← Back to catalogue
Published

Cyber Integrity

vr.wm-xct-019 · wm-xct-019-cyber-integrity

Represent evidence-qualified cyber security context attached to an externally mastered system, device or endpoint.

World Models Cross-cutting context XCT.SEC

Bundle → Layer → Finding → Questions Filled

6 bundles · 12 layers · 12 findings · 48 questions

Attachment and authority Host-scoped context for attachment and authority.

Protected subject binding

Attach security context to one externally mastered system, device or endpoint at a declared scope and revision. Host identity, topology and inventory remain external.

Scoped security attachment

Attach security context to one externally mastered system, device or endpoint at a declared scope and revision. Host identity, topology and inventory remain external.

  1. Which authoritative host and scope does this security attachment identify? identity
  2. Which inventory revision and component boundaries define the assessed subject? composition
  3. Which security objectives and criticality profile apply to that subject? classification
  4. When must this attachment be superseded after a host split, merger or retirement? lifecycle

Stewardship mandate

Bind accountable roles and delegated authority for these records. Coordination does not grant access to another tenant or permission to operate on a host.

Scoped accountability and authority

Bind accountable roles and delegated authority for these records. Coordination does not grant access to another tenant or permission to operate on a host.

  1. Which role is accountable for the security context within the declared host scope? ownership
  2. What mandate permits an assessor to contribute or approve a posture assertion? authority
  3. What restrictions follow supplied evidence into a recipient view? access
  4. How is an expired or disputed delegation represented before further edits? exception
Weakness and exposure Host-scoped context for weakness and exposure.

Applicability evidence

Reference a vulnerability or private advisory and bind its assertion to a concrete host configuration. Conflicting, missing and under-investigation evidence remain explicit.

Local vulnerability applicability

Reference a vulnerability or private advisory and bind its assertion to a concrete host configuration. Conflicting, missing and under-investigation evidence remain explicit.

  1. Which vulnerability master and advisory revision support this applicability assertion? relationship
  2. What inventory or configuration evidence establishes the affected product match? evidence
  3. Is the local subject affected, not affected, fixed, under investigation or unknown? state
  4. How are conflicting supplier statements or stale inventory prevented from becoming a confident clearance? validation

Priority context

Retain attributed severity inputs separately from an authorized local priority or risk-acceptance decision. A missing public identifier does not exclude a private vulnerability.

Severity and risk-decision context

Retain attributed severity inputs separately from an authorized local priority or risk-acceptance decision. A missing public identifier does not exclude a private vulnerability.

  1. Which scoring version, vector and metric-group label accompany a cited severity value? measurement
  2. Which host impact and exposure assumptions inform the local treatment priority? requirement
  3. Which external decision approves the treatment priority or residual risk acceptance? decision
  4. When do changed conditions require reconsideration of the recorded priority? temporal
Threat and observation Host-scoped context for threat and observation.

Threat relevance

Record a scoped relevance assertion about externally identified threat information. Attribution is a claim with provenance and confidence, not an identity verdict.

Attributed threat relevance

Record a scoped relevance assertion about externally identified threat information. Attribution is a claim with provenance and confidence, not an identity verdict.

  1. Who asserted this threat relevance and which source object revision was used? provenance
  2. How is a reported campaign or technique relevant to this host scope? relationship
  3. What confidence was stated and what remains unspecified or contested? quality
  4. What source revocation or correction invalidates the local relevance assertion? lifecycle

Signal interpretation

Link indicator definitions, observations and sightings without equating a match with compromise. Detection execution and raw telemetry retention remain outside the mixin.

Indicator and observation binding

Link indicator definitions, observations and sightings without equating a match with compromise. Detection execution and raw telemetry retention remain outside the mixin.

  1. Which indicator revision is being related to which external observation? identity
  2. What observation interval and indicator validity bound this interpretation? temporal
  3. What false-positive explanation or collection gap qualifies the apparent match? quality
  4. Which sharing restrictions apply to the linked observable and any derived summary? security
Baseline and assurance Host-scoped context for baseline and assurance.

Baseline binding

Pin a selected baseline or outcome profile with local applicability and exclusions. Control catalogues, enterprise risks and formal acceptance decisions are separately mastered.

Declared security baseline applicability

Pin a selected baseline or outcome profile with local applicability and exclusions. Control catalogues, enterprise risks and formal acceptance decisions are separately mastered.

