# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-10-06T13:49:54Z", "synthesisSha256": "eade5a639c4d111c39e1798e6590d813b230c092cb10c65f069d642addaf0b30", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-XCT-019", "registryId": "vr.wm-xct-019", "name": "Cyber Integrity", "version": "0.1.0-reviewable-draft", "previousVersions": [ { "version": "0.2.0-legacy", "url": "https://github.com/ver-cy/world-models/blob/feat/mega-model-registry/models/security-ownership-access/S8-cyber-integrity-and-system-security.md" } ], "entryKind": "mixin", "family": "World Models", "category": "Cross-cutting context", "industry": [ "Cross-industry" ], "domain": [ "XCT.SEC" ], "tags": [ "cyber", "integrity", "xct.sec" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-xct-019-cyber-integrity/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-xct-019", "model": { "registry_id": "vr.wm-xct-019", "model_id": "WM-XCT-019", "name": "Cyber Integrity", "entry_kind": "mixin", "purpose": "Represent evidence-qualified cyber security context attached to an externally mastered system, device or endpoint.", "scope_statement": "One host-attached security context with scoped applicability, threat relevance, baseline, assurance and response references. The mixin owns its assertions and revisions, not external asset, vulnerability, incident, risk or enforcement masters.", "in_scope": [ "Host and scope attachment with role-based accountability", "Local vulnerability applicability and attributed priority context", "Threat and observation interpretation with explicit uncertainty", "Baseline applicability and received integrity or posture evidence", "Treatment, incident and recovery references", "Restricted projections, correction lineage and evidence continuity" ], "out_of_scope": [ "Creating public vulnerability or incident masters", "Running scanners, exploiting weaknesses, producing attack instructions or operating protected systems", "Patch installation, containment, recovery execution, incident declaration and regulatory notification", "Generic ownership, consent, access enforcement, audit-trail or enterprise risk machinery", "Physical measurement of the abstract attachment, universal security scores and certification" ], "boundary_notes": [ { "neighbor": "WM-SFT-002", "distinction": "Software System / Business Application is a candidate host master; local attachment does not duplicate system inventory or lifecycle.", "source_refs": [ "SRC-001" ] }, { "neighbor": "WM-OBJ-008", "distinction": "Device / Sensor / Compute HW is an alternative host master; physical properties and device control stay external.", "source_refs": [ "SRC-001", "SRC-008" ] }, { "neighbor": "WM-SFT-018", "distinction": "Network / Endpoint may provide a protected endpoint reference; address, reachability and topology authority stay external.", "source_refs": [ "SRC-001", "SRC-008" ] }, { "neighbor": "WM-SFT-001", "distinction": "Software Product is a product reference, not a replacement for a concrete deployed host. Resolve legacy N4 ambiguity explicitly.", "source_refs": [ "SRC-002" ] }, { "neighbor": "WM-SFT-006", "distinction": "Vulnerability Record owns vulnerability identity, advisory lifecycle and public/private identifiers; carry scoped local applicability only.", "source_refs": [ "SRC-002", "SRC-003" ] }, { "neighbor": "WM-ACT-020", "distinction": "Cyber Incident owns the incident record and declaration lifecycle; carry host association and attributed impact references only.", "source_refs": [ "SRC-006" ] }, { "neighbor": "WM-ACT-042", "distinction": "Incident Response owns operational response, containment and recovery execution; local functions cannot initiate these operations.", "source_refs": [ "SRC-006" ] }, { "neighbor": "WM-XCT-027", "distinction": "Risk / Control owns generic risk and control bindings and acceptance decisions; carry security-specific baseline and decision references.", "source_refs": [ "SRC-001", "SRC-003" ] }, { "neighbor": "WM-XCT-001", "distinction": "Ownership / Stewardship supplies responsibility and delegation references; legal title and ownership transfer remain external.", "source_refs": [ "SRC-001" ] }, { "neighbor": "WM-XCT-002", "distinction": "Access Contract / Consent supplies scoped authorization; security evidence and TLP markings do not issue grants.", "source_refs": [ "SRC-001", "SRC-005" ] }, { "neighbor": "WM-XCT-004", "distinction": "Access Audit retains authoritative access-event records; link evidence without owning audit-trail semantics.", "source_refs": [ "SRC-001", "SRC-006" ] }, { "neighbor": "WM-XCT-007", "distinction": "Access Breach / Enforcement owns distinct access-violation cases; cyber compromise is not automatically an access-contract violation.", "source_refs": [ "SRC-006" ] }, { "neighbor": "WM-SFT-017", "distinction": "Telemetry / Operational Signal owns observations and collection context; local interpretation does not perform detection or redefine raw telemetry.", "source_refs": [ "SRC-004" ] }, { "neighbor": "WM-XCT-035", "distinction": "Retention / Disposition supplies retention and hold policy bindings; destruction execution remains in its authorized external process.", "source_refs": [ "SRC-006" ] }, { "neighbor": "Legacy S8 and unreviewed supplement", "distinction": "Treat legacy hierarchy and events as leads. Preserve weakness, threat, incident linkage and assurance concerns but move vulnerability and incident masters outward. Legacy M8/N4 labels conflict with current registry identities; bind by verified model ID and actual host kind. Legacy conformance labels and wildcard imports are not admitted.", "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ] } ] }, "sources": [ { "id": "SRC-001", "title": "The NIST Cybersecurity Framework (CSF) 2.0", "organization": "National Institute of Standards and Technology", "url": "https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf", "version_or_date": "2.0; 2024-02-26", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:48:01Z", "relevance": "Sections 2-3 and Appendix A: scoped posture, asset context, governance and outcome references; not a prescribed implementation." }, { "id": "SRC-002", "title": "Common Security Advisory Framework Version 2.0", "organization": "OASIS Open", "url": "https://docs.oasis-open.org/csaf/csaf/v2.0/os/csaf-v2.0-os.html", "version_or_date": "OASIS Standard; 2022-11-18; later errata applicability remains a hold", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:48:01Z", "relevance": "Product-specific advisory assertions, status conflicts and VEX profile rules inform local applicability bindings; public product status alone is not local exposure evidence." }, { "id": "SRC-003", "title": "Common Vulnerability Scoring System version 4.0: Specification Document", "organization": "Forum of Incident Response and Security Teams", "url": "https://www.first.org/cvss/v4.0/specification-document", "version_or_date": "CVSS 4.0; document 1.2; 2024-06-18", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:48:01Z", "relevance": "Severity, vector and metric-group context inform attributed score references; scores do not constitute local risk decisions." }, { "id": "SRC-004", "title": "STIX Version 2.1", "organization": "OASIS Open", "url": "https://docs.oasis-open.org/cti/stix/v2.1/os/stix-v2.1-os.html", "version_or_date": "OASIS Standard; 2021-06-10", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:48:01Z", "relevance": "Common properties and Indicator/Observed Data/Sighting distinctions support attributed, versioned threat and observation links." }, { "id": "SRC-005", "title": "Traffic Light Protocol (TLP): Standards Definitions and Usage Guidance", "organization": "Forum of Incident Response and Security Teams", "url": "https://www.first.org/tlp/", "version_or_date": "Version 2.0; August 2022", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:48:01Z", "relevance": "Recipient sharing boundaries inform protected projections; TLP is not an access-control implementation or legal permission." }, { "id": "SRC-006", "title": "Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile", "organization": "National Institute of Standards and Technology", "url": "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r3.pdf", "version_or_date": "SP 800-61 Rev. 3; April 2025", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:48:01Z", "relevance": "Response and recovery profile supports links to separate incident masters, recovery verification and authorized communication." }, { "id": "SRC-007", "title": "Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology", "organization": "National Institute of Standards and Technology", "url": "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-40r4.pdf", "version_or_date": "SP 800-40 Rev. 4; April 2022", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:48:01Z", "relevance": "Patch planning and verification support distinct proposed action, execution report and verification result references." }, { "id": "SRC-008", "title": "Remote ATtestation procedureS (RATS) Architecture", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc9334.html", "version_or_date": "RFC 9334; Informational; January 2023", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-10-06T13:48:01Z", "relevance": "Sections 4, 7-12 distinguish evidence, appraisal, result and relying-party use, with freshness and privacy limits; no attestation implementation is claimed." } ], "structure": { "bundles": [ { "id": "bundle-attachment", "name": "Attachment and authority", "description": "Host-scoped context for attachment and authority.", "rationale": "Group related assertions while preserving external masters and distinct evidence states.", "source_refs": [ "SRC-001", "SRC-005", "SRC-008" ], "layers": [ { "id": "layer-host", "name": "Protected subject binding", "description": "Attach security context to one externally mastered system, device or endpoint at a declared scope and revision. Host identity, topology and inventory remain external.", "source_refs": [ "SRC-001", "SRC-008" ], "findings": [ { "id": "finding-scope", "name": "Scoped security attachment", "description": "Attach security context to one externally mastered system, device or endpoint at a declared scope and revision. Host identity, topology and inventory remain external.", "source_refs": [ "SRC-001", "SRC-008" ], "questions": [ { "id": "question-scope-1", "text": "Which authoritative host and scope does this security attachment identify?", "kind": "identity", "answer_data": [ "data-scope-1: host master reference; attachment identifier; scope identifier" ] }, { "id": "question-scope-2", "text": "Which inventory revision and component boundaries define the assessed subject?", "kind": "composition", "answer_data": [ "data-scope-2: inventory revision reference; included component references; exclusions" ] }, { "id": "question-scope-3", "text": "Which security objectives and criticality profile apply to that subject?", "kind": "classification", "answer_data": [ "data-scope-3: objective codes; criticality profile reference; rationale" ] }, { "id": "question-scope-4", "text": "When must this attachment be superseded after a host split, merger or retirement?", "kind": "lifecycle", "answer_data": [ "data-scope-4: supersession rule; successor references; effective interval" ] } ], "data_elements": [ { "id": "data-scope-1", "name": "Host master reference", "description": "Candidate answer group: host master reference; attachment identifier; scope identifier. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-008" ] }, { "id": "data-scope-2", "name": "Inventory revision reference", "description": "Candidate answer group: inventory revision reference; included component references; exclusions. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-008" ] }, { "id": "data-scope-3", "name": "Objective codes", "description": "Candidate answer group: objective codes; criticality profile reference; rationale. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-008" ] }, { "id": "data-scope-4", "name": "Supersession rule", "description": "Candidate answer group: supersession rule; successor references; effective interval. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-008" ] } ], "artifacts": [ { "id": "artifact-scope", "name": "Scoped security attachment record", "description": "Versioned record or reference manifest for this finding with scope, attribution, evidence state and access markings; raw protected evidence stays in its authorized master.", "media_or_form": [ "structured record", "human review view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first, then governed IRI, then adopting-Dimension UUID or ULID. Stable logical record ID and separate immutable revision ID; a timestamp or digest alone is not identity.", "source_refs": [ "SRC-001", "SRC-008" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-mandate", "name": "Stewardship mandate", "description": "Bind accountable roles and delegated authority for these records. Coordination does not grant access to another tenant or permission to operate on a host.", "source_refs": [ "SRC-001", "SRC-005" ], "findings": [ { "id": "finding-authority", "name": "Scoped accountability and authority", "description": "Bind accountable roles and delegated authority for these records. Coordination does not grant access to another tenant or permission to operate on a host.", "source_refs": [ "SRC-001", "SRC-005" ], "questions": [ { "id": "question-authority-1", "text": "Which role is accountable for the security context within the declared host scope?", "kind": "ownership", "answer_data": [ "data-authority-1: steward reference; responsibility scope; delegation source" ] }, { "id": "question-authority-2", "text": "What mandate permits an assessor to contribute or approve a posture assertion?", "kind": "authority", "answer_data": [ "data-authority-2: role assignment reference; permitted action; mandate expiry" ] }, { "id": "question-authority-3", "text": "What restrictions follow supplied evidence into a recipient view?", "kind": "access", "answer_data": [ "data-authority-3: source markings; recipient scope; access-policy reference" ] }, { "id": "question-authority-4", "text": "How is an expired or disputed delegation represented before further edits?", "kind": "exception", "answer_data": [ "data-authority-4: authority state; dispute reference; review route" ] } ], "data_elements": [ { "id": "data-authority-1", "name": "Steward reference", "description": "Candidate answer group: steward reference; responsibility scope; delegation source. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] }, { "id": "data-authority-2", "name": "Role assignment reference", "description": "Candidate answer group: role assignment reference; permitted action; mandate expiry. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] }, { "id": "data-authority-3", "name": "Source markings", "description": "Candidate answer group: source markings; recipient scope; access-policy reference. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] }, { "id": "data-authority-4", "name": "Authority state", "description": "Candidate answer group: authority state; dispute reference; review route. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] } ], "artifacts": [ { "id": "artifact-authority", "name": "Scoped accountability and authority record", "description": "Versioned record or reference manifest for this finding with scope, attribution, evidence state and access markings; raw protected evidence stays in its authorized master.", "media_or_form": [ "structured record", "human review view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first, then governed IRI, then adopting-Dimension UUID or ULID. Stable logical record ID and separate immutable revision ID; a timestamp or digest alone is not identity.", "source_refs": [ "SRC-001", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-exposure", "name": "Weakness and exposure", "description": "Host-scoped context for weakness and exposure.", "rationale": "Group related assertions while preserving external masters and distinct evidence states.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-007" ], "layers": [ { "id": "layer-applicability", "name": "Applicability evidence", "description": "Reference a vulnerability or private advisory and bind its assertion to a concrete host configuration. Conflicting, missing and under-investigation evidence remain explicit.", "source_refs": [ "SRC-002", "SRC-007" ], "findings": [ { "id": "finding-exposure", "name": "Local vulnerability applicability", "description": "Reference a vulnerability or private advisory and bind its assertion to a concrete host configuration. Conflicting, missing and under-investigation evidence remain explicit.", "source_refs": [ "SRC-002", "SRC-007" ], "questions": [ { "id": "question-exposure-1", "text": "Which vulnerability master and advisory revision support this applicability assertion?", "kind": "relationship", "answer_data": [ "data-exposure-1: vulnerability reference; advisory identifier and revision; issuer" ] }, { "id": "question-exposure-2", "text": "What inventory or configuration evidence establishes the affected product match?", "kind": "evidence", "answer_data": [ "data-exposure-2: component reference; version evidence; matching method; uncertainty" ] }, { "id": "question-exposure-3", "text": "Is the local subject affected, not affected, fixed, under investigation or unknown?", "kind": "state", "answer_data": [ "data-exposure-3: local applicability state; assertion time; supporting rationale" ] }, { "id": "question-exposure-4", "text": "How are conflicting supplier statements or stale inventory prevented from becoming a confident clearance?", "kind": "validation", "answer_data": [ "data-exposure-4: contrary evidence references; freshness rule; unresolved conflict state" ] } ], "data_elements": [ { "id": "data-exposure-1", "name": "Vulnerability reference", "description": "Candidate answer group: vulnerability reference; advisory identifier and revision; issuer. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-007" ] }, { "id": "data-exposure-2", "name": "Component reference", "description": "Candidate answer group: component reference; version evidence; matching method; uncertainty. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-007" ] }, { "id": "data-exposure-3", "name": "Local applicability state", "description": "Candidate answer group: local applicability state; assertion time; supporting rationale. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-007" ] }, { "id": "data-exposure-4", "name": "Contrary evidence references", "description": "Candidate answer group: contrary evidence references; freshness rule; unresolved conflict state. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-007" ] } ], "artifacts": [ { "id": "artifact-exposure", "name": "Local vulnerability applicability record", "description": "Versioned record or reference manifest for this finding with scope, attribution, evidence state and access markings; raw protected evidence stays in its authorized master.", "media_or_form": [ "structured record", "human review view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first, then governed IRI, then adopting-Dimension UUID or ULID. Stable logical record ID and separate immutable revision ID; a timestamp or digest alone is not identity.", "source_refs": [ "SRC-002", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-priority", "name": "Priority context", "description": "Retain attributed severity inputs separately from an authorized local priority or risk-acceptance decision. A missing public identifier does not exclude a private vulnerability.", "source_refs": [ "SRC-003", "SRC-001" ], "findings": [ { "id": "finding-priority", "name": "Severity and risk-decision context", "description": "Retain attributed severity inputs separately from an authorized local priority or risk-acceptance decision. A missing public identifier does not exclude a private vulnerability.", "source_refs": [ "SRC-003", "SRC-001" ], "questions": [ { "id": "question-priority-1", "text": "Which scoring version, vector and metric-group label accompany a cited severity value?", "kind": "measurement", "answer_data": [ "data-priority-1: score; scoring version; vector; metric groups; assessor" ] }, { "id": "question-priority-2", "text": "Which host impact and exposure assumptions inform the local treatment priority?", "kind": "requirement", "answer_data": [ "data-priority-2: impact profile reference; exposure assumptions; priority rationale" ] }, { "id": "question-priority-3", "text": "Which external decision approves the treatment priority or residual risk acceptance?", "kind": "decision", "answer_data": [ "data-priority-3: decision reference; approving role; review date" ] }, { "id": "question-priority-4", "text": "When do changed conditions require reconsideration of the recorded priority?", "kind": "temporal", "answer_data": [ "data-priority-4: trigger conditions; valid interval; next review time" ] } ], "data_elements": [ { "id": "data-priority-1", "name": "Score", "description": "Candidate answer group: score; scoring version; vector; metric groups; assessor. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-001" ] }, { "id": "data-priority-2", "name": "Impact profile reference", "description": "Candidate answer group: impact profile reference; exposure assumptions; priority rationale. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-001" ] }, { "id": "data-priority-3", "name": "Decision reference", "description": "Candidate answer group: decision reference; approving role; review date. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-001" ] }, { "id": "data-priority-4", "name": "Trigger conditions", "description": "Candidate answer group: trigger conditions; valid interval; next review time. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-001" ] } ], "artifacts": [ { "id": "artifact-priority", "name": "Severity and risk-decision context record", "description": "Versioned record or reference manifest for this finding with scope, attribution, evidence state and access markings; raw protected evidence stays in its authorized master.", "media_or_form": [ "structured record", "human review view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first, then governed IRI, then adopting-Dimension UUID or ULID. Stable logical record ID and separate immutable revision ID; a timestamp or digest alone is not identity.", "source_refs": [ "SRC-003", "SRC-001" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-threat", "name": "Threat and observation", "description": "Host-scoped context for threat and observation.", "rationale": "Group related assertions while preserving external masters and distinct evidence states.", "source_refs": [ "SRC-004", "SRC-005" ], "layers": [ { "id": "layer-intelligence", "name": "Threat relevance", "description": "Record a scoped relevance assertion about externally identified threat information. Attribution is a claim with provenance and confidence, not an identity verdict.", "source_refs": [ "SRC-004" ], "findings": [ { "id": "finding-relevance", "name": "Attributed threat relevance", "description": "Record a scoped relevance assertion about externally identified threat information. Attribution is a claim with provenance and confidence, not an identity verdict.", "source_refs": [ "SRC-004" ], "questions": [ { "id": "question-relevance-1", "text": "Who asserted this threat relevance and which source object revision was used?", "kind": "provenance", "answer_data": [ "data-relevance-1: producer reference; object identifier; modified time; evidence reference" ] }, { "id": "question-relevance-2", "text": "How is a reported campaign or technique relevant to this host scope?", "kind": "relationship", "answer_data": [ "data-relevance-2: threat reference; host linkage rationale; alternative explanations" ] }, { "id": "question-relevance-3", "text": "What confidence was stated and what remains unspecified or contested?", "kind": "quality", "answer_data": [ "data-relevance-3: confidence scheme; value or unknown; dissent reference" ] }, { "id": "question-relevance-4", "text": "What source revocation or correction invalidates the local relevance assertion?", "kind": "lifecycle", "answer_data": [ "data-relevance-4: revocation state; superseding object reference; invalidation time" ] } ], "data_elements": [ { "id": "data-relevance-1", "name": "Producer reference", "description": "Candidate answer group: producer reference; object identifier; modified time; evidence reference. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "data-relevance-2", "name": "Threat reference", "description": "Candidate answer group: threat reference; host linkage rationale; alternative explanations. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "data-relevance-3", "name": "Confidence scheme", "description": "Candidate answer group: confidence scheme; value or unknown; dissent reference. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "data-relevance-4", "name": "Revocation state", "description": "Candidate answer group: revocation state; superseding object reference; invalidation time. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [ { "id": "artifact-relevance", "name": "Attributed threat relevance record", "description": "Versioned record or reference manifest for this finding with scope, attribution, evidence state and access markings; raw protected evidence stays in its authorized master.", "media_or_form": [ "structured record", "human review view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first, then governed IRI, then adopting-Dimension UUID or ULID. Stable logical record ID and separate immutable revision ID; a timestamp or digest alone is not identity.", "source_refs": [ "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-signals", "name": "Signal interpretation", "description": "Link indicator definitions, observations and sightings without equating a match with compromise. Detection execution and raw telemetry retention remain outside the mixin.", "source_refs": [ "SRC-004", "SRC-005" ], "findings": [ { "id": "finding-signal", "name": "Indicator and observation binding", "description": "Link indicator definitions, observations and sightings without equating a match with compromise. Detection execution and raw telemetry retention remain outside the mixin.", "source_refs": [ "SRC-004", "SRC-005" ], "questions": [ { "id": "question-signal-1", "text": "Which indicator revision is being related to which external observation?", "kind": "identity", "answer_data": [ "data-signal-1: indicator reference; observation reference; interpretation identifier" ] }, { "id": "question-signal-2", "text": "What observation interval and indicator validity bound this interpretation?", "kind": "temporal", "answer_data": [ "data-signal-2: first and last observed time; valid-from and valid-until; local freshness rule" ] }, { "id": "question-signal-3", "text": "What false-positive explanation or collection gap qualifies the apparent match?", "kind": "quality", "answer_data": [ "data-signal-3: review outcome; alternative explanation; coverage gap" ] }, { "id": "question-signal-4", "text": "Which sharing restrictions apply to the linked observable and any derived summary?", "kind": "security", "answer_data": [ "data-signal-4: marking reference; permitted audience; redaction requirements" ] } ], "data_elements": [ { "id": "data-signal-1", "name": "Indicator reference", "description": "Candidate answer group: indicator reference; observation reference; interpretation identifier. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-005" ] }, { "id": "data-signal-2", "name": "First and last observed time", "description": "Candidate answer group: first and last observed time; valid-from and valid-until; local freshness rule. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-005" ] }, { "id": "data-signal-3", "name": "Review outcome", "description": "Candidate answer group: review outcome; alternative explanation; coverage gap. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-005" ] }, { "id": "data-signal-4", "name": "Marking reference", "description": "Candidate answer group: marking reference; permitted audience; redaction requirements. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-005" ] } ], "artifacts": [ { "id": "artifact-signal", "name": "Indicator and observation binding record", "description": "Versioned record or reference manifest for this finding with scope, attribution, evidence state and access markings; raw protected evidence stays in its authorized master.", "media_or_form": [ "structured record", "human review view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first, then governed IRI, then adopting-Dimension UUID or ULID. Stable logical record ID and separate immutable revision ID; a timestamp or digest alone is not identity.", "source_refs": [ "SRC-004", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-assurance", "name": "Baseline and assurance", "description": "Host-scoped context for baseline and assurance.", "rationale": "Group related assertions while preserving external masters and distinct evidence states.", "source_refs": [ "SRC-001", "SRC-008" ], "layers": [ { "id": "layer-baseline", "name": "Baseline binding", "description": "Pin a selected baseline or outcome profile with local applicability and exclusions. Control catalogues, enterprise risks and formal acceptance decisions are separately mastered.", "source_refs": [ "SRC-001" ], "findings": [ { "id": "finding-baseline", "name": "Declared security baseline applicability", "description": "Pin a selected baseline or outcome profile with local applicability and exclusions. Control catalogues, enterprise risks and formal acceptance decisions are separately mastered.", "source_refs": [ "SRC-001" ], "questions": [ { "id": "question-baseline-1", "text": "Which versioned baseline or target profile applies to this host scope?", "kind": "requirement", "answer_data": [ "data-baseline-1: baseline reference; version; selected outcome references" ] }, { "id": "question-baseline-2", "text": "Which baseline elements are excluded or inherited and on what recorded basis?", "kind": "constraint", "answer_data": [ "data-baseline-2: exclusion rationale; inherited-control reference; responsibility boundary" ] }, { "id": "question-baseline-3", "text": "Who approved this baseline binding and its next review point?", "kind": "authority", "answer_data": [ "data-baseline-3: approval reference; authority scope; review deadline" ] }, { "id": "question-baseline-4", "text": "What mapping distinguishes a local control claim from an external framework outcome?", "kind": "interoperability", "answer_data": [ "data-baseline-4: mapping version; source and target concepts; loss or mismatch notes" ] } ], "data_elements": [ { "id": "data-baseline-1", "name": "Baseline reference", "description": "Candidate answer group: baseline reference; version; selected outcome references. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "data-baseline-2", "name": "Exclusion rationale", "description": "Candidate answer group: exclusion rationale; inherited-control reference; responsibility boundary. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "data-baseline-3", "name": "Approval reference", "description": "Candidate answer group: approval reference; authority scope; review deadline. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "data-baseline-4", "name": "Mapping version", "description": "Candidate answer group: mapping version; source and target concepts; loss or mismatch notes. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] } ], "artifacts": [ { "id": "artifact-baseline", "name": "Declared security baseline applicability record", "description": "Versioned record or reference manifest for this finding with scope, attribution, evidence state and access markings; raw protected evidence stays in its authorized master.", "media_or_form": [ "structured record", "human review view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first, then governed IRI, then adopting-Dimension UUID or ULID. Stable logical record ID and separate immutable revision ID; a timestamp or digest alone is not identity.", "source_refs": [ "SRC-001" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-evidence", "name": "Integrity and posture evidence", "description": "Bind received assessment or attestation results to their subject, verifier, policy and evidence interval. Cryptographic validity or an integrity measurement does not prove total security.", "source_refs": [ "SRC-008", "SRC-001" ], "findings": [ { "id": "finding-assessment", "name": "Bounded assessment and attestation results", "description": "Bind received assessment or attestation results to their subject, verifier, policy and evidence interval. Cryptographic validity or an integrity measurement does not prove total security.", "source_refs": [ "SRC-008", "SRC-001" ], "questions": [ { "id": "question-assessment-1", "text": "Which assessment result, evidence reference and verifier support the recorded posture?", "kind": "evidence", "answer_data": [ "data-assessment-1: result reference; evidence reference; verifier identity; method" ] }, { "id": "question-assessment-2", "text": "Which appraisal policy and trust assumptions qualify an attestation result?", "kind": "validation", "answer_data": [ "data-assessment-2: policy revision; trust anchor reference; verification disposition" ] }, { "id": "question-assessment-3", "text": "How old is each assessed claim and when does its acceptance expire?", "kind": "temporal", "answer_data": [ "data-assessment-3: claim time; result time; freshness limit; expiry" ] }, { "id": "question-assessment-4", "text": "What scope, method and unknown coverage qualify any posture score or pass label?", "kind": "measurement", "answer_data": [ "data-assessment-4: scale definition; denominator; excluded scope; uncertainty; result label" ] } ], "data_elements": [ { "id": "data-assessment-1", "name": "Result reference", "description": "Candidate answer group: result reference; evidence reference; verifier identity; method. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-001" ] }, { "id": "data-assessment-2", "name": "Policy revision", "description": "Candidate answer group: policy revision; trust anchor reference; verification disposition. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-001" ] }, { "id": "data-assessment-3", "name": "Claim time", "description": "Candidate answer group: claim time; result time; freshness limit; expiry. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-001" ] }, { "id": "data-assessment-4", "name": "Scale definition", "description": "Candidate answer group: scale definition; denominator; excluded scope; uncertainty; result label. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-001" ] } ], "artifacts": [ { "id": "artifact-assessment", "name": "Bounded assessment and attestation results record", "description": "Versioned record or reference manifest for this finding with scope, attribution, evidence state and access markings; raw protected evidence stays in its authorized master.", "media_or_form": [ "structured record", "human review view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first, then governed IRI, then adopting-Dimension UUID or ULID. Stable logical record ID and separate immutable revision ID; a timestamp or digest alone is not identity.", "source_refs": [ "SRC-008", "SRC-001" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-response", "name": "Treatment and incident linkage", "description": "Host-scoped context for treatment and incident linkage.", "rationale": "Group related assertions while preserving external masters and distinct evidence states.", "source_refs": [ "SRC-002", "SRC-006", "SRC-007" ], "layers": [ { "id": "layer-remediation", "name": "Remediation evidence", "description": "Keep planned treatment, reported execution and verification separate. Mitigation and accepted risk do not mean fixed; rollback or new configuration can invalidate verification.", "source_refs": [ "SRC-007", "SRC-002" ], "findings": [ { "id": "finding-treatment", "name": "Treatment status and verification", "description": "Keep planned treatment, reported execution and verification separate. Mitigation and accepted risk do not mean fixed; rollback or new configuration can invalidate verification.", "source_refs": [ "SRC-007", "SRC-002" ], "questions": [ { "id": "question-treatment-1", "text": "Which external change or treatment record addresses this local exposure?", "kind": "process", "answer_data": [ "data-treatment-1: change reference; intended treatment; target host revision" ] }, { "id": "question-treatment-2", "text": "What was planned, reported applied and independently checked for this treatment?", "kind": "state", "answer_data": [ "data-treatment-2: plan state; execution report reference; verification state" ] }, { "id": "question-treatment-3", "text": "Which scoped verification result supports a claim that remediation succeeded?", "kind": "evidence", "answer_data": [ "data-treatment-3: verification reference; test scope; assessed revision; result time" ] }, { "id": "question-treatment-4", "text": "What unresolved failure, deferral or rollback prevents closing the exposure?", "kind": "exception", "answer_data": [ "data-treatment-4: failure reason; exception decision reference; rollback reference; next review" ] } ], "data_elements": [ { "id": "data-treatment-1", "name": "Change reference", "description": "Candidate answer group: change reference; intended treatment; target host revision. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-002" ] }, { "id": "data-treatment-2", "name": "Plan state", "description": "Candidate answer group: plan state; execution report reference; verification state. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-002" ] }, { "id": "data-treatment-3", "name": "Verification reference", "description": "Candidate answer group: verification reference; test scope; assessed revision; result time. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-002" ] }, { "id": "data-treatment-4", "name": "Failure reason", "description": "Candidate answer group: failure reason; exception decision reference; rollback reference; next review. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-002" ] } ], "artifacts": [ { "id": "artifact-treatment", "name": "Treatment status and verification record", "description": "Versioned record or reference manifest for this finding with scope, attribution, evidence state and access markings; raw protected evidence stays in its authorized master.", "media_or_form": [ "structured record", "human review view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first, then governed IRI, then adopting-Dimension UUID or ULID. Stable logical record ID and separate immutable revision ID; a timestamp or digest alone is not identity.", "source_refs": [ "SRC-007", "SRC-002" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-incident", "name": "Incident impact linkage", "description": "Associate the host with a separately mastered cyber incident and record the provenance of impact and recovery assertions. Declaration, containment, notification and closure belong to authorized external workflows.", "source_refs": [ "SRC-006" ], "findings": [ { "id": "finding-incident", "name": "Incident and recovery context", "description": "Associate the host with a separately mastered cyber incident and record the provenance of impact and recovery assertions. Declaration, containment, notification and closure belong to authorized external workflows.", "source_refs": [ "SRC-006" ], "questions": [ { "id": "question-incident-1", "text": "Which incident master and declaration evidence establish this host association?", "kind": "event", "answer_data": [ "data-incident-1: incident reference; declaring authority reference; association evidence" ] }, { "id": "question-incident-2", "text": "Which impacts are confirmed, suspected or still unknown for this subject?", "kind": "quality", "answer_data": [ "data-incident-2: impact assertion; confidence; affected-scope reference; contrary evidence" ] }, { "id": "question-incident-3", "text": "What externally approved recovery evidence supports the current host posture?", "kind": "evidence", "answer_data": [ "data-incident-3: recovery result reference; verified host revision; approval reference" ] }, { "id": "question-incident-4", "text": "Which response, communication or access-breach case needs a distinct linked record?", "kind": "relationship", "answer_data": [ "data-incident-4: response reference; communication obligation reference; access-case reference; applicability rationale" ] } ], "data_elements": [ { "id": "data-incident-1", "name": "Incident reference", "description": "Candidate answer group: incident reference; declaring authority reference; association evidence. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "data-incident-2", "name": "Impact assertion", "description": "Candidate answer group: impact assertion; confidence; affected-scope reference; contrary evidence. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "data-incident-3", "name": "Recovery result reference", "description": "Candidate answer group: recovery result reference; verified host revision; approval reference. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "data-incident-4", "name": "Response reference", "description": "Candidate answer group: response reference; communication obligation reference; access-case reference; applicability rationale. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "artifact-incident", "name": "Incident and recovery context record", "description": "Versioned record or reference manifest for this finding with scope, attribution, evidence state and access markings; raw protected evidence stays in its authorized master.", "media_or_form": [ "structured record", "human review view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first, then governed IRI, then adopting-Dimension UUID or ULID. Stable logical record ID and separate immutable revision ID; a timestamp or digest alone is not identity.", "source_refs": [ "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bundle-continuity", "name": "Disclosure and record continuity", "description": "Host-scoped context for disclosure and record continuity.", "rationale": "Group related assertions while preserving external masters and distinct evidence states.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-008" ], "layers": [ { "id": "layer-sharing", "name": "Disclosure views", "description": "Describe proposed audience-specific views of existing security records. A public advisory must not automatically expose private deployment facts; preparing a view does not authorize transmission.", "source_refs": [ "SRC-005", "SRC-004", "SRC-006" ], "findings": [ { "id": "finding-disclosure", "name": "Controlled security projections", "description": "Describe proposed audience-specific views of existing security records. A public advisory must not automatically expose private deployment facts; preparing a view does not authorize transmission.", "source_refs": [ "SRC-005", "SRC-004", "SRC-006" ], "questions": [ { "id": "question-disclosure-1", "text": "Which identifiable systems or personal data must be suppressed from this audience view?", "kind": "privacy", "answer_data": [ "data-disclosure-1: sensitive fields; audience; minimization basis; redaction decision" ] }, { "id": "question-disclosure-2", "text": "What source marking and additional permissions bound onward disclosure?", "kind": "access", "answer_data": [ "data-disclosure-2: TLP version and label; additional restrictions; permission reference" ] }, { "id": "question-disclosure-3", "text": "Who may approve release or lift an embargo for this particular projection?", "kind": "authority", "answer_data": [ "data-disclosure-3: release authority reference; embargo conditions; approval state" ] }, { "id": "question-disclosure-4", "text": "How is the derived view checked for residual identifiers and conflicting markings?", "kind": "validation", "answer_data": [ "data-disclosure-4: projection policy version; review result; denied fields; unresolved marking conflict" ] } ], "data_elements": [ { "id": "data-disclosure-1", "name": "Sensitive fields", "description": "Candidate answer group: sensitive fields; audience; minimization basis; redaction decision. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-004", "SRC-006" ] }, { "id": "data-disclosure-2", "name": "Tlp version and label", "description": "Candidate answer group: TLP version and label; additional restrictions; permission reference. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-004", "SRC-006" ] }, { "id": "data-disclosure-3", "name": "Release authority reference", "description": "Candidate answer group: release authority reference; embargo conditions; approval state. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-004", "SRC-006" ] }, { "id": "data-disclosure-4", "name": "Projection policy version", "description": "Candidate answer group: projection policy version; review result; denied fields; unresolved marking conflict. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-004", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-disclosure", "name": "Controlled security projections record", "description": "Versioned record or reference manifest for this finding with scope, attribution, evidence state and access markings; raw protected evidence stays in its authorized master.", "media_or_form": [ "structured record", "human review view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first, then governed IRI, then adopting-Dimension UUID or ULID. Stable logical record ID and separate immutable revision ID; a timestamp or digest alone is not identity.", "source_refs": [ "SRC-005", "SRC-004", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "layer-history", "name": "Record continuity", "description": "Preserve correction lineage, bounded evidence access and semantic loss notes across projections. The adopting retention policy controls payload disposal; an evidence digest cannot replace required review.", "source_refs": [ "SRC-004", "SRC-008", "SRC-006" ], "findings": [ { "id": "finding-continuity", "name": "Revision, retention and exchange", "description": "Preserve correction lineage, bounded evidence access and semantic loss notes across projections. The adopting retention policy controls payload disposal; an evidence digest cannot replace required review.", "source_refs": [ "SRC-004", "SRC-008", "SRC-006" ], "questions": [ { "id": "question-continuity-1", "text": "Which prior assertion does a correction supersede while preserving its original attribution?", "kind": "provenance", "answer_data": [ "data-continuity-1: predecessor reference; correction reason; actor; revision digest" ] }, { "id": "question-continuity-2", "text": "Which retention schedule or hold governs local security evidence and its references?", "kind": "retention", "answer_data": [ "data-continuity-2: retention-policy reference; hold scope; disposition authority" ] }, { "id": "question-continuity-3", "text": "Which versioned exchange binding preserves identifiers, unknown states and markings?", "kind": "interoperability", "answer_data": [ "data-continuity-3: binding version; mapped fields; unmapped concepts; round-trip loss report" ] }, { "id": "question-continuity-4", "text": "What remains resolvable when a host or evidence payload is retired or lawfully erased?", "kind": "lifecycle", "answer_data": [ "data-continuity-4: retirement state; successor reference; minimal lawful tombstone; access revocation" ] } ], "data_elements": [ { "id": "data-continuity-1", "name": "Predecessor reference", "description": "Candidate answer group: predecessor reference; correction reason; actor; revision digest. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-008", "SRC-006" ] }, { "id": "data-continuity-2", "name": "Retention-policy reference", "description": "Candidate answer group: retention-policy reference; hold scope; disposition authority. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-008", "SRC-006" ] }, { "id": "data-continuity-3", "name": "Binding version", "description": "Candidate answer group: binding version; mapped fields; unmapped concepts; round-trip loss report. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-008", "SRC-006" ] }, { "id": "data-continuity-4", "name": "Retirement state", "description": "Candidate answer group: retirement state; successor reference; minimal lawful tombstone; access revocation. Nested schema and required subfields require an adoption profile; unknown is explicit, never a successful result.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-008", "SRC-006" ] } ], "artifacts": [ { "id": "artifact-continuity", "name": "Revision, retention and exchange record", "description": "Versioned record or reference manifest for this finding with scope, attribution, evidence state and access markings; raw protected evidence stays in its authorized master.", "media_or_form": [ "structured record", "human review view" ], "serial": true, "identity_strategy": "Authoritative master-system identifier first, then governed IRI, then adopting-Dimension UUID or ULID. Stable logical record ID and separate immutable revision ID; a timestamp or digest alone is not identity.", "source_refs": [ "SRC-004", "SRC-008", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "function-attach", "name": "Bind host context", "description": "Proposed local operation, not implemented. Creates only the local security attachment; ambiguous host binding is refused.", "inputs": [ "host and inventory references", "scope", "mandate" ], "outputs": [ "new local attachment or refused binding", "Refusal or unresolved-input report" ], "preconditions": [ "Authorized role for this host and operation", "Pinned input references and expected current revision", "Applicable privacy, retention and disclosure policy available; unresolved authority refuses mutation" ], "effects": [ "Creates only the local security attachment; ambiguous host binding is refused.", "Append a versioned local change record under retention policy. Correction supersedes prior assertions; external side effects require separately authorized workflows." ], "source_refs": [ "SRC-001" ] }, { "id": "function-applicability", "name": "Record applicability assertion", "description": "Proposed local operation, not implemented. Records the submitted assessment; no automatic vulnerability detection or clearance.", "inputs": [ "vulnerability and advisory references", "host revision", "supporting and contrary evidence" ], "outputs": [ "attributed assertion revision with unknown or contested state where needed", "Refusal or unresolved-input report" ], "preconditions": [ "Authorized role for this host and operation", "Pinned input references and expected current revision", "Applicable privacy, retention and disclosure policy available; unresolved authority refuses mutation" ], "effects": [ "Records the submitted assessment; no automatic vulnerability detection or clearance.", "Append a versioned local change record under retention policy. Correction supersedes prior assertions; external side effects require separately authorized workflows." ], "source_refs": [ "SRC-002" ] }, { "id": "function-interpretation", "name": "Link threat interpretation", "description": "Proposed local operation, not implemented. Links existing evidence; does not run detection, attribute an actor as fact or declare compromise.", "inputs": [ "indicator or threat revision", "observation references", "confidence and validity" ], "outputs": [ "local interpretation revision or rejected link", "Refusal or unresolved-input report" ], "preconditions": [ "Authorized role for this host and operation", "Pinned input references and expected current revision", "Applicable privacy, retention and disclosure policy available; unresolved authority refuses mutation" ], "effects": [ "Links existing evidence; does not run detection, attribute an actor as fact or declare compromise.", "Append a versioned local change record under retention policy. Correction supersedes prior assertions; external side effects require separately authorized workflows." ], "source_refs": [ "SRC-004" ] }, { "id": "function-assurance", "name": "Record assurance evidence", "description": "Proposed local operation, not implemented. Records received evidence disposition; does not perform cryptographic attestation or certify security.", "inputs": [ "baseline reference", "result reference", "verifier", "freshness and scope" ], "outputs": [ "qualified evidence binding or stale/unverifiable result flag", "Refusal or unresolved-input report" ], "preconditions": [ "Authorized role for this host and operation", "Pinned input references and expected current revision", "Applicable privacy, retention and disclosure policy available; unresolved authority refuses mutation" ], "effects": [ "Records received evidence disposition; does not perform cryptographic attestation or certify security.", "Append a versioned local change record under retention policy. Correction supersedes prior assertions; external side effects require separately authorized workflows." ], "source_refs": [ "SRC-008", "SRC-001" ] }, { "id": "function-treatment", "name": "Reconcile treatment references", "description": "Proposed local operation, not implemented. Updates local references only; does not install, contain, recover or close an external incident.", "inputs": [ "change report", "verification result", "assessed host revision", "incident link if applicable" ], "outputs": [ "separate treatment and verification states with unresolved gaps", "Refusal or unresolved-input report" ], "preconditions": [ "Authorized role for this host and operation", "Pinned input references and expected current revision", "Applicable privacy, retention and disclosure policy available; unresolved authority refuses mutation" ], "effects": [ "Updates local references only; does not install, contain, recover or close an external incident.", "Append a versioned local change record under retention policy. Correction supersedes prior assertions; external side effects require separately authorized workflows." ], "source_refs": [ "SRC-007", "SRC-006" ] }, { "id": "function-projection", "name": "Prepare restricted view", "description": "Proposed local operation, not implemented. Produces a local candidate view only; no transmission, permission expansion or embargo release.", "inputs": [ "recipient scope", "applicable markings", "local revision", "release-policy reference" ], "outputs": [ "local redacted draft view and review checklist, or denied projection", "Refusal or unresolved-input report" ], "preconditions": [ "Authorized role for this host and operation", "Pinned input references and expected current revision", "Applicable privacy, retention and disclosure policy available; unresolved authority refuses mutation" ], "effects": [ "Produces a local candidate view only; no transmission, permission expansion or embargo release.", "Append a versioned local change record under retention policy. Correction supersedes prior assertions; external side effects require separately authorized workflows." ], "source_refs": [ "SRC-005" ] } ], "composition": [ { "target": "WM-SFT-002", "relation": "REFERENCE", "purpose": "Software System / Business Application is a candidate host master; local attachment does not duplicate system inventory or lifecycle.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "WM-OBJ-008", "relation": "REFERENCE", "purpose": "Device / Sensor / Compute HW is an alternative host master; physical properties and device control stay external.", "required": false, "source_refs": [ "SRC-001", "SRC-008" ] }, { "target": "WM-SFT-018", "relation": "REFERENCE", "purpose": "Network / Endpoint may provide a protected endpoint reference; address, reachability and topology authority stay external.", "required": false, "source_refs": [ "SRC-001", "SRC-008" ] }, { "target": "WM-SFT-001", "relation": "REFERENCE", "purpose": "Software Product is a product reference, not a replacement for a concrete deployed host. Resolve legacy N4 ambiguity explicitly.", "required": false, "source_refs": [ "SRC-002" ] }, { "target": "WM-SFT-006", "relation": "REFERENCE", "purpose": "Vulnerability Record owns vulnerability identity, advisory lifecycle and public/private identifiers; carry scoped local applicability only.", "required": false, "source_refs": [ "SRC-002", "SRC-003" ] }, { "target": "WM-ACT-020", "relation": "REFERENCE", "purpose": "Cyber Incident owns the incident record and declaration lifecycle; carry host association and attributed impact references only.", "required": false, "source_refs": [ "SRC-006" ] }, { "target": "WM-ACT-042", "relation": "REFERENCE", "purpose": "Incident Response owns operational response, containment and recovery execution; local functions cannot initiate these operations.", "required": false, "source_refs": [ "SRC-006" ] }, { "target": "WM-XCT-027", "relation": "REFERENCE", "purpose": "Risk / Control owns generic risk and control bindings and acceptance decisions; carry security-specific baseline and decision references.", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] }, { "target": "WM-XCT-001", "relation": "REFERENCE", "purpose": "Ownership / Stewardship supplies responsibility and delegation references; legal title and ownership transfer remain external.