# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-09-03T09:18:19Z", "synthesisSha256": "5e6f59f2a5b543d67e8ca1dae94147b8a222fcdf71a897c47d1bd351be687e3a", "providerMode": "single-provider-waiver", "providers": [ "Claude" ], "waivedProviders": [ "Grok" ] }, "metaModel": { "id": "WM-XCT-027", "registryId": "vr.wm-xct-027", "name": "Risk / Control", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "mixin", "family": "World Models", "category": "Cross-cutting context", "industry": [ "Cross-industry" ], "domain": [ "XCT.RSK" ], "tags": [ "risk", "control", "xct.rsk" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-xct-027-risk-control/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-xct-027", "model": { "registry_id": "vr.wm-xct-027", "model_id": "WM-XCT-027", "name": "Risk / Control", "entry_kind": "mixin", "purpose": "Provide an embeddable field group that binds one risk assessment context to a referenced risk, links it to referenced controls and their cited effectiveness determinations, and explains the residual position against referenced appetite or tolerance, without owning the risk entity, the control register or any treatment workflow.", "scope_statement": "WM-XCT-027 is a mixin: a reusable set of fields attached to a host record so that record can carry a defensible, revision-pinned risk assessment context. It owns the reference and binding fields (risk reference and exact revision, objective/asset/process/context anchors, source-event-consequence anchors), the pinned assessment frame (category and taxonomy pins, scope, exclusions, time horizon, criteria set, method and technique with versions, expression mode), the estimate slots (likelihood and consequence dimension declarations, inherent estimate with its exclusion statement, residual estimate with change explanation), the evidential basis (assumptions, information sources, data currency, estimation basis kind, uncertainty and confidence qualification), the control-linkage references (relied-on control references and the effectiveness determinations cited for them), the governance stamps at assessment-context level (assessor, context owner, reviewer and acceptance-decision references, review-due timing), and the comparability surface (comparability verdicts, aggregation caveats, scenario dependence). It does not evaluate controls, does not run assessments, does not set or enforce appetite, does not grant acceptance or authorization, and does not define the internals of any pinned technique. Storage and interface are projections: the same field semantics must survive JSON, YAML, Markdown, HTML, Git, MCP and MongoDB representations.", "in_scope": [ "Reference to one risk or opportunity entity together with an exact revision or version pin of the assessed statement.", "Anchor references the assessment is scoped against: objectives, assets, processes, organizational units, contextual conditions and applicable jurisdiction or site.", "Causal-chain references: risk source or threat source, the event or event class quantified, and the consequences included or explicitly excluded.", "Category values with an explicit taxonomy scheme identifier and version pin.", "Assessment scope statement, exclusions, likelihood time horizon, as-of time of the assessed state, recording time and validity or review-due time.", "Criteria set, assessment method and technique pins with their versions, plus the expression mode (qualitative, ordinal, semi-quantitative, quantitative, probabilistic, scenario-based).", "Likelihood and consequence dimension declarations with units, scale references, distribution parameters and support for multi-dimensional impact.", "Inherent (pre-control) estimate together with an explicit statement of what 'inherent' excluded in this context, or a documented ground for omitting it.", "Assumptions, information sources, data currency, estimation basis kind, analysis constraints and identification of critical assumptions.", "Uncertainty representation, confidence or data-quality grading, unmeasurable aspects and precision caveats.", "Control linkage: references to the controls relied on and to the effectiveness determinations cited for them, produced by the owning control assessment model.", "Residual (post-control) estimate, the characterization state marking it as adjusted rather than initial, the changed-dimension set and the explanation of change.", "References to the appetite or tolerance statement in force and the recorded outcome of comparing the residual estimate against it.", "Assessment-context governance stamps: assessor, context owner, reviewer and acceptance-decision references, and review-due timing.", "Comparability verdicts, mismatched-pin reporting, aggregation caveats, scenario identifiers and reference-case designation." ], "out_of_scope": [ "The risk or opportunity entity itself: its identity, statement, status, register membership and lifecycle transitions.", "The control register: control identity, design, implementation records, control ownership and control lifecycle.", "Evaluation or testing of control design or operating effectiveness and the production of effectiveness determinations.", "Risk treatment options, treatment plans, milestones, remediation tracking, plan-of-action records and closure.", "Incidents, realized loss events, issues, near misses and post-event investigation.", "Objective, asset, process and organizational-unit master data.", "Setting, approving, publishing or enforcing risk appetite and tolerance thresholds.", "Granting acceptance, authorization or exception decisions on a residual position.", "Assessment execution, observation capture and evidence collection procedures.", "Audit-trail storage, log integrity and retention execution.", "Technique internals and algorithm semantics of any pinned method, including simulation, fault-tree, event-tree and Bayesian computation.", "Any fixed numeric risk matrix, default likelihood band, default impact scale or universal scoring rule.", "Runtime evaluation or enforcement of thresholds by a policy engine." ], "boundary_notes": [ { "neighbor": "WM-KNW-015 risk / opportunity entity and lifecycle", "distinction": "The parent model owns risk identity, statement, register status and lifecycle. This mixin attaches one assessment context to a pinned revision of that entity, carries no risk