  1. Which versioned baseline or target profile applies to this host scope? requirement
  2. Which baseline elements are excluded or inherited and on what recorded basis? constraint
  3. Who approved this baseline binding and its next review point? authority
  4. What mapping distinguishes a local control claim from an external framework outcome? interoperability

Integrity and posture evidence

Bind received assessment or attestation results to their subject, verifier, policy and evidence interval. Cryptographic validity or an integrity measurement does not prove total security.

Bounded assessment and attestation results

Bind received assessment or attestation results to their subject, verifier, policy and evidence interval. Cryptographic validity or an integrity measurement does not prove total security.

  1. Which assessment result, evidence reference and verifier support the recorded posture? evidence
  2. Which appraisal policy and trust assumptions qualify an attestation result? validation
  3. How old is each assessed claim and when does its acceptance expire? temporal
  4. What scope, method and unknown coverage qualify any posture score or pass label? measurement
Treatment and incident linkage Host-scoped context for treatment and incident linkage.

Remediation evidence

Keep planned treatment, reported execution and verification separate. Mitigation and accepted risk do not mean fixed; rollback or new configuration can invalidate verification.

Treatment status and verification

Keep planned treatment, reported execution and verification separate. Mitigation and accepted risk do not mean fixed; rollback or new configuration can invalidate verification.

  1. Which external change or treatment record addresses this local exposure? process
  2. What was planned, reported applied and independently checked for this treatment? state
  3. Which scoped verification result supports a claim that remediation succeeded? evidence
  4. What unresolved failure, deferral or rollback prevents closing the exposure? exception

Incident impact linkage

Associate the host with a separately mastered cyber incident and record the provenance of impact and recovery assertions. Declaration, containment, notification and closure belong to authorized external workflows.

Incident and recovery context

Associate the host with a separately mastered cyber incident and record the provenance of impact and recovery assertions. Declaration, containment, notification and closure belong to authorized external workflows.

  1. Which incident master and declaration evidence establish this host association? event
  2. Which impacts are confirmed, suspected or still unknown for this subject? quality
  3. What externally approved recovery evidence supports the current host posture? evidence
  4. Which response, communication or access-breach case needs a distinct linked record? relationship
Disclosure and record continuity Host-scoped context for disclosure and record continuity.

Disclosure views

Describe proposed audience-specific views of existing security records. A public advisory must not automatically expose private deployment facts; preparing a view does not authorize transmission.

Controlled security projections

Describe proposed audience-specific views of existing security records. A public advisory must not automatically expose private deployment facts; preparing a view does not authorize transmission.

  1. Which identifiable systems or personal data must be suppressed from this audience view? privacy
  2. What source marking and additional permissions bound onward disclosure? access
  3. Who may approve release or lift an embargo for this particular projection? authority
  4. How is the derived view checked for residual identifiers and conflicting markings? validation

Record continuity

Preserve correction lineage, bounded evidence access and semantic loss notes across projections. The adopting retention policy controls payload disposal; an evidence digest cannot replace required review.

Revision, retention and exchange

Preserve correction lineage, bounded evidence access and semantic loss notes across projections. The adopting retention policy controls payload disposal; an evidence digest cannot replace required review.

  1. Which prior assertion does a correction supersede while preserving its original attribution? provenance
  2. Which retention schedule or hold governs local security evidence and its references? retention
  3. Which versioned exchange binding preserves identifiers, unknown states and markings? interoperability
  4. What remains resolvable when a host or evidence payload is retired or lawfully erased? lifecycle

Classifiers Filled

Family
World Models
Category
Cross-cutting context
Entry kind
mixin
Navigation path
NAV.XCT.SEC
Domain
XCT.SEC
Industry
Cross-industry
Tags
cyberintegrityxct.sec
Also called
S8

What it is Filled

One host-attached security context with scoped applicability, threat relevance, baseline, assurance and response references. The mixin owns its assertions and revisions, not external asset, vulnerability, incident, risk or enforcement masters.

