# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-09-06T03:50:09Z", "synthesisSha256": "81ef7bacb326c523f5e6ac957e1ae5c7793b3198c22336a48d8ca072d3b9309e", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-SFT-006", "registryId": "vr.wm-sft-006", "name": "Vulnerability Record", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "aggregate", "family": "World Models", "category": "Information and virtual systems", "industry": [ "Cross-industry" ], "domain": [ "INF.SFT.VUL" ], "tags": [ "vulnerability", "record", "inf.sft.vul" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-sft-006-vulnerability-record/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-sft-006", "model": { "registry_id": "vr.wm-sft-006", "model_id": "WM-SFT-006", "name": "Vulnerability Record", "entry_kind": "aggregate", "purpose": "Represent an authority-qualified security vulnerability record, its affected product assertions, evidence, assessments and disclosure lifecycle independent of storage and interface format.", "scope_statement": "Owns vulnerability record identity and aliases, source assertion containers, descriptions, weakness mappings, affected product and version assertions, discovery and disclosure evidence, credits, references, severity and exploitation assessments, lifecycle changes, quality, access and provenance. Product, package, deployed asset, advisory, patch, remediation task, exploit, threat, risk decision and incident masters remain external.", "in_scope": [ "Authoritative identity, aliases, source containers, descriptions, problem types, affected products, platforms, versions and configurations", "Discovery, reporter and validation evidence, coordination timeline, references, credits, CVSS and time-varying exploitation or prioritization signals", "Remediation and exposure links, corrections, rejection, withdrawal, supersession, interoperability, quality, access, retention and safe operations" ], "out_of_scope": [ "Product, package, software component, deployed asset, advisory, patch, fix, remediation task or inventory master lifecycle", "Exploit, threat actor, campaign, indicator, cyber incident, control, organizational risk or risk-acceptance master lifecycle", "Exploit generation, unauthorized scanning, universal risk scoring, automated disclosure decisions or guaranteed cross-schema equivalence" ], "boundary_notes": [ { "neighbor": "Weakness / CWE class", "distinction": "A weakness class describes a recurring error pattern; a vulnerability record describes one source-qualified flaw or exposure instance that may map to one or more weakness classes.", "source_refs": [ "SRC-001", "SRC-004" ] }, { "neighbor": "Product / Package / Component", "distinction": "Product identity and version ordering remain external; this model owns source-qualified affectedness assertions about them.", "source_refs": [ "SRC-001", "SRC-003", "SRC-009" ] }, { "neighbor": "Deployed Asset Exposure", "distinction": "Product-level affectedness does not prove that a specific deployed asset contains, reaches or exposes the vulnerable configuration.", "source_refs": [ "SRC-003", "SRC-008" ] }, { "neighbor": "Security Advisory / Remediation", "distinction": "An advisory can group vulnerabilities, products and remedies; fixes, workarounds and remediation execution retain separate identity and lifecycle.", "source_refs": [ "SRC-008", "SRC-009" ] }, { "neighbor": "Exploit / Threat / Cyber Incident", "distinction": "A vulnerability may enable exploitation and be referenced by threat or incident records, but exploit and incident evidence have independent identity, authority and lifecycle.", "source_refs": [ "SRC-007", "SRC-010" ] } ] }, "sources": [ { "id": "SRC-001", "title": "CVE Record Format", "organization": "CVE Program", "url": "https://cveproject.github.io/cve-schema/", "version_or_date": "Current production format accessed 2026-09-06", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T03:45:00Z", "relevance": "Defines CVE record metadata, CNA and ADP containers, descriptions, affected products, problem types, impacts, references, credits, metrics, timeline and lifecycle states." }, { "id": "SRC-002", "title": "CVE JSON record format documentation", "organization": "CVE Program", "url": "https://cveproject.github.io/cve-schema/schema/docs/", "version_or_date": "Production schema documentation accessed 2026-09-06", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T03:45:00Z", "relevance": "Provides field-level documentation and schema constraints for machine-readable CVE records." }, { "id": "SRC-003", "title": "NVD Data Feeds and JSON 2.0 schemas", "organization": "National Institute of Standards and Technology", "url": "https://nvd.nist.gov/vuln/data-feeds", "version_or_date": "NVD API and feeds accessed 2026-09-06", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T03:45:00Z", "relevance": "Defines NVD vulnerability enrichment, CPE applicability, metrics, weaknesses, references, change retrieval and feed metadata." }, { "id": "SRC-004", "title": "CWE Downloads and published schemas", "organization": "MITRE", "url": "https://cwe.mitre.org/data/downloads.html", "version_or_date": "Current published CWE content accessed 2026-09-06", "source_type": "classifier", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T03:45:00Z", "relevance": "Provides versioned weakness identifiers, relationships, views, categories and machine-readable downloads." }, { "id": "SRC-005", "title": "Common Vulnerability Scoring System version 4.0 Specification", "organization": "Forum of Incident Response and Security Teams", "url": "https://www.first.org/cvss/v4.0/specification-document", "version_or_date": "CVSS 4.0 document version 1.2", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T03:45:00Z", "relevance": "Separates Base, Threat, Environmental and Supplemental metrics and defines vectors and severity scoring semantics." }, { "id": "SRC-006", "title": "Exploit Prediction Scoring System", "organization": "Forum of Incident Response and Security Teams", "url": "https://www.first.org/epss/", "version_or_date": "Current model resources accessed 2026-09-06", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T03:45:00Z", "relevance": "Defines a time-varying model that estimates probability of exploitation in the wild within the next 30 days, not overall risk." }, { "id": "SRC-007", "title": "Known Exploited Vulnerabilities Catalog", "organization": "Cybersecurity and Infrastructure Security Agency", "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog", "version_or_date": "Living catalog accessed 2026-09-06", "source_type": "registry", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T03:45:00Z", "relevance": "Provides source-qualified known-exploitation inclusion, dates, required action and due-date context for vulnerability prioritization." }, { "id": "SRC-008", "title": "Common Security Advisory Framework Version 2.0 Errata 01", "organization": "OASIS", "url": "https://docs.oasis-open.org/csaf/csaf/v2.0/errata01/os/csaf-v2.0-errata01-os.html", "version_or_date": "OASIS Standard with Approved Errata, 26 January 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T03:45:00Z", "relevance": "Defines structured advisories, product trees, vulnerabilities, product status, threats, scores and remediation, including the VEX profile." }, { "id": "SRC-009", "title": "Open Source Vulnerability format", "organization": "Open Source Security Foundation", "url": "https://ossf.github.io/osv-schema/", "version_or_date": "Current schema documentation accessed 2026-09-06", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T03:45:00Z", "relevance": "Defines vulnerability IDs, aliases, upstream and related records, affected packages, version ranges, severity, references, credits, publication and withdrawal." }, { "id": "SRC-010", "title": "STIX Version 2.1", "organization": "OASIS", "url": "https://docs.oasis-open.org/cti/stix/v2.1/os/stix-v2.1-os.html", "version_or_date": "OASIS Standard, 10 June 2021", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T03:45:00Z", "relevance": "Defines a vulnerability threat-intelligence object and typed relationships to software, exploits, incidents and other intelligence objects." }, { "id": "SRC-011", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T03:45:00Z", "relevance": "Provides provenance for records, enrichments, assessments, translations, revisions and responsible agents." }, { "id": "SRC-012", "title": "Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3339", "version_or_date": "RFC 3339, July 2002", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T03:45:00Z", "relevance": "Defines offset-bearing timestamps for reservation, discovery, disclosure, publication, modification, observation and knowledge events." } ], "structure": { "bundles": [ { "id": "vulnerability-identity-record-authority-and-class", "name": "Vulnerability identity, record authority and class", "description": "Identifies one vulnerability record and preserves source authority, aliases and assertion containers.", "rationale": "A CVE identifier names a record in one program, not every weakness, misconfiguration, advisory or database entry, and enrichments need independent attribution.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009", "SRC-011" ], "layers": [ { "id": "record-identity-aliases-and-boundary", "name": "Record identity, aliases and boundary", "description": "Stable identifiers and relations among same, upstream and related vulnerability records.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ], "findings": [ { "id": "authoritative-identifier-namespace-alias-resolver-and-collision", "name": "Authoritative identifier, namespace, alias, resolver and collision", "description": "Master identifier, assigning namespace, aliases, resolver, reservation status, predecessor, duplicate and collision evidence.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ], "questions": [ { "id": "authoritative-identifier-namespace-alias-resolver-and-collision-q01", "text": "What identifiers, source containers, classes, scope and values define authoritative identifier, namespace, alias, resolver and collision?", "kind": "identity", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "authoritative-identifier-namespace-alias-resolver-and-collision-q02", "text": "Which authority, evidence, method, event time and knowledge time support authoritative identifier, namespace, alias, resolver and collision?", "kind": "evidence", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "authoritative-identifier-namespace-alias-resolver-and-collision-q03", "text": "How may authoritative identifier, namespace, alias, resolver and collision be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "validation", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "authoritative-identifier-namespace-alias-resolver-and-collision-data", "name": "Authoritative identifier, namespace, alias, resolver and collision data", "description": "Structured source-qualified vulnerability data for authoritative identifier, namespace, alias, resolver and collision.