status transitions, and marks its own binding as stale when the pinned revision is superseded upstream.", "source_refs": [ "SRC-002", "SRC-007" ] }, { "neighbor": "Control implementation records and control assessment determinations", "distinction": "This mixin stores control references and cites effectiveness determinations by reference; determining, testing or re-opening effectiveness belongs to the control assessment model, where assessment objectives, methods and satisfied / other-than-satisfied determinations are produced.", "source_refs": [ "SRC-005", "SRC-006" ] }, { "neighbor": "Risk treatment, remediation and plan-of-action records", "distinction": "A residual estimate is an input to treatment planning. Treatment option selection, milestones, scheduling, cost tracking and closure are owned by the treatment model and are not represented here.", "source_refs": [ "SRC-002", "SRC-005" ] }, { "neighbor": "Assessment execution, observation and evidence records", "distinction": "Observations and evidence are cited as the basis of an estimate. Collecting evidence, executing assessment procedures and logging assessment results are owned by the assessment-results model; this mixin holds references and a basis statement only.", "source_refs": [ "SRC-005", "SRC-006" ] }, { "neighbor": "Risk appetite and tolerance governance", "distinction": "The mixin references a versioned tolerance statement and records the comparison outcome. Determining appetite, approving tolerance lines and enforcing them are enterprise governance acts held elsewhere.", "source_refs": [ "SRC-003", "SRC-007", "SRC-010" ] }, { "neighbor": "Acceptance, authorization and exception decisions", "distinction": "Accepting a residual position is an authorization act performed by a designated official and recorded in an authorization or decision model. This mixin carries only a reference to that decision and never grants, derives or enforces it.", "source_refs": [ "SRC-011", "SRC-012" ] }, { "neighbor": "Incident, loss event and issue records", "distinction": "A realized event is not an assessment. Loss data may be cited as an information source for an estimate, but event records, their timelines and their consequences are owned by event models.", "source_refs": [ "SRC-001", "SRC-002" ] }, { "neighbor": "Risk assessment technique definitions (IEC 31010 technique catalogue and comparable method registries)", "distinction": "The mixin pins which technique and version were applied and stores the technique's declared outputs. It never restates, parameterizes or re-implements the technique's internal semantics.", "source_refs": [ "SRC-008", "SRC-001" ] }, { "neighbor": "Alternative subject kind: relationship (a first-class risk-to-control association)", "distinction": "Modelling this as a relationship was tested. A relationship entry would give each risk-control link its own identity, which suits relied-on-control attribution. It fails for the rest of the required content: assessment scope, horizon, criteria pin, likelihood and consequence dimensions, uncertainty and appetite comparison are properties of an assessment context attached to a host record, and one context routinely cites many controls and many consequences. The mixin kind is retained; the residual-change attribution is the part a Dimension may legitimately reify as a separate association record without altering this field group.", "source_refs": [ "SRC-005", "SRC-002", "SRC-007" ] } ] }, "sources": [ { "id": "SRC-001", "title": "NIST Special Publication 800-30 Revision 1, Guide for Conducting Risk Assessments", "organization": "National Institute of Standards and Technology (U.S. Department of Commerce)", "url": "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf", "version_or_date": "Revision 1, September 2012", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T00:00:00Z", "relevance": "Primary source for the generic risk model components (threat source, threat event, vulnerability, predisposing condition, likelihood of initiation, likelihood of adverse impact, level of impact), the quantitative / qualitative / semi-quantitative assessment approaches, the threat-, asset-impact- and vulnerability-oriented analysis approaches, the requirement to document purpose, scope, assumptions, constraints, information sources, risk model and analytic approach, and the treatment of residual risk and confidence." }, { "id": "SRC-002", "title": "NIST Interagency Report 8286 Revision 1, Integrating Cybersecurity and Enterprise Risk Management (ERM)", "organization": "National Institute of Standards and Technology (U.S. Department of Commerce)", "url": "https://csrc.nist.gov/pubs/ir/8286/r1/final", "version_or_date": "Revision 1, December 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T00:00:00Z", "relevance": "Primary source for risk register field semantics (risk identifier, description, category, likelihood, impact, exposure, response type, response cost, risk owner, status), the risk detail record as supporting documentation, and the published risk register and risk detail record schemas used as an alignment target." }, { "id": "SRC-003", "title": "NIST Interagency Report 8286A Revision 1, Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management", "organization": "National Institute of Standards and Technology (U.S. Department of Commerce)", "url": "https://csrc.nist.gov/pubs/ir/8286/a/r1/final", "version_or_date": "Revision 1, December 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T00:00:00Z", "relevance": "Primary source for the distinction and use of risk tolerance and risk appetite, for documenting likelihood and impact of threat scenarios in registers, and for the schema-level definition of risk register and risk detail record elements." }, { "id": "SRC-004", "title": "NIST Interagency Report 8286C Revision 1, Staging Cybersecurity Risks for Enterprise Risk Management and Governance Oversight", "organization": "National Institute of Standards and Technology (U.S. Department of Commerce)", "url": "https://csrc.nist.gov/pubs/ir/8286/c/r1/final", "version_or_date": "Revision 1, December 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T00:00:00Z", "relevance": "Primary source for integrating multiple risk registers into an enterprise risk register and risk profile, and therefore for the roll-up and normalization