-bound exceptions", "disposition": "accepted", "rationale": "Access section states: 'Default rule: Deny continuity plans, vulnerabilities, alternate locations, contacts, supplier weaknesses, recovery assets, credentials and incident-linked evidence unless a purpose-bound policy permits the minimum necessary view.' Five scopes identified (bundle, layer, finding, artifact). Exceptions require cited authority, time limit, scope, and logging. Audit requirements specify actor, agent, role, purpose, capability, operation, authority, policy, RFC 3339 time, affected fields, source revision, outcome without unnecessary protected content. Sound in principle; operationalization (who approves exceptions, sufficient audit trail, meaning of 'unnecessary protected content') deferred to operational policies." }, { "concept": "Candidate registry relations (WM-ACT-008 Plan parent, WM-ACT-042 Incident Response incoming)", "disposition": "deferred", "rationale": "Boundary notes label WM-ACT-008 Plan / Schedule as a candidate parent and WM-ACT-042 Incident Response as a candidate incoming reference. The model is internally coherent without either edge. Approval is deferred so later registry work can decide inheritance versus reference semantics and formalize the incident-response handoff; this limits composition-completeness claims but does not block reviewable-draft publication." }, { "concept": "Sector-specific and jurisdiction-specific profiles", "disposition": "deferred", "rationale": "Known omissions state: 'Health, safety, civil protection, financial, telecom, energy, government, humanitarian and other sector continuity duties require separate profiles.' Regional assumptions note: 'Essential function, critical service classifications depend on adopting authority and jurisdiction. DORA applies only within its regulated scope.' WM-ACT-043 provides neutral continuity-capability schema. Sector and jurisdiction models must be created as separate models with explicit relationships (e.g., health-continuity-profile extends WM-ACT-043). This is properly scoped, not an omission." }, { "concept": "Recovery verification vs. exercise success vs. backup restorability", "disposition": "accepted", "rationale": "Adversarial checks explicitly reject: 'Treating targets as outcomes, plans as activations, invocations as execution, backups as verified recovery or exercises as proof of real-event success.' Model lifecycle clearly separates planned state (exercise design), invoked state (activation-decision), observed execution (continuity-task-workaround), verified recovery (recovery-action-backup-integrity-restored-asset), and normal-operation declaration (reconstitution-return-to-normal). Each step has own findings, artifacts, and role. This distinction is sound and prevents fallacy of assuming readiness equals capability." } ], "publicationHolds": [ "Source-access hold: all 15 official URLs were live-checked on 6 September 2026, but ISO evidence is limited to public catalogue abstracts and preview content, and link availability can change.", "Absence-of-external-review hold: one Claude Sonnet attempt and one Grok 4.6 attempt for WM-ACT-043 each timed out after 120 seconds. No external result was admitted; the model remains reviewable-draft after a separate no-tools audit.", "Sector and jurisdiction profile gap: WM-ACT-043 provides a neutral continuity-capability structure. Operational use in health, safety, civil protection, finance, telecom, energy, government or humanitarian settings must bind the applicable rules; dedicated Vercy profiles remain deferred.", "Registry edge approval hold: the candidate WM-ACT-008 parent and WM-ACT-042 incoming reference are not approved. This blocks complete relationship claims, not publication of the standalone reviewable draft.", "Clause-level source conformance hold: ISO sources limited to public abstracts and preview content; no clause-level or certification-grade conformance claimed. Full-text review against ISO 22301:2019 Amendment 1:2024 and related standards deferred. Organizations requiring ISO certification must supplement WM-ACT-043 with direct conformance mapping.", "Governance operationalization hold: Delegation of authority, residual-risk acceptance, and protected-data disclosure require binding to operational policies, role-based access control (RBAC) systems, approval workflows, and audit-trail standards. Abstract policy rules must be instantiated in runbooks, escalation matrices, and compliance controls before production activation authority delegated.", "Access audit and logging operationalization hold: Access exceptions and logging requirements defined at policy level but require operational binding to audit systems, retention schedules, and redaction rules. Audit log schemas, storage, retention, and review procedures must be implemented before protected continuity data disclosed under purpose-bound exceptions.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Formal registry approval for WM-ACT-008 and WM-ACT-042 edges: Define whether continuity capability inherits plan identity from WM-ACT-008 or references it; define whether WM-ACT-042 owns incident facts or continuity capability owns activation authority; create approved relationship contract.", "Full-text ISO 22301:2019 (Amendment 1:2024), 22313, 22317, 22318, 22330, 22331, 22361, and 22398 clause-by-clause alignment: Map each clause to corresponding findings, artifacts, and functions; identify gaps; document any conflicts with NIST, FEMA, or DORA profiles.", "Sector-specific continuity-capability profiles: Create and publish health, safety, civil-protection, financial (DORA-aligned), telecom, energy, government, and humanitarian sector successor models with explicit boundary, conformance statement, and regulatory references.", "Jurisdiction-specific essential-function and critical-service classification schemes: Document how US federal, EU (DORA), UK, Canadian, Australian, and other authority classifications map to continuity capability priority and recovery objectives; document conflicts and resolution procedures.", "Operational policy binding and role-based access control: Instantiate eight steward roles in RBAC system; define delegation approval workflows; document residual-risk acceptance procedures; create audit-log schemas and redaction rules for protected continuity data." ] }, "statistics": { "sources": 15, "bundles": 6, "layers": 12, "findings": 24, "questions": 72, "artifacts": 24, "functions": 10 } }