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ] } ], "artifacts": [ { "id": "authoritative-identifier-namespace-alias-resolver-and-collision-record", "name": "Authoritative identifier, namespace, alias, resolver and collision record", "description": "Versioned evidence-bearing vulnerability record for authoritative identifier, namespace, alias, resolver and collision with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus authoritative-identifier-namespace-alias-resolver-and-collision assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "same-vulnerability-upstream-related-split-and-merge-boundary", "name": "Same vulnerability, upstream, related, split and merge boundary", "description": "Source-qualified relation kind, direction, matching criteria, affected-component scope, split or merge rationale and uncertainty.", "source_refs": [ "SRC-001", "SRC-009" ], "questions": [ { "id": "same-vulnerability-upstream-related-split-and-merge-boundary-q01", "text": "What identifiers, source containers, classes, scope and values define same vulnerability, upstream, related, split and merge boundary?", "kind": "relationship", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "same-vulnerability-upstream-related-split-and-merge-boundary-q02", "text": "Which authority, evidence, method, event time and knowledge time support same vulnerability, upstream, related, split and merge boundary?", "kind": "authority", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "same-vulnerability-upstream-related-split-and-merge-boundary-q03", "text": "How may same vulnerability, upstream, related, split and merge boundary be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "exception", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "same-vulnerability-upstream-related-split-and-merge-boundary-data", "name": "Same vulnerability, upstream, related, split and merge boundary data", "description": "Structured source-qualified vulnerability data for same vulnerability, upstream, related, split and merge boundary.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-009" ] } ], "artifacts": [ { "id": "same-vulnerability-upstream-related-split-and-merge-boundary-record", "name": "Same vulnerability, upstream, related, split and merge boundary record", "description": "Versioned evidence-bearing vulnerability record for same vulnerability, upstream, related, split and merge boundary with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus same-vulnerability-upstream-related-split-and-merge-boundary assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-001", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "record-container-authorship-and-version", "name": "Record container, authorship and version", "description": "Separates authoritative source containers and immutable versions.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-011" ], "findings": [ { "id": "cna-adp-nvd-vendor-ecosystem-and-database-assertion-container", "name": "CNA, ADP, NVD, vendor, ecosystem and database assertion container", "description": "Container kind, source organization, role, authority, schema version, covered claims, original locator and signature or digest.", "source_refs": [ "SRC-001", "SRC-003", "SRC-009", "SRC-011" ], "questions": [ { "id": "cna-adp-nvd-vendor-ecosystem-and-database-assertion-container-q01", "text": "What identifiers, source containers, classes, scope and values define cna, adp, nvd, vendor, ecosystem and database assertion container?", "kind": "ownership", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "cna-adp-nvd-vendor-ecosystem-and-database-assertion-container-q02", "text": "Which authority, evidence, method, event time and knowledge time support cna, adp, nvd, vendor, ecosystem and database assertion container?", "kind": "provenance", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "cna-adp-nvd-vendor-ecosystem-and-database-assertion-container-q03", "text": "How may cna, adp, nvd, vendor, ecosystem and database assertion container be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "access", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "cna-adp-nvd-vendor-ecosystem-and-database-assertion-container-data", "name": "CNA, ADP, NVD, vendor, ecosystem and database assertion container data", "description": "Structured source-qualified vulnerability data for cna, adp, nvd, vendor, ecosystem and database assertion container.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-009", "SRC-011" ] } ], "artifacts": [ { "id": "cna-adp-nvd-vendor-ecosystem-and-database-assertion-container-record", "name": "CNA, ADP, NVD, vendor, ecosystem and database assertion container record", "description": "Versioned evidence-bearing vulnerability record for cna, adp, nvd, vendor, ecosystem and database assertion container with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus cna-adp-nvd-vendor-ecosystem-and-database-assertion-container assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-009", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "record-version-state-published-modified-rejected-and-withdrawn", "name": "Record version, state, published, modified, rejected and withdrawn", "description": "Version identifier, lifecycle state, state reason, predecessor, publication and modification times, withdrawal or rejection and retained history.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-012" ], "questions": [ { "id": "record-version-state-published-modified-rejected-and-withdrawn-q01", "text": "What identifiers, source containers, classes, scope and values define record version, state, published, modified, rejected and withdrawn?", "kind": "lifecycle", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "record-version-state-published-modified-rejected-and-withdrawn-q02", "text": "Which authority, evidence, method, event time and knowledge time support record version, state, published, modified, rejected and withdrawn?", "kind": "temporal", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "record-version-state-published-modified-rejected-and-withdrawn-q03", "text": "How may record version, state, published, modified, rejected and withdrawn be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "retention", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "record-version-state-published-modified-rejected-and-withdrawn-data", "name": "Record version, state, published, modified, rejected and withdrawn data", "description": "Structured source-qualified vulnerability data for record version, state, published, modified, rejected and withdrawn.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-012" ] } ], "artifacts": [ { "id": "record-version-state-published-modified-rejected-and-withdrawn-record", "name": "Record version, state, published, modified, rejected and withdrawn record", "description": "Versioned evidence-bearing vulnerability record for record version, state, published, modified, rejected and withdrawn with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus record-version-state-published-modified-rejected-and-withdrawn assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-012" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "description-weakness-and-affected-product", "name": "Description, weakness and affected product", "description": "Describes the flaw and source-qualified affected product and version assertions.", "rationale": "CWE classifies weakness types, while affectedness applies a vulnerability to named product configurations and still does not prove a deployed asset is exposed.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-008", "SRC-009" ], "layers": [ { "id": "descriptions-problem-types-and-root-cause", "name": "Descriptions, problem types and root cause", "description": "Captures multilingual statements and classifier mappings without turning inference into fact.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004", "SRC-009" ], "findings": [ { "id": "summary-description-language-supporting-media-and-redaction", "name": "Summary, description, language, supporting media and redaction", "description": "Plain-language and technical descriptions, language, media type, value, redaction markers, source, audience and version.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ], "questions": [ { "id": "summary-description-language-supporting-media-and-redaction-q01", "text": "What identifiers, source containers, classes, scope and values define summary, description, language, supporting media and redaction?", "kind": "definition", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "summary-description-language-supporting-media-and-redaction-q02", "text": "Which authority, evidence, method, event time and knowledge time support summary, description, language, supporting media and redaction?", "kind": "quality", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "summary-description-language-supporting-media-and-redaction-q03", "text": "How may summary, description, language, supporting media and redaction be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "security", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "summary-description-language-supporting-media-and-redaction-data", "name": "Summary, description, language, supporting media and redaction data", "description": "Structured source-qualified vulnerability data for summary, description, language, supporting media and redaction.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ] } ], "artifacts": [ { "id": "summary-description-language-supporting-media-and-redaction-record", "name": "Summary, description, language, supporting media and redaction record", "description": "Versioned evidence-bearing vulnerability record for summary, description, language, supporting media and redaction with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus summary-description-language-supporting-media-and-redaction assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "cwe-problem-type-root-cause-mechanism-and-prerequisite", "name": "CWE problem type, root cause, mechanism and prerequisite", "description": "Versioned CWE or other classifier reference, mapping method, weakness mechanism, prerequisites, confidence and disputed mappings.", "source_refs": [ "SRC-001", "SRC-004" ], "questions": [ { "id": "cwe-problem-type-root-cause-mechanism-and-prerequisite-q01", "text": "What identifiers, source containers, classes, scope and values define cwe problem type, root cause, mechanism and prerequisite?", "kind": "classification", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "cwe-problem-type-root-cause-mechanism-and-prerequisite-q02", "text": "Which authority, evidence, method, event time and knowledge time support cwe problem type, root cause, mechanism and prerequisite?", "kind": "process", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "cwe-problem-type-root-cause-mechanism-and-prerequisite-q03", "text": "How may cwe problem type, root cause, mechanism and prerequisite be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "interoperability", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "cwe-problem-type-root-cause-mechanism-and-prerequisite-data", "name": "CWE problem type, root cause, mechanism and prerequisite data", "description": "Structured source-qualified vulnerability data for cwe problem type, root cause, mechanism and prerequisite.