In scope

  • Host and scope attachment with role-based accountability
  • Local vulnerability applicability and attributed priority context
  • Threat and observation interpretation with explicit uncertainty
  • Baseline applicability and received integrity or posture evidence
  • Treatment, incident and recovery references
  • Restricted projections, correction lineage and evidence continuity

Out of scope

  • Creating public vulnerability or incident masters
  • Running scanners, exploiting weaknesses, producing attack instructions or operating protected systems
  • Patch installation, containment, recovery execution, incident declaration and regulatory notification
  • Generic ownership, consent, access enforcement, audit-trail or enterprise risk machinery
  • Physical measurement of the abstract attachment, universal security scores and certification

Why it exists Filled

Represent evidence-qualified cyber security context attached to an externally mastered system, device or endpoint.

Distinguishing features Derived, awaiting review

  • Unlike WM-SFT-002: Software System / Business Application is a candidate host master; local attachment does not duplicate system inventory or lifecycle.
  • Unlike WM-OBJ-008: Device / Sensor / Compute HW is an alternative host master; physical properties and device control stay external.
  • Unlike WM-SFT-018: Network / Endpoint may provide a protected endpoint reference; address, reachability and topology authority stay external.
  • Unlike WM-SFT-001: Software Product is a product reference, not a replacement for a concrete deployed host. Resolve legacy N4 ambiguity explicitly.
  • Unlike WM-SFT-006: Vulnerability Record owns vulnerability identity, advisory lifecycle and public/private identifiers; carry scoped local applicability only.
  • Unlike WM-ACT-020: Cyber Incident owns the incident record and declaration lifecycle; carry host association and attributed impact references only.
  • Unlike WM-ACT-042: Incident Response owns operational response, containment and recovery execution; local functions cannot initiate these operations.
  • Unlike WM-XCT-027: Risk / Control owns generic risk and control bindings and acceptance decisions; carry security-specific baseline and decision references.
  • Unlike WM-XCT-001: Ownership / Stewardship supplies responsibility and delegation references; legal title and ownership transfer remain external.
  • Unlike WM-XCT-002: Access Contract / Consent supplies scoped authorization; security evidence and TLP markings do not issue grants.
  • Unlike WM-XCT-004: Access Audit retains authoritative access-event records; link evidence without owning audit-trail semantics.
  • Unlike WM-XCT-007: Access Breach / Enforcement owns distinct access-violation cases; cyber compromise is not automatically an access-contract violation.
  • Unlike WM-SFT-017: Telemetry / Operational Signal owns observations and collection context; local interpretation does not perform detection or redefine raw telemetry.
  • Unlike WM-XCT-035: Retention / Disposition supplies retention and hold policy bindings; destruction execution remains in its authorized external process.
  • Unlike Legacy S8 and unreviewed supplement: Treat legacy hierarchy and events as leads. Preserve weakness, threat, incident linkage and assurance concerns but move vulnerability and incident masters outward. Legacy M8/N4 labels conflict with current registry identities; bind by verified model ID and actual host kind. Legacy conformance labels and wildcard imports are not admitted.

Note: Derived from boundary notes against neighbouring models.

What robots and AI may and may not do Derived, awaiting review

Must not

  • Return authorized summaries when payload access is denied.
  • Deny by default; grant least privilege by tenant, host, purpose, role and evidence sensitivity.
  • A visible finding never implies permission to fetch its artifacts.

May

  • Bind host context: Proposed local operation, not implemented. Creates only the local security attachment; ambiguous host binding is refused.
  • Record applicability assertion: Proposed local operation, not implemented. Records the submitted assessment; no automatic vulnerability detection or clearance.
  • Link threat interpretation: Proposed local operation, not implemented. Links existing evidence; does not run detection, attribute an actor as fact or declare compromise.
  • Record assurance evidence: Proposed local operation, not implemented. Records received evidence disposition; does not perform cryptographic attestation or certify security.
  • Reconcile treatment references: Proposed local operation, not implemented. Updates local references only; does not install, contain, recover or close an external incident.
  • Prepare restricted view: Proposed local operation, not implemented. Produces a local candidate view only; no transmission, permission expansion or embargo release.

Note: Derived from functions, policies, CRUD and access rules; prohibitions were not authored for agents as such.

Moral aspects Derived, awaiting review

  • Versioned security, disclosure, privacy and retention policies with authority references
  • Resolve every candidate model ID and pin an accepted version before use; no compulsory child models are declared.
  • Source markings and embargo terms constrain onward use in addition to applicable permissions and privacy rules.
  • Disclosure and privacy reviewer
  • Generic ownership, consent, access enforcement, audit-trail or enterprise risk machinery
  • Access Contract / Consent supplies scoped authorization; security evidence and TLP markings do not issue grants.