surface that the comparability check in this model constrains." }, { "id": "SRC-005", "title": "OSCAL Assessment Results Model v1.1.2 JSON Format Metaschema Reference", "organization": "National Institute of Standards and Technology (OSCAL project)", "url": "https://pages.nist.gov/OSCAL-Reference/models/v1.1.2/assessment-results/json-definitions/", "version_or_date": "Model version 1.1.2", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T00:00:00Z", "relevance": "Primary machine-readable schema for a risk assembly (uuid, title, description, statement, status, origin, threat-id, characterization, mitigating-factor, deadline, remediation, risk-log, related-observation), for characterization with origin and facets (name, system, value), for mitigating factors linked to implementation statements, and for findings that bind a target objective status to associated risks." }, { "id": "SRC-006", "title": "NIST Special Publication 800-53A Revision 5, Assessing Security and Privacy Controls in Information Systems and Organizations", "organization": "National Institute of Standards and Technology (U.S. Department of Commerce)", "url": "https://csrc.nist.gov/pubs/sp/800/53/a/r5/final", "version_or_date": "Revision 5, January 2022 (patch release 5.2.0, August 2025)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T00:00:00Z", "relevance": "Primary evidence that control assessment procedures, objectives and determinations are owned by a distinct assessment model, establishing the boundary that this mixin cites effectiveness determinations rather than producing them." }, { "id": "SRC-007", "title": "The Orange Book: Management of Risk - Principles and Concepts", "organization": "HM Treasury (United Kingdom)", "url": "https://www.gov.uk/government/publications/orange-book/the-orange-book-management-of-risk-principles-and-concepts", "version_or_date": "Updated 29 July 2026", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T00:00:00Z", "relevance": "Primary public-authority source for risk as the effect of uncertainty on objectives expressed through causes, events and consequences; for risk appetite; for control defined as processes and conditions that maintain or modify risk; for an example category taxonomy; for likelihood-and-consequence analysis against common risk criteria using qualitative, quantitative or combined approaches; and for assurance and three-lines role separation." }, { "id": "SRC-008", "title": "IEC 31010:2019 Risk management - Risk assessment techniques", "organization": "International Electrotechnical Commission (published jointly with ISO)", "url": "https://webstore.iec.ch/en/publication/59809", "version_or_date": "Edition 2.0, 13 June 2019", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T00:00:00Z", "relevance": "Catalogue-level primary confirmation of the standard that governs selection and application of risk assessment techniques under uncertainty, of its joint ISO/IEC status and its relationship to ISO 31000. Used to justify pinning a named technique and version by reference rather than defining technique semantics locally. Full normative text is paywalled and no clause-level claim is made." }, { "id": "SRC-009", "title": "Risk Taxonomy (O-RT), Version 3.1 (Document C251)", "organization": "The Open Group", "url": "https://publications.opengroup.org/c251", "version_or_date": "Version 3.1, 22 May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-03T00:00:00Z", "relevance": "Publication-level primary confirmation of a standard definition and taxonomy for information security risk, companion to the Risk Analysis (O-RA) Standard Version 2.1, used to justify supporting a loss-frequency-and-magnitude decomposition as one pinnable expression mode rather than the universal one. Taxonomy factor detail was not read from the standard text and no clause-level claim is made." }, { "id": "SRC-010", "title": "NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0)", "organization": "National Institute of Standards and Technology (U.S. Department of Commerce)", "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf", "version_or_date": "Version 1.0, January 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T00:00:00Z", "relevance": "Primary source for risk measurement challenges (variable risk tolerance, prioritization difficulty, emergent and hard-to-predict risks, plurality of valid measurement approaches), for documenting risk tolerance explicitly, and for the requirement to document and disclose residual risk to downstream users." }, { "id": "SRC-011", "title": "NIST Special Publication 800-37 Revision 2, Risk Management Framework for Information Systems and Organizations", "organization": "National Institute of Standards and Technology (U.S. Department of Commerce)", "url": "https://csrc.nist.gov/pubs/sp/800/37/r2/final", "version_or_date": "Revision 2, December 2018", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T00:00:00Z", "relevance": "Primary source establishing that control selection, implementation, assessment and authorization are linked but separately accountable processes, and that senior officials make risk decisions on the basis of assessed results, supporting the boundary that acceptance and authorization are referenced rather than owned here." }, { "id": "SRC-012", "title": "Article 9: Risk Management System, Regulation (EU) 2024/1689 (Artificial Intelligence Act)", "organization": "Future of Life Institute (AI Act Explorer republication of the Official Journal text)", "url": "https://artificialintelligenceact.eu/article/9/", "version_or_date": "Regulation (EU) 2024/1689; provisions applicable from 2 December 2027 and 2 August 2028 for the categories referenced", "source_type": "legislation", "primary_source": false, "authority_tier": 3, "accessed_at": "2026-09-03T00:00:00Z", "relevance": "Legislative text accessed via republication because the EUR-Lex host was not retrievable. Used only as a scoped jurisdictional projection evidencing a legal requirement that risk management measures ensure the relevant residual risk associated with each hazard is judged acceptable, and that estimation and evaluation cover both intended use and reasonably foreseeable misuse." }, { "id": "SRC-013", "title": "Guidance on Enterprise Risk Management - Enterprise Risk Management: Integrating with Strategy and