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] } ], "artifacts": [ { "id": "cwe-problem-type-root-cause-mechanism-and-prerequisite-record", "name": "CWE problem type, root cause, mechanism and prerequisite record", "description": "Versioned evidence-bearing vulnerability record for cwe problem type, root cause, mechanism and prerequisite with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus cwe-problem-type-root-cause-mechanism-and-prerequisite assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-001", "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "products-platforms-versions-and-status", "name": "Products, platforms, versions and status", "description": "Expresses affectedness independently of inventory exposure.", "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009" ], "findings": [ { "id": "vendor-product-package-module-platform-cpe-purl-and-identity-reference", "name": "Vendor, product, package, module, platform, CPE, purl and identity reference", "description": "External product or package identity, vendor, module, platform, CPE or purl, ecosystem and source namespace.", "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009" ], "questions": [ { "id": "vendor-product-package-module-platform-cpe-purl-and-identity-reference-q01", "text": "What identifiers, source containers, classes, scope and values define vendor, product, package, module, platform, cpe, purl and identity reference?", "kind": "composition", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "vendor-product-package-module-platform-cpe-purl-and-identity-reference-q02", "text": "Which authority, evidence, method, event time and knowledge time support vendor, product, package, module, platform, cpe, purl and identity reference?", "kind": "measurement", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "vendor-product-package-module-platform-cpe-purl-and-identity-reference-q03", "text": "How may vendor, product, package, module, platform, cpe, purl and identity reference be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "validation", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "vendor-product-package-module-platform-cpe-purl-and-identity-reference-data", "name": "Vendor, product, package, module, platform, CPE, purl and identity reference data", "description": "Structured source-qualified vulnerability data for vendor, product, package, module, platform, cpe, purl and identity reference.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "vendor-product-package-module-platform-cpe-purl-and-identity-reference-record", "name": "Vendor, product, package, module, platform, CPE, purl and identity reference record", "description": "Versioned evidence-bearing vulnerability record for vendor, product, package, module, platform, cpe, purl and identity reference with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus vendor-product-package-module-platform-cpe-purl-and-identity-reference assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "affected-unaffected-unknown-version-range-configuration-and-justification", "name": "Affected, unaffected, unknown version range, configuration and justification", "description": "Product-status assertion, range scheme, introduced, fixed, last affected or limit events, configuration constraints, justification and source confidence.", "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009" ], "questions": [ { "id": "affected-unaffected-unknown-version-range-configuration-and-justification-q01", "text": "What identifiers, source containers, classes, scope and values define affected, unaffected, unknown version range, configuration and justification?", "kind": "state", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "affected-unaffected-unknown-version-range-configuration-and-justification-q02", "text": "Which authority, evidence, method, event time and knowledge time support affected, unaffected, unknown version range, configuration and justification?", "kind": "decision", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "affected-unaffected-unknown-version-range-configuration-and-justification-q03", "text": "How may affected, unaffected, unknown version range, configuration and justification be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "temporal", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "affected-unaffected-unknown-version-range-configuration-and-justification-data", "name": "Affected, unaffected, unknown version range, configuration and justification data", "description": "Structured source-qualified vulnerability data for affected, unaffected, unknown version range, configuration and justification.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "affected-unaffected-unknown-version-range-configuration-and-justification-record", "name": "Affected, unaffected, unknown version range, configuration and justification record", "description": "Versioned evidence-bearing vulnerability record for affected, unaffected, unknown version range, configuration and justification with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus affected-unaffected-unknown-version-range-configuration-and-justification assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "discovery-disclosure-evidence-and-coordination", "name": "Discovery, disclosure, evidence and coordination", "description": "Records accountable discovery and disclosure evidence without publishing restricted exploit detail.", "rationale": "Discovery, reporting, reservation, vendor notification and public disclosure can occur at different times under coordinated-disclosure policy.", "source_refs": [ "SRC-001", "SRC-002", "SRC-008", "SRC-009", "SRC-011", "SRC-012" ], "layers": [ { "id": "discovery-reporting-evidence-and-confidence", "name": "Discovery, reporting, evidence and confidence", "description": "Separates reports and observations from validated vulnerability claims.", "source_refs": [ "SRC-001", "SRC-009", "SRC-011", "SRC-012" ], "findings": [ { "id": "discoverer-reporter-contact-role-credit-and-attribution", "name": "Discoverer, reporter, contact role, credit and attribution", "description": "External actor reference, contribution role, requested credit, contact protection, organization, consent and attribution status.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ], "questions": [ { "id": "discoverer-reporter-contact-role-credit-and-attribution-q01", "text": "What identifiers, source containers, classes, scope and values define discoverer, reporter, contact role, credit and attribution?", "kind": "identity", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "discoverer-reporter-contact-role-credit-and-attribution-q02", "text": "Which authority, evidence, method, event time and knowledge time support discoverer, reporter, contact role, credit and attribution?", "kind": "evidence", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "discoverer-reporter-contact-role-credit-and-attribution-q03", "text": "How may discoverer, reporter, contact role, credit and attribution be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "validation", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "discoverer-reporter-contact-role-credit-and-attribution-data", "name": "Discoverer, reporter, contact role, credit and attribution data", "description": "Structured source-qualified vulnerability data for discoverer, reporter, contact role, credit and attribution.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ] } ], "artifacts": [ { "id": "discoverer-reporter-contact-role-credit-and-attribution-record", "name": "Discoverer, reporter, contact role, credit and attribution record", "description": "Versioned evidence-bearing vulnerability record for discoverer, reporter, contact role, credit and attribution with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus discoverer-reporter-contact-role-credit-and-attribution assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "discovery-method-report-evidence-reproducer-validation-and-confidence", "name": "Discovery method, report, evidence, reproducer, validation and confidence", "description": "Method, report reference, restricted evidence locator, affected environment, validation outcome, validator, confidence and disclosure class.", "source_refs": [ "SRC-001", "SRC-009", "SRC-011" ], "questions": [ { "id": "discovery-method-report-evidence-reproducer-validation-and-confidence-q01", "text": "What identifiers, source containers, classes, scope and values define discovery method, report, evidence, reproducer, validation and confidence?", "kind": "relationship", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "discovery-method-report-evidence-reproducer-validation-and-confidence-q02", "text": "Which authority, evidence, method, event time and knowledge time support discovery method, report, evidence, reproducer, validation and confidence?", "kind": "authority", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "discovery-method-report-evidence-reproducer-validation-and-confidence-q03", "text": "How may discovery method, report, evidence, reproducer, validation and confidence be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "exception", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "discovery-method-report-evidence-reproducer-validation-and-confidence-data", "name": "Discovery method, report, evidence, reproducer, validation and confidence data", "description": "Structured source-qualified vulnerability data for discovery method, report, evidence, reproducer, validation and confidence.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-009", "SRC-011" ] } ], "artifacts": [ { "id": "discovery-method-report-evidence-reproducer-validation-and-confidence-record", "name": "Discovery method, report, evidence, reproducer, validation and confidence record", "description": "Versioned evidence-bearing vulnerability record for discovery method, report, evidence, reproducer, validation and confidence with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus discovery-method-report-evidence-reproducer-validation-and-confidence assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-001", "SRC-009", "SRC-011" ] } ], "inline_only_rationale": null } ] }, { "id": "coordination-timeline-references-and-disclosure", "name": "Coordination, timeline, references and disclosure", "description": "Maintains event and publication history and typed evidence links.", "source_refs": [ "SRC-001", "SRC-002", "SRC-008", "SRC-009", "SRC-012" ], "findings": [ { "id": "reservation-vendor-notification-embargo-publication-update-and-knowledge-time", "name": "Reservation, vendor notification, embargo, publication, update and knowledge time", "description": "Event kind, actor, event time, observation and knowledge time, embargo authority, planned disclosure, actual publication and sequence.", "source_refs": [ "SRC-001", "SRC-002", "SRC-012" ], "questions": [ { "id": "reservation-vendor-notification-embargo-publication-update-and-knowledge-time-q01", "text": "What identifiers, source containers, classes, scope and values define reservation, vendor notification, embargo, publication, update and knowledge time?", "kind": "ownership", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "reservation-vendor-notification-embargo-publication-update-and-knowledge-time-q02", "text": "Which authority, evidence, method, event time and knowledge time support reservation, vendor notification, embargo, publication, update and knowledge time?", "kind": "provenance", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "reservation-vendor-notification-embargo-publication-update-and-knowledge-time-q03", "text": "How may reservation, vendor notification, embargo, publication, update and knowledge time be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "access", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "reservation-vendor-notification-embargo-publication-update-and-knowledge-time-data", "name": "Reservation, vendor notification, embargo, publication, update and knowledge time data", "description": "Structured source-qualified vulnerability data for reservation, vendor notification, embargo, publication, update and knowledge time.