Note: Sentences mentioning harm, privacy, consent or similar, collected from the specification.

Owners Filled

Steward

Adopting system steward role and accountable security coordinator with scoped delegation

Roles

System steward
Accountable for host binding, scope and delegation.
Security analyst
Submits evidence-qualified assertions and preserves uncertainty.
Security reviewer
Reviews applicability, freshness and verification claims independently of their submitter where policy requires.
Response liaison
Links authorized incident and recovery records without executing their workflows.
Disclosure and privacy reviewer
Approves candidate recipient views and retention decisions within an explicit mandate.

Links to other meta-models Filled

references

  • WM-SFT-002 - Software System / Business Application is a candidate host master; local attachment does not duplicate system inventory or lifecycle.
  • WM-OBJ-008 - Device / Sensor / Compute HW is an alternative host master; physical properties and device control stay external.
  • WM-SFT-018 - Network / Endpoint may provide a protected endpoint reference; address, reachability and topology authority stay external.
  • WM-SFT-001 - Software Product is a product reference, not a replacement for a concrete deployed host. Resolve legacy N4 ambiguity explicitly.
  • WM-SFT-006 - Vulnerability Record owns vulnerability identity, advisory lifecycle and public/private identifiers; carry scoped local applicability only.
  • WM-ACT-020 - Cyber Incident owns the incident record and declaration lifecycle; carry host association and attributed impact references only.
  • WM-ACT-042 - Incident Response owns operational response, containment and recovery execution; local functions cannot initiate these operations.
  • WM-XCT-027 - Risk / Control owns generic risk and control bindings and acceptance decisions; carry security-specific baseline and decision references.
  • WM-XCT-001 - Ownership / Stewardship supplies responsibility and delegation references; legal title and ownership transfer remain external.
  • WM-XCT-002 - Access Contract / Consent supplies scoped authorization; security evidence and TLP markings do not issue grants.
  • WM-XCT-004 - Access Audit retains authoritative access-event records; link evidence without owning audit-trail semantics.
  • WM-XCT-007 - Access Breach / Enforcement owns distinct access-violation cases; cyber compromise is not automatically an access-contract violation.
  • WM-SFT-017 - Telemetry / Operational Signal owns observations and collection context; local interpretation does not perform detection or redefine raw telemetry.
  • WM-XCT-035 - Retention / Disposition supplies retention and hold policy bindings; destruction execution remains in its authorized external process.

aligned

  • NIST CSF 2.0 - Conceptual mapping to selected outcomes and profiles; no blanket conformance or certification.
  • OASIS CSAF 2.0 - Advisory and product-status mapping only; pin errata and validate an actual exchange before claiming conformance.
  • STIX 2.1 - Selected threat, observation and marking concepts only; no lossless implementation claimed.
  • CVSS 4.0 - Carry attributed severity vectors and metric-group labels; no score calculator or risk engine.
  • TLP 2.0 - Record sharing restrictions without replacing applicable access or legal rules.
  • RFC 9334 - Conceptual separation of received evidence and results from appraisal and enforcement; no attestation protocol implementation.

neighbor

  • WM-SFT-002 - Software System / Business Application is a candidate host master; local attachment does not duplicate system inventory or lifecycle.
  • WM-OBJ-008 - Device / Sensor / Compute HW is an alternative host master; physical properties and device control stay external.
  • WM-SFT-018 - Network / Endpoint may provide a protected endpoint reference; address, reachability and topology authority stay external.
  • WM-SFT-001 - Software Product is a product reference, not a replacement for a concrete deployed host. Resolve legacy N4 ambiguity explicitly.
  • WM-SFT-006 - Vulnerability Record owns vulnerability identity, advisory lifecycle and public/private identifiers; carry scoped local applicability only.
  • WM-ACT-020 - Cyber Incident owns the incident record and declaration lifecycle; carry host association and attributed impact references only.
  • WM-ACT-042 - Incident Response owns operational response, containment and recovery execution; local functions cannot initiate these operations.
  • WM-XCT-027 - Risk / Control owns generic risk and control bindings and acceptance decisions; carry security-specific baseline and decision references.
  • WM-XCT-001 - Ownership / Stewardship supplies responsibility and delegation references; legal title and ownership transfer remain external.
  • WM-XCT-002 - Access Contract / Consent supplies scoped authorization; security evidence and TLP markings do not issue grants.
  • WM-XCT-004 - Access Audit retains authoritative access-event records; link evidence without owning audit-trail semantics.
  • WM-XCT-007 - Access Breach / Enforcement owns distinct access-violation cases; cyber compromise is not automatically an access-contract violation.
  • WM-SFT-017 - Telemetry / Operational Signal owns observations and collection context; local interpretation does not perform detection or redefine raw telemetry.
  • WM-XCT-035 - Retention / Disposition supplies retention and hold policy bindings; destruction execution remains in its authorized external process.
  • Legacy S8 and unreviewed supplement - Treat legacy hierarchy and events as leads. Preserve weakness, threat, incident linkage and assurance concerns but move vulnerability and incident masters outward. Legacy M8/N4 labels conflict with current registry identities; bind by verified model ID and actual host kind. Legacy conformance labels and wildcard imports are not admitted.