Performance", "organization": "Committee of Sponsoring Organizations of the Treadway Commission (COSO)", "url": "https://www.coso.org/guidance-erm", "version_or_date": "2017 framework; guidance page accessed 2026", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-03T00:00:00Z", "relevance": "First-party identification of the 2017 enterprise risk management framework and its freely available executive summary, used to support that a portfolio or profile view and an appetite construct exist as an independent framework family whose vocabulary must be referenced by version rather than assumed. Framework text was not consulted and no principle-level claim is made." }, { "id": "SRC-014", "title": "NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final", "version_or_date": "Revision 5, September 2020, updated through Release 5.2.0 (27 August 2025)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:05:00Z", "relevance": "Authoritative control catalogue structure: control identifiers, base controls and enhancements, parameters, related controls, families, tailoring and baselines; source for revision-pinned control reference semantics." }, { "id": "SRC-015", "title": "OSCAL Implementation Layer: Component Definition Model", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://pages.nist.gov/OSCAL/learn/concepts/layer/implementation/component-definition/", "version_or_date": "OSCAL documentation, last updated 3 March 2025", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:12:00Z", "relevance": "Machine-readable pattern for asserting which controls a component supports: control-implementation with source and set-parameters, implemented-requirement keyed to control-id, capability grouping, responsible roles, and mandatory UUID/last-modified change discipline." }, { "id": "SRC-016", "title": "OSCAL Assessment Layer: Assessment Results Model", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://pages.nist.gov/OSCAL/learn/concepts/layer/assessment/assessment-results/", "version_or_date": "OSCAL documentation, last updated 3 March 2025", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:14:00Z", "relevance": "Structures for reviewed-controls, observations with relevant evidence and collection/expiry, findings carrying objective and implementation status, risks with mitigating factors and remediations, and explicit result expiration." }, { "id": "SRC-017", "title": "OSCAL Implementation Layer: System Security Plan Model", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://pages.nist.gov/OSCAL/learn/concepts/layer/implementation/ssp/", "version_or_date": "OSCAL documentation, last updated 3 March 2025", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:16:00Z", "relevance": "Implemented-requirement and by-component structures, implementation-status values (implemented, partial, planned, not applicable), inherited/provided/responsibility splits and statement-level granularity." }, { "id": "SRC-018", "title": "OSCAL Assessment Layer: Assessment Plan Model", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://pages.nist.gov/OSCAL/learn/concepts/layer/assessment/assessment-plan/", "version_or_date": "OSCAL documentation, last updated 3 March 2025", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:18:00Z", "relevance": "Control selection and objective selection for scoping, assessment subjects and assets, and task timing expressed on-date, within-date-range or at-frequency; anchors frequency and trigger declarations." }, { "id": "SRC-019", "title": "AS 2201: An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements", "organization": "Public Company Accounting Oversight Board (PCAOB)", "url": "https://pcaobus.org/oversight/standards/auditing-standards/details/AS2201", "version_or_date": "AS 2201 as published in the PCAOB standards library; amendments noted effective 15 December 2026", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:22:00Z", "relevance": "Regulator-set distinction between testing design effectiveness and operating effectiveness; deficiency, significant deficiency and material weakness; nature, timing and extent of tests; evidence sufficiency proportional to control risk; compensating control precision; benchmarking of automated controls; rollforward from interim testing." }, { "id": "SRC-020", "title": "Standards for Internal Control in the Federal Government (Green Book), GAO-25-107721", "organization": "U.S. Government Accountability Office (GAO)", "url": "https://www.gao.gov/products/gao-25-107721", "version_or_date": "GAO-25-107721, 15 May 2025, effective fiscal year 2026", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:26:00Z", "relevance": "Current edition of the federal internal-control standards: management responsibility at all levels, documentation of risk assessment and response, change assessment, prioritisation of preventive control activities, and harmonisation with COSO." }, { "id": "SRC-021", "title": "Standards for Internal Control in the Federal Government (Green Book), GAO-14-704G", "organization": "U.S. Government Accountability Office (GAO)", "url": "https://www.gao.gov/assets/gao-14-704g.pdf", "version_or_date": "GAO-14-704G, September 2014, effective fiscal year 2016; superseded by GAO-25-107721", "source_type": "public-authority", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-03T09:28:00Z", "relevance": "Full text source for the preventive versus detective control-activity distinction, documentation of control responsibilities in policies, the requirement that components operate together in an integrated manner, and deficiency identification and remediation." }, { "id": "SRC-022", "title": "NIST CSWP 29, The NIST Cybersecurity Framework (CSF) 2.0", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://csrc.nist.gov/pubs/cswp/29/the-nist-cybersecurity-framework-csf-20/final", "version_or_date": "Version 2.0, 26 February 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:37:00Z", "relevance": "Outcome taxonomy that links to external practices and controls through informative references without prescribing implementation; basis for treating crosswalks as alignment rather than conformance." }, { "id": "SRC-023", "title": "NIST Computer Security Resource Center Glossary: compensating security control", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://csrc.nist.gov/glossary/term/compensating_security_control", "version_or_date": "CSRC