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "WM-XCT-002", "relation": "REFERENCE", "purpose": "Access Contract / Consent supplies scoped authorization; security evidence and TLP markings do not issue grants.", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] }, { "target": "WM-XCT-004", "relation": "REFERENCE", "purpose": "Access Audit retains authoritative access-event records; link evidence without owning audit-trail semantics.", "required": false, "source_refs": [ "SRC-001", "SRC-006" ] }, { "target": "WM-XCT-007", "relation": "REFERENCE", "purpose": "Access Breach / Enforcement owns distinct access-violation cases; cyber compromise is not automatically an access-contract violation.", "required": false, "source_refs": [ "SRC-006" ] }, { "target": "WM-SFT-017", "relation": "REFERENCE", "purpose": "Telemetry / Operational Signal owns observations and collection context; local interpretation does not perform detection or redefine raw telemetry.", "required": false, "source_refs": [ "SRC-004" ] }, { "target": "WM-XCT-035", "relation": "REFERENCE", "purpose": "Retention / Disposition supplies retention and hold policy bindings; destruction execution remains in its authorized external process.", "required": false, "source_refs": [ "SRC-006" ] }, { "target": "NIST CSF 2.0", "relation": "ALIGN", "purpose": "Conceptual mapping to selected outcomes and profiles; no blanket conformance or certification.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "OASIS CSAF 2.0", "relation": "ALIGN", "purpose": "Advisory and product-status mapping only; pin errata and validate an actual exchange before claiming conformance.", "required": false, "source_refs": [ "SRC-002" ] }, { "target": "STIX 2.1", "relation": "ALIGN", "purpose": "Selected threat, observation and marking concepts only; no lossless implementation claimed.", "required": false, "source_refs": [ "SRC-004" ] }, { "target": "CVSS 4.0", "relation": "ALIGN", "purpose": "Carry attributed severity vectors and metric-group labels; no score calculator or risk engine.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "TLP 2.0", "relation": "ALIGN", "purpose": "Record sharing restrictions without replacing applicable access or legal rules.", "required": false, "source_refs": [ "SRC-005" ] }, { "target": "RFC 9334", "relation": "ALIGN", "purpose": "Conceptual separation of received evidence and results from appraisal and enforcement; no attestation protocol implementation.", "required": false, "source_refs": [ "SRC-008" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Adopting system steward role and accountable security coordinator with scoped delegation", "Host master resolver, inventory revision binding and tenant boundary", "Versioned security, disclosure, privacy and retention policies with authority references", "Profile-defined unknown states, freshness limits and review responsibilities" ], "namespace_guidance": "Use a governed namespace for host attachments and stable local assertion IDs. Namespace ownership does not imply host ownership or access. Keep logical identity separate from revisions and payload hashes.", "registry_links": [ "vr.wm-xct-019", "Resolve every candidate model ID and pin an accepted version before use; no compulsory child models are declared." ] }, "canon_and_patch": { "canonicalization_rules": [ "Retain host identity, source attribution, original states and explicit unknown values across projections. No global secure boolean is inferred.", "Normalize timestamps and identifiers without conflating object modification, event occurrence, observation and ingestion." ], "patch_rules": [ "Use expected-revision checks and immutable correction links; preserve contrary claims under applicable retention policy.", "A change to host scope, indicator revision, appraisal policy or baseline invalidates affected conclusions until reviewed." ], "compatibility_rules": [ "Version mappings explicitly; reject unsupported state or marking mappings instead of silently dropping them.", "Legacy wildcard imports and conformance labels do not migrate as authority. A narrowed reference replaces a legacy owned object only with an explicit identity mapping." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier", "Governed global identifier or IRI", "UUID or ULID assigned by the adopting Dimension" ], "timestamp_rule": "Use RFC 3339 with seconds and an explicit offset or Z. Preserve event time, assessment time, observation time and ingestion time separately; record uncertain time as qualified data.", "serial_naming_rule": "Use stable logical IDs with separate monotonically ordered revision tokens. Filenames may display dates but dates do not supply identity.", "integrity_rule": "Record digest algorithm, payload digest, source, retrieval time and any signature-validation result. Hash equality proves byte equality only; trust, truth and freshness need separate evidence. Do not place secrets in evidence indexes." }, "policies": [ "Keep public vulnerability information separate from tenant-sensitive applicability and deployment details.", "Source markings and embargo terms constrain onward use in addition to applicable permissions and privacy rules. TLP does not itself grant access.", "Unknown, not assessed, stale, disputed, not affected, mitigated and fixed must remain distinct.", "Agents may prepare local records and views under scoped authority; external scanning, patching, containment, notification and release require their own authorized workflows. No operational attack material is part of this model.", "Specialist and legal profile review determines sector obligations and reporting deadlines; no universal time limit is asserted." ], "crud": { "read": [ "Resolve tenant and host scope before loading findings or evidence. Return authorized summaries when payload access is denied." ], "create": [ "Require a resolvable host, declared scope and authorized steward. Record provenance, review state and unknowns for submitted assertions." ], "update": [ "Require expected revision and current authority. Supersede incorrect assertions with a reason; propagate staleness to dependent views without modifying source masters." ], "delete": [ "Retire local attachments and resolve successors. Apply retention schedules, legal holds and lawful payload erasure through the adopting policy or referenced Retention / Disposition workflow; preserve only a lawful minimal tombstone.", "Deleting a local reference does not delete an incident, advisory, telemetry master or its independently controlled evidence." ] }, "roles": [ { "name": "System steward", "responsibilities": [ "Accountable for host binding, scope and delegation." ] }, { "name": "Security analyst", "responsibilities": [ "Submits evidence-qualified assertions and preserves uncertainty." ] }, { "name": "Security reviewer", "responsibilities": [ "Reviews applicability, freshness and verification claims independently of their submitter where policy requires." ] }, { "name": "Response liaison", "responsibilities": [ "Links authorized incident and recovery records without executing their workflows." ] }, { "name": "Disclosure and privacy reviewer", "responsibilities": [ "Approves candidate recipient views and retention decisions within an explicit mandate." ] } ], "access": { "default_rule": "Deny by default; grant least privilege by tenant, host, purpose, role and evidence sensitivity. A visible finding never implies permission to fetch its artifacts.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Emergency access requires a separately recorded, time-bounded authority and retrospective review; it does not automatically remove source sharing restrictions." ], "audit_requirements": [ "Reference authoritative access audit events for reads, edits, exports, denied requests and exceptional use. Keep local revision provenance without duplicating the audit master." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL", "Host scope", "Research holds" ], "read_order": [ "Nearest owner and Dimension policy", "AGENTS.md", "spec.yaml and publication holds", "Pinned host and related model specifications", "Authorized source evidence and profile-specific validation rules" ] } }, "coverage": { "claim": "Source-grounded proposed host-attached Cyber Integrity mixin with distinct local assertions and external masters. A separate frozen no-tools Codex self-audit found no critical conflicts. Independent review, source/version verification, specialist adoption profiles and executable conformance remain holds; this is a noncanonical reviewable draft.