What else AI and robots need to interact with it Incomplete

Identity and identifiers required Filled

  • Authoritative master-system identifier
  • Governed global identifier or IRI
  • UUID or ULID assigned by the adopting Dimension

Direct properties not applicable Not applicable

Not applicable

Institutional or informational subject: no invented physical properties.

Recognition optional Missing, in the backlog

Not described yet. This gap is in the card backlog.

Capabilities and actions required Filled

  • Bind host context: Proposed local operation, not implemented. Creates only the local security attachment; ambiguous host binding is refused.
  • Record applicability assertion: Proposed local operation, not implemented. Records the submitted assessment; no automatic vulnerability detection or clearance.
  • Link threat interpretation: Proposed local operation, not implemented. Links existing evidence; does not run detection, attribute an actor as fact or declare compromise.
  • Record assurance evidence: Proposed local operation, not implemented. Records received evidence disposition; does not perform cryptographic attestation or certify security.
  • Reconcile treatment references: Proposed local operation, not implemented. Updates local references only; does not install, contain, recover or close an external incident.
  • Prepare restricted view: Proposed local operation, not implemented. Produces a local candidate view only; no transmission, permission expansion or embargo release.

Hazards and failure modes optional Missing, in the backlog

Not described yet. This gap is in the card backlog.

Standards and interfaces required Derived, awaiting review

  • The NIST Cybersecurity Framework (CSF) 2.0

Context of use required Filled

  • Cited sources provide technical guidance and exchange concepts, not a universal legal regime.
  • Adopting jurisdiction and sector determine reporting duties, evidence retention and authority.
  • NIST guidance is used as a conceptual source without importing federal mandates.

Sources Filled

  1. The NIST Cybersecurity Framework (CSF) 2.0 - National Institute of Standards and Technology
  2. Common Security Advisory Framework Version 2.0 - OASIS Open
  3. Common Vulnerability Scoring System version 4.0: Specification Document - Forum of Incident Response and Security Teams
  4. STIX Version 2.1 - OASIS Open
  5. Traffic Light Protocol (TLP): Standards Definitions and Usage Guidance - Forum of Incident Response and Security Teams
  6. Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile - National Institute of Standards and Technology
  7. Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology - National Institute of Standards and Technology
  8. Remote ATtestation procedureS (RATS) Architecture - Internet Engineering Task Force

Open questions

  • Restore independent external review before canonical or publishable-draft promotion.
  • Complete source reachability, version and errata checks with substantive claim review, including a pinned CSAF errata policy.
  • Develop adopting profiles and executable cases for ambiguous hosts, conflicting advisories, stale attestation, indicator false positives, rollback, withheld evidence, privacy and lawful erasure.
  • Reconcile and pin external model versions and legacy host identities with the coordinator before instance migration.
  • Independent external review absent under the single-provider waiver.
  • Direct HTTP checks not attempted under owner-reported sandbox restriction; selected browser readings do not verify all errata or current versions.
  • Nested instance schemas, stable neighbor version pins, exchange conformance and executable adversarial fixtures remain incomplete.
  • Jurisdictional obligations, disclosure licensing, operational safety and specialized sector profiles require adopting expert review.

Machine files

Provenance

world-models research · reviewable-draft

Built from: models/wm-xct-019-cyber-integrity/spec.yaml