glossary entry citing NIST SP 800-30 Rev. 1, SP 800-39 and SP 800-137; accessed September 2026", "source_type": "registry", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-03T09:39:00Z", "relevance": "Normative definition of a compensating control as an alternative to a baseline control providing equivalent or comparable protection; distinguishes the NIST sense from the audit-deficiency sense." }, { "id": "SRC-024", "title": "NIST Computer Security Resource Center Glossary: assessment method", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://csrc.nist.gov/glossary/term/assessment_method", "version_or_date": "CSRC glossary entry citing NIST SP 800-53A Rev. 5, SP 800-137, SP 800-137A and SP 800-79-2; accessed September 2026", "source_type": "registry", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-03T09:41:00Z", "relevance": "Defines the three assessment methods (examine, interview, test) that assessors use to obtain evidence; supplies the controlled vocabulary for the assessment-method field." }, { "id": "SRC-025", "title": "Introduction to the Cyber Assessment Framework (CAF) v4.0", "organization": "National Cyber Security Centre (NCSC), United Kingdom", "url": "https://www.ncsc.gov.uk/collection/cyber-assessment-framework/introduction-to-caf", "version_or_date": "CAF v4.0, published 18 April 2024, reviewed 6 August 2025", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:44:00Z", "relevance": "Objective/principle/contributing-outcome/indicator hierarchy with achieved, partially achieved and not achieved values, and an explicit warning against tick-box assessment; supplies an alternative outcome vocabulary and supports the mapping-is-not-effectiveness rule." }, { "id": "SRC-026", "title": "Internal Control - Integrated Framework (ICIF-2013), guidance page", "organization": "Committee of Sponsoring Organizations of the Treadway Commission (COSO)", "url": "https://www.coso.org/guidance-on-ic", "version_or_date": "Framework originally issued 1992, refreshed 2013 (ICIF-2013); page accessed September 2026", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-03T09:47:00Z", "relevance": "Confirms the five components, seventeen principles and the criterion that effective internal control requires all principles present and functioning. Limited evidence: the full framework text is paywalled and was not retrieved." }, { "id": "SRC-027", "title": "PCI DSS v4.0: Compensating Controls vs Customized Approach", "organization": "PCI Security Standards Council", "url": "https://blog.pcisecuritystandards.org/pci-dss-v4-0-compensating-controls-vs-customized-approach", "version_or_date": "Published 18 July 2022, referring to PCI DSS v4.0", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-03T09:50:00Z", "relevance": "Standards-body statement that a compensating control requires a legitimate and documented technical or business constraint, cannot be applied retroactively, and is distinct from a customized approach requiring a targeted risk analysis; the two cannot be combined for the same requirement." }, { "id": "SRC-028", "title": "NIST SP 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://csrc.nist.gov/pubs/sp/800/137/final", "version_or_date": "September 2011", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:53:00Z", "relevance": "Visibility into the effectiveness of deployed controls, determination of assessment frequency from criticality and volatility, ongoing assessment in place of periodic snapshots and reuse of assessment results." }, { "id": "SRC-029", "title": "Revisions to the Principles for the Sound Management of Operational Risk", "organization": "Basel Committee on Banking Supervision (BCBS), Bank for International Settlements", "url": "https://www.bis.org/bcbs/publ/d515.htm", "version_or_date": "31 March 2021", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:56:00Z", "relevance": "Supervisory operational-risk principles aligned to the Basel III operational risk framework with updated change-management and ICT guidance; the Committee's 2014 review finding that several principles had not been adequately implemented supports treating documentation as no evidence of implementation. Limited evidence: only the publication landing page was retrievable." }, { "id": "SRC-030", "title": "ISO 31000:2018 Risk management — Guidelines", "organization": "International Organization for Standardization", "url": "https://www.iso.org/standard/65694.html", "version_or_date": "Edition 2, 2018-02", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:12:00Z", "relevance": "Defines the risk management process including risk treatment, monitoring and review, and recording and reporting; establishes that risk management activities must be traceable and that records support improvement of methods and tools." }, { "id": "SRC-031", "title": "ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements", "organization": "International Organization for Standardization / International Electrotechnical Commission", "url": "https://www.iso.org/standard/27001", "version_or_date": "Edition 3, 2022-10", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:14:00Z", "relevance": "Clause 6.1.3 requires determining necessary controls, comparing them with a catalogue, producing a Statement of Applicability with justification for inclusion and exclusion, formulating a risk treatment plan, and obtaining risk owners' approval and acceptance of residual risks." }, { "id": "SRC-032", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:22:00Z", "relevance": "Normative provenance vocabulary supplying Entity, Activity and Agent, wasAttributedTo, wasGeneratedBy, wasDerivedFrom, wasRevisionOf, actedOnBehalfOf, generatedAtTime and invalidatedAtTime, plus the qualified influence pattern used for attributed assertions." }, { "id": "SRC-033", "title": "Traffic Light Protocol (TLP) Version 2.0", "organization": "FIRST — Forum of Incident Response and Security Teams", "url": "https://www.first.org/tlp/", "version_or_date": "Version 2.0, authoritative from August 2022", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-03T09:24:00Z", "relevance": "Normative labelling and handling rules for sensitive risk information (TLP:RED, TLP:AMBER, TLP:AMBER+STRICT, TLP:GREEN, TLP:CLEAR), including label placement