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Host plus scope and stable assertion identities; external masters retain identity." }, { "dimension": "lifecycle", "status": "covered", "notes": "Attachment succession, assertion correction and treatment state separation." }, { "dimension": "relationships", "status": "covered", "notes": "Candidate sibling references and standards alignments; no duplicated external workflows." }, { "dimension": "temporal", "status": "covered", "notes": "Event, assertion, observation and ingestion time plus freshness and invalidation." }, { "dimension": "provenance", "status": "covered", "notes": "Producer, revision, verifier, method and contrary evidence references." }, { "dimension": "ownership", "status": "covered", "notes": "Role archetypes and bounded delegation; no organization named as model owner." }, { "dimension": "validation", "status": "gap", "notes": "Research schema validation only; nested instance schemas and executable fixtures remain open." }, { "dimension": "access", "status": "covered", "notes": "Deny-by-default views and artifact-level checks with source markings." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Adopting retention schedule, holds, lawful payload erasure and minimal tombstones." }, { "dimension": "interoperability", "status": "gap", "notes": "Conceptual CSAF, STIX, CVSS, TLP and RATS mappings; no implemented conformance." }, { "dimension": "direct properties", "status": "covered", "notes": "Scope, state, criticality, confidence and freshness are nonphysical properties of the attachment." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Evidence distinguishes a reported weakness, local exposure, signal match and declared incident." }, { "dimension": "capabilities and actions", "status": "covered", "notes": "Six proposed local record operations with authority preconditions and refusal paths." }, { "dimension": "physical properties", "status": "not-applicable", "notes": "The abstract mixin has no mass or geometry; host models own physical properties." }, { "dimension": "sector coverage", "status": "gap", "notes": "OT, safety-critical, embedded, cloud and supply-chain profiles require specialist validation." } ], "known_omissions": [ "Independent external review absent under the single-provider waiver.", "Direct HTTP checks not attempted under owner-reported sandbox restriction; selected browser readings do not verify all errata or current versions.", "Nested instance schemas, stable neighbor version pins, exchange conformance and executable adversarial fixtures remain incomplete.", "Jurisdictional obligations, disclosure licensing, operational safety and specialized sector profiles require adopting expert review." ], "conflicts": [], "regional_assumptions": [ "Cited sources provide technical guidance and exchange concepts, not a universal legal regime.", "Adopting jurisdiction and sector determine reporting duties, evidence retention and authority.", "NIST guidance is used as a conceptual source without importing federal mandates." ], "adversarial_checks": [ "A supplier fixed assertion does not prove the local host received or verified the fix.", "A signal match and high confidence do not prove compromise or actor identity.", "A signed or recent attestation result does not prove every host property or authorize access.", "TLP:CLEAR does not remove personal-data or other applicable release restrictions.", "Legacy N4 and M8 labels must not silently select a wrong modern host master.", "No source or provider agreement is inferred from a schema-valid local result." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "mixin", "status": "accepted", "rationale": "The local record attaches security context to one externally mastered host and scope. Stable assertion and revision identity does not transfer ownership of assets, vulnerabilities, incidents, responses, generic controls or enforcement. A host is required by creation rules even though the alternative host-class composition links are individually optional." }, "decisions": [ { "concept": "Host-attached boundary", "disposition": "accepted", "rationale": "The six bundles consistently describe context for an external host. A standalone security aggregate or operational security engine would exceed the declared boundary." }, { "concept": "Legacy alias reconciliation", "disposition": "qualified", "rationale": "The frozen material exposes conflicting N4/M8 descriptions and a shared N4 alias. Modern model IDs and actual host kind are required; alias-only migration is rejected." }, { "concept": "Composition authority", "disposition": "candidate only", "rationale": "No incoming or outgoing ledger row exists for this model at freeze. Proposed sibling links remain reviewable adoption bindings and do not establish new registry edges." }, { "concept": "Vulnerability and incident masters", "disposition": "delegated", "rationale": "Public or private vulnerability records and cyber incidents retain separate masters. This mixin records applicability and host associations without copying source lifecycle or operational response." }, { "concept": "Exposure and treatment states", "disposition": "accepted", "rationale": "Supplier assertions, inventory matching, local applicability, reported installation and verification are distinct. Unknown, mitigated and accepted risk cannot silently become fixed." }, { "concept": "Severity and priority", "disposition": "separated", "rationale": "Attributed score version, vector and metric groups are inputs. Local priority and residual risk acceptance require separate authority and do not follow automatically from severity." }, { "concept": "Threat and observation", "disposition": "qualified", "rationale": "Threat relevance and indicator interpretation retain provenance, uncertainty, time and corrections. An observation or match cannot alone establish compromise or actor identity." }, { "concept": "Integrity and posture evidence", "disposition": "bounded", "rationale": "Received assessment and attestation results are scoped by verifier, policy, evidence and freshness. The proposed record operation does not implement appraisal or grant access." }, { "concept": "Function authority", "disposition": "accepted as proposed", "rationale": "All six functions operate on local records with role and expected-revision checks and refusal results. They do not scan, install, contain, notify, disclose or close incidents." }, { "concept": "Disclosure and privacy", "disposition": "accepted with constraints", "rationale": "Recipient views preserve source markings and additional restrictions. Public advisory content does not authorize disclosure of private deployments, and view preparation is not transmission." }, { "concept": "Retention and correction", "disposition": "policy-bound", "rationale": "Correction lineage is compatible with lawful payload erasure, holds and minimal tombstones. Local reference deletion has no automatic effect on external masters." }, { "concept": "Instance and exchange conformance", "disposition": "deferred", "rationale": "Optional candidate answer groups do not enforce nested instance requirements or conditional host binding. Conceptual alignments need pinned profiles, mappings and executable fixtures before use." }, { "concept": "Source and independent review limits", "disposition": "held", "rationale": "Selected browser readings provide conceptual evidence only. Direct HTTP is unmeasured, errata and applicability are not fully verified, and this local self-audit is not independent external review." } ], "publicationHolds": [ "Independent external review is absent. Claude and Grok were skipped with zero attempts under the owner-authorized single-provider waiver; this separate local Codex no-tools self-audit does not replace a second provider.", "Source and version verification remains incomplete. Direct HTTP checks were not attempted under the owner-reported sandbox restriction; no HTTP status was measured. Selected browser readings do not establish complete latest-version, errata, licensing or applicability verification. The coordinator must run check_sources.py outside the sandbox and review substantive support separately.", "Qualified adopting-profile review is required for legal obligations, disclosure authority, privacy, retention and operational safety, including specialized cloud, embedded, OT and safety-critical contexts. No universal reporting deadline or security certification is claimed.", "Executable conformance remains incomplete: nested instance schemas, conditional host-binding rules, pinned sibling versions, legacy identity migration, standards exchange mappings and adversarial instance fixtures require implementation and validation. Proposed local functions are not implemented runtime operations.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Restore independent external review before canonical or publishable-draft promotion.", "Complete source reachability, version and errata checks with substantive claim review, including a pinned CSAF errata policy.", "Develop adopting profiles and executable cases for ambiguous hosts, conflicting advisories, stale attestation, indicator false positives, rollback, withheld evidence, privacy and lawful erasure.", "Reconcile and pin external model versions and legacy host identities with the coordinator before instance migration." ] }, "statistics": { "sources": 8, "bundles": 6, "layers": 12, "findings": 12, "questions": 48, "artifacts": 12, "functions": 6 } }