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-012" ] } ], "artifacts": [ { "id": "reservation-vendor-notification-embargo-publication-update-and-knowledge-time-record", "name": "Reservation, vendor notification, embargo, publication, update and knowledge time record", "description": "Versioned evidence-bearing vulnerability record for reservation, vendor notification, embargo, publication, update and knowledge time with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus reservation-vendor-notification-embargo-publication-update-and-knowledge-time assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-012" ] } ], "inline_only_rationale": null }, { "id": "advisory-report-fix-evidence-reference-tag-and-integrity", "name": "Advisory, report, fix, evidence reference, tag and integrity", "description": "Typed URL or document reference, source, role, tags, access class, retrieved version, digest, publication state and trust caveat.", "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009" ], "questions": [ { "id": "advisory-report-fix-evidence-reference-tag-and-integrity-q01", "text": "What identifiers, source containers, classes, scope and values define advisory, report, fix, evidence reference, tag and integrity?", "kind": "lifecycle", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "advisory-report-fix-evidence-reference-tag-and-integrity-q02", "text": "Which authority, evidence, method, event time and knowledge time support advisory, report, fix, evidence reference, tag and integrity?", "kind": "temporal", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "advisory-report-fix-evidence-reference-tag-and-integrity-q03", "text": "How may advisory, report, fix, evidence reference, tag and integrity be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "retention", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "advisory-report-fix-evidence-reference-tag-and-integrity-data", "name": "Advisory, report, fix, evidence reference, tag and integrity data", "description": "Structured source-qualified vulnerability data for advisory, report, fix, evidence reference, tag and integrity.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "advisory-report-fix-evidence-reference-tag-and-integrity-record", "name": "Advisory, report, fix, evidence reference, tag and integrity record", "description": "Versioned evidence-bearing vulnerability record for advisory, report, fix, evidence reference, tag and integrity with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus advisory-report-fix-evidence-reference-tag-and-integrity assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "severity-exploitability-and-prioritization-signals", "name": "Severity, exploitability and prioritization signals", "description": "Stores versioned assessments while preventing severity, exploitation probability, known exploitation and organizational risk from being conflated.", "rationale": "CVSS, EPSS, KEV, SSVC and local risk answer different questions, use different evidence and change on different schedules.", "source_refs": [ "SRC-003", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-011", "SRC-012" ], "layers": [ { "id": "cvss-severity-and-impact-assertions", "name": "CVSS severity and impact assertions", "description": "Preserves vector, metric group, scope and assessor.", "source_refs": [ "SRC-003", "SRC-005", "SRC-008" ], "findings": [ { "id": "cvss-version-vector-base-threat-environmental-and-supplemental-metrics", "name": "CVSS version, vector, Base, Threat, Environmental and Supplemental metrics", "description": "CVSS version, full vector, metric groups, score, qualitative rating, calculator version and calculation evidence.", "source_refs": [ "SRC-003", "SRC-005" ], "questions": [ { "id": "cvss-version-vector-base-threat-environmental-and-supplemental-metrics-q01", "text": "What identifiers, source containers, classes, scope and values define cvss version, vector, base, threat, environmental and supplemental metrics?", "kind": "definition", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "cvss-version-vector-base-threat-environmental-and-supplemental-metrics-q02", "text": "Which authority, evidence, method, event time and knowledge time support cvss version, vector, base, threat, environmental and supplemental metrics?", "kind": "quality", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "cvss-version-vector-base-threat-environmental-and-supplemental-metrics-q03", "text": "How may cvss version, vector, base, threat, environmental and supplemental metrics be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "security", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "cvss-version-vector-base-threat-environmental-and-supplemental-metrics-data", "name": "CVSS version, vector, Base, Threat, Environmental and Supplemental metrics data", "description": "Structured source-qualified vulnerability data for cvss version, vector, base, threat, environmental and supplemental metrics.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "cvss-version-vector-base-threat-environmental-and-supplemental-metrics-record", "name": "CVSS version, vector, Base, Threat, Environmental and Supplemental metrics record", "description": "Versioned evidence-bearing vulnerability record for cvss version, vector, base, threat, environmental and supplemental metrics with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus cvss-version-vector-base-threat-environmental-and-supplemental-metrics assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-003", "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "severity-assessor-scope-product-context-time-and-disagreement", "name": "Severity assessor, scope, product context, time and disagreement", "description": "Assessor identity and role, affected product scope, environment, assertion time, source container, confidence and relation to competing scores.", "source_refs": [ "SRC-003", "SRC-005", "SRC-008", "SRC-011" ], "questions": [ { "id": "severity-assessor-scope-product-context-time-and-disagreement-q01", "text": "What identifiers, source containers, classes, scope and values define severity assessor, scope, product context, time and disagreement?", "kind": "classification", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "severity-assessor-scope-product-context-time-and-disagreement-q02", "text": "Which authority, evidence, method, event time and knowledge time support severity assessor, scope, product context, time and disagreement?", "kind": "process", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "severity-assessor-scope-product-context-time-and-disagreement-q03", "text": "How may severity assessor, scope, product context, time and disagreement be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "interoperability", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "severity-assessor-scope-product-context-time-and-disagreement-data", "name": "Severity assessor, scope, product context, time and disagreement data", "description": "Structured source-qualified vulnerability data for severity assessor, scope, product context, time and disagreement.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-005", "SRC-008", "SRC-011" ] } ], "artifacts": [ { "id": "severity-assessor-scope-product-context-time-and-disagreement-record", "name": "Severity assessor, scope, product context, time and disagreement record", "description": "Versioned evidence-bearing vulnerability record for severity assessor, scope, product context, time and disagreement with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus severity-assessor-scope-product-context-time-and-disagreement assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-003", "SRC-005", "SRC-008", "SRC-011" ] } ], "inline_only_rationale": null } ] }, { "id": "exploitation-priority-and-risk-context", "name": "Exploitation, priority and risk context", "description": "Links time-varying signals and local decisions without inventing one universal priority.", "source_refs": [ "SRC-003", "SRC-006", "SRC-007", "SRC-011", "SRC-012" ], "findings": [ { "id": "epss-probability-percentile-model-date-window-and-source", "name": "EPSS probability, percentile, model date, window and source", "description": "Estimated probability, percentile, scoring date, prediction window, model version, source and later-observed outcome reference.", "source_refs": [ "SRC-006", "SRC-012" ], "questions": [ { "id": "epss-probability-percentile-model-date-window-and-source-q01", "text": "What identifiers, source containers, classes, scope and values define epss probability, percentile, model date, window and source?", "kind": "composition", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "epss-probability-percentile-model-date-window-and-source-q02", "text": "Which authority, evidence, method, event time and knowledge time support epss probability, percentile, model date, window and source?", "kind": "measurement", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "epss-probability-percentile-model-date-window-and-source-q03", "text": "How may epss probability, percentile, model date, window and source be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "validation", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "epss-probability-percentile-model-date-window-and-source-data", "name": "EPSS probability, percentile, model date, window and source data", "description": "Structured source-qualified vulnerability data for epss probability, percentile, model date, window and source.