obligations and the source's duty to ensure recipients can follow the sharing guidance." }, { "id": "SRC-034", "title": "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)", "organization": "European Union (European Parliament and Council)", "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng", "version_or_date": "Regulation (EU) 2024/1689, OJ L, 12 July 2024", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:26:00Z", "relevance": "Article 9 requires a continuous iterative risk management system run throughout the lifecycle with regular systematic review and updating, and that each residual risk and the overall residual risk be judged acceptable; Article 18 requires documentation to be kept at the disposal of national competent authorities for ten years." }, { "id": "SRC-035", "title": "The IIA's Three Lines Model: An Update of the Three Lines of Defense", "organization": "The Institute of Internal Auditors", "url": "https://www.theiia.org/globalassets/documents/resources/the-iias-three-lines-model-an-update-of-the-three-lines-of-defense-july-2020/three-lines-model-updated-english.pdf", "version_or_date": "July 2020", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-03T09:28:00Z", "relevance": "Separates governing body oversight, first- and second-line management and risk/compliance roles, and third-line independent assurance; states that independence from management responsibilities is critical to objectivity, authority and credibility, underpinning segregation of duties in this mixin." }, { "id": "SRC-036", "title": "Federal Records Centers Program Freeze Process Overview / FAQ", "organization": "National Archives and Records Administration (United States)", "url": "https://www.archives.gov/frc/arcis/freeze-faq", "version_or_date": "Current NARA guidance, accessed 2026-09-03", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:30:00Z", "relevance": "Defines litigation holds as moratoriums on destruction issued by counsel, freezes that suspend the normal disposition cycle for records held elsewhere, and the requirement that the agency request in writing that a freeze be lifted; the model for hold and disposition-suspension semantics." }, { "id": "SRC-037", "title": "Government Auditing Standards, 2024 Revision (GAO-24-106786)", "organization": "U.S. Government Accountability Office", "url": "https://www.gao.gov/yellowbook", "version_or_date": "2024 revision, issued 1 February 2024, effective 15 December 2025", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:32:00Z", "relevance": "Standards for financial audits, attestation engagements and performance audits, including the conceptual framework for independence, sufficient and appropriate evidence, professional judgment and engagement documentation; the basis for recording assurance level and limitations." } ], "structure": { "bundles": [ { "id": "rctl-risk-binding-bundle", "name": "Risk subject binding and assessment framing", "description": "Everything that fixes what was assessed and under which declared frame: the referenced risk and its exact revision, the anchors the assessment is scoped against, the causal chain quantified, the category and taxonomy pins, the scope and horizon, and the criteria, method and expression-mode pins.", "rationale": "A recorded level of risk is uninterpretable and non-comparable without the reference it belongs to and the frame it was produced under. NIST SP 800-30 requires the purpose, scope, assumptions, constraints, information sources, risk model and analytic approach to be documented alongside results, and IEC 31010 exists precisely because technique choice changes what a result means. Binding fields therefore precede estimate fields.", "source_refs": [ "SRC-001", "SRC-007", "SRC-008", "SRC-002" ], "layers": [ { "id": "rctl-risk-reference-layer", "name": "Referenced risk, anchors and causal chain", "description": "Reference-carrying fields that attach one assessment context to a pinned risk revision, to the objectives, assets, processes and contextual conditions it is scoped against, and to the risk source, event and consequences it quantifies.", "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-007" ], "findings": [ { "id": "rctl-risk-subject-reference", "name": "Referenced risk identity and exact revision pin", "description": "Identifies which risk or opportunity entity this assessment context is bound to and which exact revision of its statement was assessed, so an estimate cannot silently drift when the referenced statement is later restated. The referenced entity's own status and lifecycle stay with the owning risk model; only the local binding validity state is held here.", "source_refs": [ "SRC-002", "SRC-005", "SRC-007" ], "questions": [ { "id": "rctl-risk-q-subject-identifier", "text": "Which authoritative identifier designates the risk entity that this assessment context is bound to?", "kind": "identity", "answer_data": [ "risk reference identifier value", "identifier system or namespace", "assigning authority or system of record" ] }, { "id": "rctl-risk-q-subject-revision", "text": "Which exact revision or version of the referenced risk statement was assessed?", "kind": "provenance", "answer_data": [ "risk revision or version token", "time the revision was retrieved", "content digest of the assessed statement" ] }, { "id": "rctl-risk-q-subject-staleness", "text": "How is this assessment context marked once the pinned risk revision is superseded upstream?", "kind": "state", "answer_data": [ "binding validity state code", "time supersession was detected", "re-assessment required indicator" ] }, { "id": "rctl-risk-q-subject-polarity", "text": "Does the bound subject represent a threat, an opportunity, or both, and where is that reading declared?", "kind": "classification", "answer_data": [ "effect polarity code", "reference to the statement establishing polarity" ] } ], "data_elements": [ { "id": "rctl-risk-de-risk-reference", "name": "risk-reference", "description": "Resolvable reference to the risk or opportunity entity in its owning model.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-005" ] }, { "id": "rctl-risk-de-risk-revision-pin", "name": "risk-revision-pin", "description": "Exact revision, version token or immutable snapshot identifier of the assessed risk statement.