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-012" ] } ], "artifacts": [ { "id": "epss-probability-percentile-model-date-window-and-source-record", "name": "EPSS probability, percentile, model date, window and source record", "description": "Versioned evidence-bearing vulnerability record for epss probability, percentile, model date, window and source with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus epss-probability-percentile-model-date-window-and-source assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-006", "SRC-012" ] } ], "inline_only_rationale": null }, { "id": "kev-known-exploitation-ssvc-decision-priority-and-local-risk-reference", "name": "KEV known exploitation, SSVC decision, priority and local risk reference", "description": "Catalog or decision source, inclusion evidence, known-ransomware status, decision points, required action, due date and external local-risk decision.", "source_refs": [ "SRC-003", "SRC-007", "SRC-011" ], "questions": [ { "id": "kev-known-exploitation-ssvc-decision-priority-and-local-risk-reference-q01", "text": "What identifiers, source containers, classes, scope and values define kev known exploitation, ssvc decision, priority and local risk reference?", "kind": "state", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "kev-known-exploitation-ssvc-decision-priority-and-local-risk-reference-q02", "text": "Which authority, evidence, method, event time and knowledge time support kev known exploitation, ssvc decision, priority and local risk reference?", "kind": "decision", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "kev-known-exploitation-ssvc-decision-priority-and-local-risk-reference-q03", "text": "How may kev known exploitation, ssvc decision, priority and local risk reference be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "temporal", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "kev-known-exploitation-ssvc-decision-priority-and-local-risk-reference-data", "name": "KEV known exploitation, SSVC decision, priority and local risk reference data", "description": "Structured source-qualified vulnerability data for kev known exploitation, ssvc decision, priority and local risk reference.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-007", "SRC-011" ] } ], "artifacts": [ { "id": "kev-known-exploitation-ssvc-decision-priority-and-local-risk-reference-record", "name": "KEV known exploitation, SSVC decision, priority and local risk reference record", "description": "Versioned evidence-bearing vulnerability record for kev known exploitation, ssvc decision, priority and local risk reference with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus kev-known-exploitation-ssvc-decision-priority-and-local-risk-reference assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-003", "SRC-007", "SRC-011" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "remediation-exposure-and-change-lifecycle", "name": "Remediation, exposure and change lifecycle", "description": "Links remediation and concrete exposure processes while preserving vulnerability record history.", "rationale": "A fixed product version, vendor workaround, deployed patch, asset exposure and accepted operational risk have different owners and lifecycles.", "source_refs": [ "SRC-001", "SRC-003", "SRC-007", "SRC-008", "SRC-009", "SRC-011" ], "layers": [ { "id": "remediation-advisory-fix-and-exposure-links", "name": "Remediation, advisory, fix and exposure links", "description": "Connects external products, advisories, fixes and deployments.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-009" ], "findings": [ { "id": "fix-version-patch-commit-workaround-mitigation-and-remediation-reference", "name": "Fix version, patch, commit, workaround, mitigation and remediation reference", "description": "External remediation identifier, kind, vendor, product scope, fixed version or commit, availability, restart, caveat and supersession.", "source_refs": [ "SRC-001", "SRC-008", "SRC-009" ], "questions": [ { "id": "fix-version-patch-commit-workaround-mitigation-and-remediation-reference-q01", "text": "What identifiers, source containers, classes, scope and values define fix version, patch, commit, workaround, mitigation and remediation reference?", "kind": "identity", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "fix-version-patch-commit-workaround-mitigation-and-remediation-reference-q02", "text": "Which authority, evidence, method, event time and knowledge time support fix version, patch, commit, workaround, mitigation and remediation reference?", "kind": "evidence", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "fix-version-patch-commit-workaround-mitigation-and-remediation-reference-q03", "text": "How may fix version, patch, commit, workaround, mitigation and remediation reference be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "validation", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "fix-version-patch-commit-workaround-mitigation-and-remediation-reference-data", "name": "Fix version, patch, commit, workaround, mitigation and remediation reference data", "description": "Structured source-qualified vulnerability data for fix version, patch, commit, workaround, mitigation and remediation reference.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "fix-version-patch-commit-workaround-mitigation-and-remediation-reference-record", "name": "Fix version, patch, commit, workaround, mitigation and remediation reference record", "description": "Versioned evidence-bearing vulnerability record for fix version, patch, commit, workaround, mitigation and remediation reference with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus fix-version-patch-commit-workaround-mitigation-and-remediation-reference assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-001", "SRC-008", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "deployed-asset-exposure-detection-vex-status-and-verification-reference", "name": "Deployed asset exposure, detection, VEX status and verification reference", "description": "External asset and exposure identifiers, matched product evidence, VEX product status, detection time, verification method and current remediation-state reference.", "source_refs": [ "SRC-003", "SRC-007", "SRC-008" ], "questions": [ { "id": "deployed-asset-exposure-detection-vex-status-and-verification-reference-q01", "text": "What identifiers, source containers, classes, scope and values define deployed asset exposure, detection, vex status and verification reference?", "kind": "relationship", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "deployed-asset-exposure-detection-vex-status-and-verification-reference-q02", "text": "Which authority, evidence, method, event time and knowledge time support deployed asset exposure, detection, vex status and verification reference?", "kind": "authority", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "deployed-asset-exposure-detection-vex-status-and-verification-reference-q03", "text": "How may deployed asset exposure, detection, vex status and verification reference be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "exception", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "deployed-asset-exposure-detection-vex-status-and-verification-reference-data", "name": "Deployed asset exposure, detection, VEX status and verification reference data", "description": "Structured source-qualified vulnerability data for deployed asset exposure, detection, vex status and verification reference.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-007", "SRC-008" ] } ], "artifacts": [ { "id": "deployed-asset-exposure-detection-vex-status-and-verification-reference-record", "name": "Deployed asset exposure, detection, VEX status and verification reference record", "description": "Versioned evidence-bearing vulnerability record for deployed asset exposure, detection, vex status and verification reference with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus deployed-asset-exposure-detection-vex-status-and-verification-reference assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-003", "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "record-change-dispute-correction-and-retirement", "name": "Record change, dispute, correction and retirement", "description": "Keeps append-only changes and justified terminal states.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-009", "SRC-011" ], "findings": [ { "id": "change-item-field-diff-reason-source-actor-and-predecessor", "name": "Change item, field diff, reason, source, actor and predecessor", "description": "Changed path, old and new assertion references, reason, responsible actor, authority, predecessor digest, validation and effective time.", "source_refs": [ "SRC-001", "SRC-003", "SRC-011" ], "questions": [ { "id": "change-item-field-diff-reason-source-actor-and-predecessor-q01", "text": "What identifiers, source containers, classes, scope and values define change item, field diff, reason, source, actor and predecessor?", "kind": "ownership", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "change-item-field-diff-reason-source-actor-and-predecessor-q02", "text": "Which authority, evidence, method, event time and knowledge time support change item, field diff, reason, source, actor and predecessor?", "kind": "provenance", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "change-item-field-diff-reason-source-actor-and-predecessor-q03", "text": "How may change item, field diff, reason, source, actor and predecessor be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "access", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "change-item-field-diff-reason-source-actor-and-predecessor-data", "name": "Change item, field diff, reason, source, actor and predecessor data", "description": "Structured source-qualified vulnerability data for change item, field diff, reason, source, actor and predecessor.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-011" ] } ], "artifacts": [ { "id": "change-item-field-diff-reason-source-actor-and-predecessor-record", "name": "Change item, field diff, reason, source, actor and predecessor record", "description": "Versioned evidence-bearing vulnerability record for change item, field diff, reason, source, actor and predecessor with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus change-item-field-diff-reason-source-actor-and-predecessor assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "dispute-correction-rejection-withdrawal-supersession-and-tombstone", "name": "Dispute, correction, rejection, withdrawal, supersession and tombstone", "description": "Challenge and evidence, resolution authority, corrected successor, rejection or withdrawal reason, tombstone status and retained aliases.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-011" ], "questions": [ { "id": "dispute-correction-rejection-withdrawal-supersession-and-tombstone-q01", "text": "What identifiers, source containers, classes, scope and values define dispute, correction, rejection, withdrawal, supersession and tombstone?", "kind": "lifecycle", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "dispute-correction-rejection-withdrawal-supersession-and-tombstone-q02", "text": "Which authority, evidence, method, event time and knowledge time support dispute, correction, rejection, withdrawal, supersession and tombstone?", "kind": "temporal", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "dispute-correction-rejection-withdrawal-supersession-and-tombstone-q03", "text": "How may dispute, correction, rejection, withdrawal, supersession and tombstone be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "retention", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "dispute-correction-rejection-withdrawal-supersession-and-tombstone-data", "name": "Dispute, correction, rejection, withdrawal, supersession and tombstone data", "description": "Structured source-qualified vulnerability data for dispute, correction, rejection, withdrawal, supersession and tombstone.