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005" ] }, { "id": "rctl-risk-de-statement-digest", "name": "risk-statement-digest", "description": "Content digest of the assessed statement, allowing detection of upstream change without re-reading the source.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "rctl-risk-de-binding-state", "name": "binding-validity-state", "description": "Local state of the binding: current, superseded-upstream, dangling or withdrawn. Describes this record only, never the referenced risk's own status.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-005" ] }, { "id": "rctl-risk-de-effect-polarity", "name": "effect-polarity", "description": "Whether the assessed effect is treated as downside, upside or two-sided under the pinned criteria.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "These are reference and pin fields carried on the host record; they produce no separable document. Reproducing the referenced risk statement here would fork the authoritative text owned by the risk entity model, so the binding stores an identifier, a revision token and a digest rather than a copy." }, { "id": "rctl-risk-context-anchors", "name": "Objective, asset, process and context anchors", "description": "Records what the risk is assessed against - objectives, assets, processes, organizational units, fixed contextual conditions and applicable jurisdiction or site - as references, so the estimate is interpretable and comparable only within its declared anchor set. Master data for each anchor belongs to its own registry.", "source_refs": [ "SRC-001", "SRC-007", "SRC-002", "SRC-010" ], "questions": [ { "id": "rctl-risk-q-anchor-objectives", "text": "Which objectives does this assessment measure the effect of uncertainty against?", "kind": "relationship", "answer_data": [ "objective reference set", "objective owner reference", "objective version or planning period reference" ] }, { "id": "rctl-risk-q-anchor-exposure", "text": "Which assets, processes or organizational units are inside the assessed exposure?", "kind": "composition", "answer_data": [ "asset or process reference set", "organizational scope reference", "explicit exclusion statements" ] }, { "id": "rctl-risk-q-anchor-fixed-conditions", "text": "Which contextual conditions were treated as fixed rather than assessed for this estimate?", "kind": "constraint", "answer_data": [ "fixed context condition statements", "reference to the context description in force" ] }, { "id": "rctl-risk-q-anchor-location", "text": "Where anchors are jurisdiction-specific or site-specific, how is the applicable location recorded?", "kind": "spatial", "answer_data": [ "jurisdiction code set", "site or facility reference", "basis for jurisdictional applicability" ] } ], "data_elements": [ { "id": "rctl-risk-de-anchor-set", "name": "assessment-anchor-set", "description": "The complete set of resolvable anchors this assessment is scoped against; at least one anchor must resolve for the context to be valid.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007" ] }, { "id": "rctl-risk-de-objective-reference", "name": "objective-reference", "description": "Reference to an objective whose achievement the assessed uncertainty affects.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-002" ] }, { "id": "rctl-risk-de-asset-process-reference", "name": "asset-or-process-reference", "description": "Reference to an asset, process, system or service inside the assessed exposure.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "rctl-risk-de-context-condition", "name": "context-condition-statement", "description": "A contextual condition held fixed for this assessment, whose change invalidates the estimate.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-010" ] }, { "id": "rctl-risk-de-applicable-jurisdiction", "name": "applicable-jurisdiction-or-site", "description": "Jurisdiction, site or facility whose rules or conditions make the anchor set location-specific.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012", "SRC-007" ] } ], "artifacts": [], "inline_only_rationale": "Anchors are pure reference data pointing into objective, asset, process and organizational registries owned elsewhere. Materialising them as a local artifact would duplicate master data and create a second, silently diverging copy of records this model has no authority to maintain." }, { "id": "rctl-risk-causal-anchors", "name": "Risk source, event and consequence anchors", "description": "Carries references to the risk source or threat source, the single event or event class whose likelihood is quantified, and the consequences included in the impact estimate, together with named exclusions. This makes likelihood and impact attach to a stated causal chain rather than to a bare label.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007", "SRC-009" ], "questions": [ { "id": "rctl-risk-q-causal-source", "text": "Which risk source or threat source does this estimate attribute the event to?", "kind": "relationship", "answer_data": [ "risk source or threat source reference", "source characterization such as adversarial or non-adversarial", "source catalogue reference" ] }, { "id": "rctl-risk-q-causal-event", "text": "Which single event or event class does the likelihood dimension quantify?", "kind": "definition", "answer_data": [ "event reference or event statement", "event class boundary description", "distinction between initiating event and consequential event" ] }, { "id": "rctl-risk-q-causal-consequences", "text": "Which consequences are inside the impact estimate and which named consequences are excluded?", "kind": "composition", "answer_data": [ "included consequence reference set", "excluded consequence statements", "order of consequence such as primary or secondary" ] }, { "id": "rctl-risk-q-causal-preconditions", "text": "Which vulnerability or predisposing condition is assumed present for the event to occur?", "kind": "constraint", "answer_data": [ "vulnerability or weakness reference", "predisposing condition statement", "status of that condition at the as-of time" ] }, { "id": "rctl-risk-q-causal-catalogue", "text": "Which external threat or hazard catalogue entry is cited, and under which catalogue version?", "kind": "interoperability", "answer_data": [ "threat or hazard catalogue identifier", "catalogue system or namespace", "catalogue version token" ] } ], "data_elements": [ { "id": "rctl-risk-de-risk-source-reference", "name": "risk-source-reference", "description": "Reference to the risk source or threat source the event is attributed to.