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-011" ] } ], "artifacts": [ { "id": "dispute-correction-rejection-withdrawal-supersession-and-tombstone-record", "name": "Dispute, correction, rejection, withdrawal, supersession and tombstone record", "description": "Versioned evidence-bearing vulnerability record for dispute, correction, rejection, withdrawal, supersession and tombstone with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus dispute-correction-rejection-withdrawal-supersession-and-tombstone assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-011" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "interoperability-access-quality-and-agent-governance", "name": "Interoperability, access, quality and agent governance", "description": "Provides versioned projections, quality controls, restricted views and safe automated maintenance.", "rationale": "Security data can include embargoed evidence, personal contacts and exploit-sensitive detail, and schema translation never proves semantic equivalence.", "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009", "SRC-010", "SRC-011", "SRC-012" ], "layers": [ { "id": "crosswalk-projection-deduplication-and-quality", "name": "Crosswalk, projection, deduplication and quality", "description": "Maps overlapping formats and measures claim-level quality.", "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009", "SRC-010", "SRC-011" ], "findings": [ { "id": "cve-nvd-osv-csaf-vex-stix-cwe-cvss-crosswalk-and-loss", "name": "CVE, NVD, OSV, CSAF, VEX, STIX, CWE and CVSS crosswalk and loss", "description": "Source and target versions, field mappings, code translations, omissions, assertion-authority changes and round-trip limits.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-008", "SRC-009", "SRC-010" ], "questions": [ { "id": "cve-nvd-osv-csaf-vex-stix-cwe-cvss-crosswalk-and-loss-q01", "text": "What identifiers, source containers, classes, scope and values define cve, nvd, osv, csaf, vex, stix, cwe and cvss crosswalk and loss?", "kind": "definition", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "cve-nvd-osv-csaf-vex-stix-cwe-cvss-crosswalk-and-loss-q02", "text": "Which authority, evidence, method, event time and knowledge time support cve, nvd, osv, csaf, vex, stix, cwe and cvss crosswalk and loss?", "kind": "quality", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "cve-nvd-osv-csaf-vex-stix-cwe-cvss-crosswalk-and-loss-q03", "text": "How may cve, nvd, osv, csaf, vex, stix, cwe and cvss crosswalk and loss be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "security", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "cve-nvd-osv-csaf-vex-stix-cwe-cvss-crosswalk-and-loss-data", "name": "CVE, NVD, OSV, CSAF, VEX, STIX, CWE and CVSS crosswalk and loss data", "description": "Structured source-qualified vulnerability data for cve, nvd, osv, csaf, vex, stix, cwe and cvss crosswalk and loss.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-008", "SRC-009", "SRC-010" ] } ], "artifacts": [ { "id": "cve-nvd-osv-csaf-vex-stix-cwe-cvss-crosswalk-and-loss-record", "name": "CVE, NVD, OSV, CSAF, VEX, STIX, CWE and CVSS crosswalk and loss record", "description": "Versioned evidence-bearing vulnerability record for cve, nvd, osv, csaf, vex, stix, cwe and cvss crosswalk and loss with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus cve-nvd-osv-csaf-vex-stix-cwe-cvss-crosswalk-and-loss assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-008", "SRC-009", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "completeness-consistency-timeliness-source-trust-and-conflict-quality", "name": "Completeness, consistency, timeliness, source trust and conflict quality", "description": "Quality rule version, evaluated claims, missing fields, stale sources, contradictions, validation evidence, score and prohibited inference.", "source_refs": [ "SRC-001", "SRC-003", "SRC-009", "SRC-011" ], "questions": [ { "id": "completeness-consistency-timeliness-source-trust-and-conflict-quality-q01", "text": "What identifiers, source containers, classes, scope and values define completeness, consistency, timeliness, source trust and conflict quality?", "kind": "classification", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "completeness-consistency-timeliness-source-trust-and-conflict-quality-q02", "text": "Which authority, evidence, method, event time and knowledge time support completeness, consistency, timeliness, source trust and conflict quality?", "kind": "process", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "completeness-consistency-timeliness-source-trust-and-conflict-quality-q03", "text": "How may completeness, consistency, timeliness, source trust and conflict quality be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "interoperability", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "completeness-consistency-timeliness-source-trust-and-conflict-quality-data", "name": "Completeness, consistency, timeliness, source trust and conflict quality data", "description": "Structured source-qualified vulnerability data for completeness, consistency, timeliness, source trust and conflict quality.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-009", "SRC-011" ] } ], "artifacts": [ { "id": "completeness-consistency-timeliness-source-trust-and-conflict-quality-record", "name": "Completeness, consistency, timeliness, source trust and conflict quality record", "description": "Versioned evidence-bearing vulnerability record for completeness, consistency, timeliness, source trust and conflict quality with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus completeness-consistency-timeliness-source-trust-and-conflict-quality assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-009", "SRC-011" ] } ], "inline_only_rationale": null } ] }, { "id": "access-retention-and-safe-agent-operations", "name": "Access, retention and safe agent operations", "description": "Controls disclosure and autonomous use.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-011", "SRC-012" ], "findings": [ { "id": "public-coordinator-vendor-researcher-operator-and-analytical-view", "name": "Public, coordinator, vendor, researcher, operator and analytical view", "description": "Audience, purpose, authority, allowed fields, embargo, contact masking, exploit-detail restriction, expiry, freshness and disclosure event.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-011" ], "questions": [ { "id": "public-coordinator-vendor-researcher-operator-and-analytical-view-q01", "text": "What identifiers, source containers, classes, scope and values define public, coordinator, vendor, researcher, operator and analytical view?", "kind": "composition", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "public-coordinator-vendor-researcher-operator-and-analytical-view-q02", "text": "Which authority, evidence, method, event time and knowledge time support public, coordinator, vendor, researcher, operator and analytical view?", "kind": "measurement", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "public-coordinator-vendor-researcher-operator-and-analytical-view-q03", "text": "How may public, coordinator, vendor, researcher, operator and analytical view be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "validation", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "public-coordinator-vendor-researcher-operator-and-analytical-view-data", "name": "Public, coordinator, vendor, researcher, operator and analytical view data", "description": "Structured source-qualified vulnerability data for public, coordinator, vendor, researcher, operator and analytical view.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-011" ] } ], "artifacts": [ { "id": "public-coordinator-vendor-researcher-operator-and-analytical-view-record", "name": "Public, coordinator, vendor, researcher, operator and analytical view record", "description": "Versioned evidence-bearing vulnerability record for public, coordinator, vendor, researcher, operator and analytical view with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus public-coordinator-vendor-researcher-operator-and-analytical-view assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "agent-authority-operation-prewrite-postwrite-concurrency-recovery-and-retention", "name": "Agent authority, operation, pre-write, post-write, concurrency, recovery and retention", "description": "Actor and agent, delegated authority, operation, expected head, validation, idempotency, approval class, outcome, rollback, retention and audit event.", "source_refs": [ "SRC-001", "SRC-011", "SRC-012" ], "questions": [ { "id": "agent-authority-operation-prewrite-postwrite-concurrency-recovery-and-retention-q01", "text": "What identifiers, source containers, classes, scope and values define agent authority, operation, pre-write, post-write, concurrency, recovery and retention?", "kind": "state", "answer_data": [ "identifiers and aliases", "source and class", "scope and values", "explicit unknowns" ] }, { "id": "agent-authority-operation-prewrite-postwrite-concurrency-recovery-and-retention-q02", "text": "Which authority, evidence, method, event time and knowledge time support agent authority, operation, pre-write, post-write, concurrency, recovery and retention?", "kind": "decision", "answer_data": [ "authority", "evidence and method", "event and knowledge time", "confidence" ] }, { "id": "agent-authority-operation-prewrite-postwrite-concurrency-recovery-and-retention-q03", "text": "How may agent authority, operation, pre-write, post-write, concurrency, recovery and retention be validated, disputed, corrected, superseded, retained and disclosed without enabling unsafe exploitation?", "kind": "temporal", "answer_data": [ "validation", "challenge and correction", "successor history", "retention and access", "unsafe-detail boundary" ] } ], "data_elements": [ { "id": "agent-authority-operation-prewrite-postwrite-concurrency-recovery-and-retention-data", "name": "Agent authority, operation, pre-write, post-write, concurrency, recovery and retention data", "description": "Structured source-qualified vulnerability data for agent authority, operation, pre-write, post-write, concurrency, recovery and retention.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-011", "SRC-012" ] } ], "artifacts": [ { "id": "agent-authority-operation-prewrite-postwrite-concurrency-recovery-and-retention-record", "name": "Agent authority, operation, pre-write, post-write, concurrency, recovery and retention record", "description": "Versioned evidence-bearing vulnerability record for agent authority, operation, pre-write, post-write, concurrency, recovery and retention with source, method, event and knowledge time, confidence and access marking.", "media_or_form": [ "logical vulnerability assertion", "authoritative registry, advisory or assessment reference" ], "serial": true, "identity_strategy": "Vulnerability record identifier plus agent-authority-operation-prewrite-postwrite-concurrency-recovery-and-retention assertion or event identifier; description, product, score, date and digest never identify a vulnerability alone.", "source_refs": [ "SRC-001", "SRC-011", "SRC-012" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "register-vulnerability-record", "name": "Register vulnerability record", "description": "Create authority-qualified identity, source container, initial description and explicit provisional state.", "inputs": [ "source authority", "identifier or reservation", "initial report" ], "outputs": [ "vulnerability revision" ], "preconditions": [ "namespace, authority, duplicate search and minimum evidence validate" ], "effects": [ "record becomes resolvable without claiming universal validation" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-009" ] }, { "id": "classify-weakness-and-describe-mechanism", "name": "Classify weakness and describe mechanism", "description": "Attach source-qualified descriptions, CWE mappings, prerequisites and mechanism assertions.", "inputs": [ "vulnerability", "description", "classifier mapping" ], "outputs": [ "description and problem-type revision" ], "preconditions": [ "language, classifier version, mapping method and confidence validate" ], "effects": [ "description and classification become attributable" ], "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "assert-affected-product-range", "name": "Assert affected product range", "description": "Bind external product identity and a version or configuration status assertion.", "inputs": [ "vulnerability", "product reference", "range or versions", "source" ], "outputs": [ "affectedness assertion" ], "preconditions": [ "product namespace, range scheme, status, source and evidence validate" ], "effects": [ "affectedness becomes queryable without asserting deployed exposure" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-008", "SRC-009" ] }, { "id": "record-discovery-and-coordination-event", "name": "Record discovery and coordination event", "description": "Append reporting, validation, vendor notification, embargo or disclosure events with protected attribution.", "inputs": [ "vulnerability", "event", "actor", "evidence" ], "outputs": [ "timeline revision" ], "preconditions": [ "authority, access class and event versus knowledge time validate" ], "effects": [ "coordination history advances without exposing restricted detail" ], "source_refs": [ "SRC-001", "SRC-009", "SRC-011", "SRC-012" ] }, { "id": "attach-severity-assessment", "name": "Attach severity assessment", "description": "Record a complete versioned CVSS vector or another source-qualified severity assertion.", "inputs": [ "vulnerability", "assessment", "assessor" ], "outputs": [ "severity assertion" ], "preconditions": [ "scoring version, vector, scope, assessor and calculation validate" ], "effects": [ "severity remains comparable without becoming universal risk" ], "source_refs": [ "SRC-003", "SRC-005", "SRC-008" ] }, { "id": "attach-exploitation-or-priority-signal", "name": "Attach exploitation or priority signal", "description": "Record EPSS, KEV, SSVC or local-decision references with their distinct semantics and times.", "inputs": [ "vulnerability", "signal", "source" ], "outputs": [ "priority-signal revision" ], "preconditions": [ "source, model or catalog version, scoring date and scope validate" ], "effects": [ "time-varying signals remain attributable and non-interchangeable" ], "source_refs": [ "SRC-003", "SRC-006", "SRC-007" ] }, { "id": "link-remediation-or-exposure", "name": "Link remediation or exposure", "description": "Connect external fix, advisory, VEX product status, deployed exposure or remediation state.", "inputs": [ "vulnerability", "external record", "relation" ], "outputs": [ "typed external relation" ], "preconditions": [ "external identity, product scope, authority and freshness validate" ], "effects": [ "consumer can traverse context without duplicating the external lifecycle" ], "source_refs": [ "SRC-007", "SRC-008", "SRC-009" ] }, { "id": "correct-reject-withdraw-or-supersede", "name": "Correct, reject, withdraw or supersede", "description": "Append a justified successor or terminal record state while retaining all cited history and aliases.", "inputs": [ "vulnerability", "change authority", "reason", "evidence" ], "outputs": [ "successor revision or tombstone" ], "preconditions": [ "authority, expected head, reason, aliases and references validate" ], "effects": [ "current state changes without destructive overwrite" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-009", "SRC-011" ] }, { "id": "issue-purpose-bound-vulnerability-view", "name": "Issue purpose-bound vulnerability view", "description": "Create public, coordinator, vendor, operator or analytical projection with redaction and version pins.", "inputs": [ "vulnerability revision", "audience", "purpose", "target profile" ], "outputs": [ "validated vulnerability projection" ], "preconditions": [ "embargo, contact protection, unsafe detail, freshness and target schema validate" ], "effects": [ "view links source digest, omissions and loss statement" ], "source_refs": [ "SRC-001", "SRC-008", "SRC-010", "SRC-011" ] }, { "id": "validate-reconcile-and-retire-record", "name": "Validate, reconcile and retire record", "description": "Evaluate schema, identifiers, relations, affectedness, sources and conflicts, then close or retain under policy.", "inputs": [ "vulnerability revision", "validation profile", "retention authority" ], "outputs": [ "validation report", "retirement event when authorized" ], "preconditions": [ "source records, disputes, legal hold and retention policy resolve" ], "effects": [ "quality and terminal state are explicit without erasing evidence" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-009", "SRC-011" ] } ], "composition": [ { "target": "Product, Package and Software Component models", "relation": "REFERENCE", "purpose": "Resolve affected subjects and version semantics without duplicating product identity.", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-009" ] }, { "target": "Weakness Classifier / CWE", "relation": "ALIGN", "purpose": "Map vulnerability mechanisms to versioned weakness classes with method and confidence.", "required": false, "source_refs": [ "SRC-001", "SRC-004" ] }, { "target": "Advisory, Fix, Remediation and Exposure models", "relation": "REFERENCE", "purpose": "Connect communications and operational response while preserving external master lifecycles.", "required": false, "source_refs": [ "SRC-007", "SRC-008", "SRC-009" ] }, { "target": "Exploit, Threat and Cyber Incident models", "relation": "REFERENCE", "purpose": "Link exploitation and realized security events without importing their evidence or response lifecycle.", "required": false, "source_refs": [ "SRC-007", "SRC-010" ] }, { "target": "CVE, NVD, OSV, CSAF, VEX, STIX, CWE and CVSS", "relation": "ALIGN", "purpose": "Project identity, affectedness, advisory, intelligence, classification and scoring data with declared loss.", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005", "SRC-008", "SRC-009", "SRC-010" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Dimension identity, owner, vulnerability-record authority, namespace and accountable coordination roles", "Vulnerability, product, weakness, advisory, exposure, remediation, exploit, threat and incident registries", "Master-system mappings for CVE, ecosystem advisories, products, packages, versions, assets, patches, incidents and actors", "Disclosure, embargo, affectedness, scoring, prioritization, access, retention and agent-operation policies" ], "namespace_guidance": "Prefer the authoritative master-system vulnerability identifier and preserve CVE, ecosystem and advisory namespaces. Keep products, packages, deployments, advisories, patches, exploits, threats, incidents and remediation tasks as typed external references.", "registry_links": [ "https://ver.cy/models/", "https://ver.cy/model-agent-protocol.md", "Dimension-local vulnerability, alias, affectedness, assessment, disclosure-event and external-relation registries" ] }, "canon_and_patch": { "canonicalization_rules": [ "Canonicalize by authoritative master-system vulnerability identifier and source namespace, never by description, product name, weakness class, CVSS score, date or digest.", "Do not merge records from aliases alone unless same-vulnerability criteria and authority are recorded; keep upstream and related distinct." ], "patch_rules": [ "Extensions declare ecosystem and product profile, target finding, source authority, schema or classifier versions and interoperability impact.", "Changes to identity, aliases, affectedness, lifecycle state, authority, access or exploit-sensitive detail require a successor revision, migration map and preserved history." ], "compatibility_rules": [ "Unknown additive fields may be ignored only when identity, authority, description, affectedness, lifecycle, access and provenance remain intact.", "Every CVE, NVD, OSV, CSAF, VEX, STIX, CWE or CVSS projection pins versions and states translations, omissions, authority changes and round-trip limits." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system vulnerability identifier qualified by issuing or home registry namespace.", "Governed globally resolvable vulnerability IRI bound to the authoritative record.", "Dimension UUID or ULID for a pre-publication local report when no external identifier exists." ], "timestamp_rule": "Use RFC 3339 timestamps with seconds and explicit offset or Z; separate reservation, discovery, report, validation, vendor-notice, disclosure, publication, modification, withdrawal, exploitation-observation and knowledge times.", "serial_naming_rule": "Use {vulnerability-id}--{artifact-kind}--{assertion-or-event-id}; never use description, product, weakness class, score, date or digest alone.", "integrity_rule": "Store digest, media type, source authority, schema and classifier versions, language, product scope, event and knowledge times, confidence, licence, access marking and provenance." }, "policies": [ "Only an authorized source organization may establish or change its vulnerability record and assertion containers; enrichments never silently overwrite CNA, vendor or ecosystem claims.", "Vulnerability, weakness, affected product, deployed exposure, advisory, remediation, exploit, threat, incident and organizational risk remain distinct.", "Severity, exploitation probability, known exploitation, decision priority and local risk retain source, method, version, scope and scoring time.", "Agents may perform reversible record maintenance and validation but may not generate exploit instructions, conduct unauthorized scanning, violate an embargo or disclose restricted evidence." ], "crud": { "read": [ "Resolve Dimension policy, source authority, vulnerability head, product namespaces, lifecycle, disclosure class, event and knowledge time, and requested purpose." ], "create": [ "Create identity, source container, initial description, affectedness hypothesis, evidence and explicit unknowns before publishing or scoring." ], "update": [ "Append description, affectedness, assessment, event, relation, correction or source-enrichment assertions with actor, authority, time and provenance; never overwrite cited history." ], "delete": [ "Apply coordinated-disclosure, legal-hold and retention policy; prefer rejection, withdrawal, supersession or tombstone and never cascade deletion to products, advisories, patches, exposures, incidents or evidence." ] }, "roles": [ { "name": "Vulnerability record authority", "responsibilities": [ "Own canonical identifier, record state and authorized source container." ] }, { "name": "CNA, vendor or ecosystem maintainer", "responsibilities": [ "Publish attributable descriptions, affectedness and references within delegated scope." ] }, { "name": "Authorized data publisher or enrichment provider", "responsibilities": [ "Add source-labelled metrics, mappings or threat signals without replacing master claims." ] }, { "name": "Researcher or reporter", "responsibilities": [ "Provide reports and evidence under disclosure and credit policy." ] }, { "name": "Product and remediation owner", "responsibilities": [ "Own product identity, fixes, advisories and remediation statements." ] }, { "name": "Asset and exposure owner", "responsibilities": [ "Determine deployed applicability and operational response in external systems." ] }, { "name": "Disclosure, privacy and records steward", "responsibilities": [ "Control embargoes, contact data, unsafe detail, access, retention and auditability." ] } ], "access": { "default_rule": "Public published claims may be read, but embargoed evidence, reporter contacts, exploit-sensitive detail and internal exposure or risk data default to denied unless role, purpose and policy grant access.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Coordinated disclosure, vendor validation, emergency response, regulator or legal access cites authority and remains purpose-bound, attributable, time-limited and reviewable." ], "audit_requirements": [ "Log actor, agent, role, purpose, vulnerability, operation, policy, RFC 3339 time, source authority, affected records, disclosure class and outcome." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Read Dimension vulnerability authority, disclosure, embargo, affectedness, scoring, product, access, retention and safe-operation policies.", "Read this model and linked product, weakness, advisory, exposure, remediation, exploit, threat and incident models before mutation." ] } }, "coverage": { "claim": "A source-grounded reviewable draft of a vulnerability record across CVE, NVD, CWE, CVSS, EPSS, KEV, CSAF/VEX, OSV, STIX, PROV-O and RFC 3339 primary materials, without deployed-exposure, universal risk, unsafe exploit, automated disclosure or certified-crosswalk claims.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Authoritative vulnerability record identity is separated from weakness, product, advisory, exposure, exploit and incident identities." }, { "dimension": "classification and definition", "status": "covered", "notes": "Record class, schema, CWE mappings and relation kinds are versioned and source-qualified." }, { "dimension": "direct properties", "status": "covered", "notes": "Descriptions, problem types, affected-product assertions, references, credits, metrics and timeline are first-class." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Discovery reports, evidence, validation, known exploitation and source confidence are covered." }, { "dimension": "capabilities and possible actions", "status": "covered", "notes": "Register, describe, bind affectedness, coordinate, assess, link, correct, project, reconcile and retire operations are governed." }, { "dimension": "composition", "status": "covered", "notes": "CNA and ADP containers remain attributable, while products, advisories, patches, deployments and incidents retain external identity." }, { "dimension": "lifecycle", "status": "covered", "notes": "Reservation, discovery, report, validation, disclosure, publication, update, rejection, withdrawal and supersession preserve history." }, { "dimension": "relationships", "status": "covered", "notes": "Aliases, upstream, related, affected product, weakness, advisory, remediation, exposure, exploit and incident links are typed." }, { "dimension": "temporal", "status": "covered", "notes": "Reservation, discovery, reporting, embargo, disclosure, publication, scoring, observation and knowledge times remain distinct." }, { "dimension": "spatial", "status": "covered", "notes": "Jurisdiction and affected deployment location are delegated to source, product or external exposure context." }, { "dimension": "provenance", "status": "covered", "notes": "Source containers, descriptions, affectedness, scores, signals, changes and projections retain responsible-agent provenance." }, { "dimension": "ownership and stewardship", "status": "covered", "notes": "CVE, vendor, ecosystem, product, asset, advisory, remediation and incident masters remain separate." }, { "dimension": "validation and quality", "status": "covered", "notes": "Schema, identifier, alias, affected-range, vector, chronology, source, conflict and stale-head checks are explicit." }, { "dimension": "access and privacy", "status": "covered", "notes": "Public, coordinator, vendor, researcher, operator and analytical views protect contacts and exploit-sensitive details." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Reports, disclosures, record changes, rejections, withdrawals, evidence and legal holds are preserved." }, { "dimension": "interoperability", "status": "covered", "notes": "CVE, NVD, OSV, CSAF, VEX, STIX, CWE and CVSS projections are versioned and loss-aware." } ], "known_omissions": [ "No independent Claude or Grok result was available; later vulnerability-management review is required before canonical promotion.", "No approved outgoing relation rows were supplied; product, weakness, advisory, exposure, remediation, exploit, threat and incident contracts remain reviewable draft references.", "Vendor, ecosystem, embedded, cloud, hardware, configuration and end-of-life product profiles require specialist review.", "Certified CVE, NVD, OSV, CSAF, VEX, STIX, CWE and CVSS crosswalk fixtures remain future work." ], "conflicts": [ "CNA, ADP, NVD, vendor and ecosystem sources can publish different descriptions, affected versions, weakness mappings and severity scores.", "CVSS severity, EPSS exploitation probability, KEV known exploitation, SSVC decisions and local risk are not interchangeable.", "An upstream vulnerability, downstream advisory, bundled issue and fork-specific vulnerability may be related without being aliases." ], "regional_assumptions": [ "CVE and NVD are globally used but their program and U.S. enrichment governance are not universal product truth.", "CISA KEV operational deadlines apply to defined U.S. federal scope, although the catalog can inform other organizations.", "Vendor, CNA, ecosystem and national disclosure practices differ and require local policy profiles." ], "adversarial_checks": [ "Reject identity based only on description, product, CWE class, severity score, date or digest.", "Reject a deployed asset exposure inferred solely from a product-level affected-version assertion.", "Reject severity, exploitation probability, known exploitation or local risk represented as the same measure.", "Reject silent source selection when descriptions, ranges, scores or remediation claims conflict.", "Reject an agent operation that generates exploitation instructions, performs unauthorized scanning, breaks an embargo or deletes cited history." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "aggregate", "status": "accepted as an authority-qualified vulnerability record aggregate", "rationale": "The record owns vulnerability identity, attributable content containers, descriptions, affected-product assertions, assessments and disclosure history. Weakness classes, products, packages, deployed exposures, advisories, fixes, exploits, threats, incidents and risk decisions retain external identity and lifecycle." }, "decisions": [ { "concept": "Vulnerability versus weakness", "disposition": "accepted as separate identities", "rationale": "CWE describes recurring weakness classes; a vulnerability record describes one source-qualified flaw or issue and may map to several classes." }, { "concept": "Record authority and enrichment", "disposition": "accepted as attributable assertion containers", "rationale": "CNA, ADP, NVD, vendor and ecosystem claims can coexist and must not silently overwrite each other." }, { "concept": "Affected product versus deployed exposure", "disposition": "accepted as separate boundaries", "rationale": "A product-range assertion does not prove that a particular deployed asset contains, reaches or exposes the vulnerable configuration." }, { "concept": "Aliases, upstream and related records", "disposition": "accepted as distinct relation semantics", "rationale": "Same-vulnerability criteria are stricter than shared code, advisory grouping or conceptual similarity." }, { "concept": "Severity, exploitability and risk", "disposition": "accepted as distinct assessments", "rationale": "CVSS severity, EPSS probability, KEV inclusion, SSVC decisions and organizational risk answer different questions and vary by source and time." }, { "concept": "Disclosure lifecycle", "disposition": "accepted as multi-event and multi-temporal", "rationale": "Reservation, discovery, reporting, validation, vendor notice, embargo, disclosure, publication and knowledge are not one date or state." }, { "concept": "Remediation and response", "disposition": "accepted as external masters", "rationale": "A fixed version or workaround is not the same as patch deployment, exposure closure, incident response or risk acceptance." }, { "concept": "Corrections and terminal states", "disposition": "accepted as immutable successor history", "rationale": "Rejection, withdrawal, correction, split, merge and supersession preserve identifiers, references and cited predecessor evidence." }, { "concept": "Interoperability", "disposition": "accepted as loss-aware projections", "rationale": "CVE, NVD, OSV, CSAF/VEX, STIX, CWE and CVSS overlap but have different authority and semantics." }, { "concept": "Unsafe agent actions", "disposition": "forbidden", "rationale": "Agents may maintain and validate records but cannot generate exploit instructions, scan without authority, break embargoes or disclose restricted evidence." } ], "publicationHolds": [ "Claude and Grok timed out during their bounded attempts, so independent external review is absent and explicitly waived for this published reviewable draft.", "No approved outgoing model relations were supplied; product, weakness, advisory, exposure, remediation, exploit, threat and incident contracts require governance review.", "Vendor, ecosystem, embedded, cloud, hardware, configuration and end-of-life profiles require specialist review.", "Certified CVE, NVD, OSV, CSAF, VEX, STIX, CWE and CVSS crosswalks and conformance fixtures remain unverified.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Approve relation cardinalities and ownership contracts for products, weaknesses, advisories, exposures, remediation, exploits, threats and incidents.", "Develop ecosystem and product profiles for affected-version ordering, forks, backports, configurations and end-of-life branches.", "Create fixtures for duplicate, split, merge, rejection, withdrawal, conflicting ranges, multiple CVSS sources, KEV addition and VEX status changes.", "Validate certified cross-schema projections with authority, time, conflict, access, information-loss and round-trip tests." ] }, "statistics": { "sources": 12, "bundles": 6, "layers": 12, "findings": 24, "questions": 72, "artifacts": 24, "functions": 10 } }