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-007" ] }, { "id": "rctl-risk-de-event-statement", "name": "event-reference-or-statement", "description": "Reference to, or statement of, the event or event class whose likelihood is quantified.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007" ] }, { "id": "rctl-risk-de-consequence-reference", "name": "consequence-reference", "description": "Reference to a consequence included in the impact estimate.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-009" ] }, { "id": "rctl-risk-de-excluded-consequence", "name": "excluded-consequence-statement", "description": "A consequence deliberately outside the impact estimate, recorded so the omission is visible rather than inferred.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "rctl-risk-de-predisposing-condition", "name": "predisposing-condition-statement", "description": "Vulnerability, weakness or predisposing condition assumed present for the event to occur.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "rctl-risk-de-threat-catalogue-id", "name": "threat-catalogue-identifier", "description": "Identifier of a cited external threat or hazard catalogue entry, with its naming system and version.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-001" ] } ], "artifacts": [], "inline_only_rationale": "The causal chain is expressed as short reference and statement fields on the host record. Full source, threat and consequence descriptions belong to threat catalogues and consequence registries; carrying only identifiers plus catalogue version keeps the mixin embeddable and avoids asserting ownership of catalogue content." } ] }, { "id": "rctl-risk-frame-layer", "name": "Classification, scope and method framing", "description": "Fields that pin the interpretive frame of the estimate: category values against a versioned taxonomy, the assessment boundary and time structure, and the criteria set, method, technique and expression mode under which any recorded value must be read.", "source_refs": [ "SRC-001", "SRC-003", "SRC-007", "SRC-008" ], "findings": [ { "id": "rctl-risk-taxonomy-pin", "name": "Category assignment with taxonomy and version pin", "description": "Pins the category values used to classify the referenced risk within this assessment context, together with the taxonomy scheme identifier and version, because category labels are only comparable inside one pinned scheme and category lists differ materially between frameworks.", "source_refs": [ "SRC-002", "SRC-007", "SRC-005", "SRC-009" ], "questions": [ { "id": "rctl-risk-q-taxonomy-scheme", "text": "Which taxonomy scheme and version supplies the category values asserted here?", "kind": "classification", "answer_data": [ "taxonomy system identifier", "taxonomy version token", "publisher of the taxonomy" ] }, { "id": "rctl-risk-q-taxonomy-multiplicity", "text": "Which category values are asserted, and is more than one concurrent categorization permitted?", "kind": "constraint", "answer_data": [ "asserted category value set", "multiplicity rule", "primary category designation where one is required" ] }, { "id": "rctl-risk-q-taxonomy-mapping", "text": "How is a category value mapped when the adopting Dimension and an external framework use different schemes?", "kind": "interoperability", "answer_data": [ "mapping reference or crosswalk identifier", "mapping fidelity such as exact, broader, narrower or unmapped", "mapping version" ] }, { "id": "rctl-risk-q-taxonomy-authority", "text": "Who is authorized to change a pinned category value after an estimate has been recorded against it?", "kind": "authority", "answer_data": [ "authorized role reference", "required supersession action", "record of the prior pinned value" ] } ], "data_elements": [ { "id": "rctl-risk-de-taxonomy-system", "name": "taxonomy-system-identifier", "description": "Identifier or namespace of the category scheme supplying the asserted values.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-007" ] }, { "id": "rctl-risk-de-taxonomy-version", "name": "taxonomy-version", "description": "Immutable version token of the category scheme in force for this assessment context.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-008" ] }, { "id": "rctl-risk-de-category-value", "name": "category-value", "description": "A category value asserted against the pinned scheme.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-002", "SRC-007" ] }, { "id": "rctl-risk-de-category-mapping", "name": "category-mapping-note", "description": "Reference to a crosswalk plus the fidelity of the mapping when values are restated in another scheme.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-004" ] } ], "artifacts": [], "inline_only_rationale": "Category pins are coded field values plus a scheme and version reference. The taxonomy document itself is owned and published by its issuing registry, so this model stores the pin and any crosswalk reference rather than a local copy of the scheme." }, { "id": "rctl-risk-assessment-scope", "name": "Assessment scope, horizon and time structure", "description": "Declares what the assessment covers and for how long: the assessment boundary and its exclusions, the time horizon over which likelihood is expressed, the as-of time of the assessed state, the time the estimate was recorded, the validity or review-due time, and the decision the assessment was produced for.", "source_refs": [ "SRC-001", "SRC-002", "SRC-007", "SRC-010" ], "questions": [ { "id": "rctl-risk-q-scope-boundary", "text": "What is the declared boundary of this assessment and what is explicitly excluded from it?", "kind": "constraint", "answer_data": [ "scope statement", "exclusion statements", "reason each exclusion was made" ] }, { "id": "rctl-risk-q-scope-horizon", "text": "Over what time horizon is the likelihood or frequency dimension expressed?", "kind": "temporal", "answer_data": [ "horizon duration or period", "horizon start reference", "whether the horizon is rolling or fixed" ] }, { "id": "rctl-risk-q-scope-time-separation", "text": "What are the as-of time of the assessed state and the time the estimate was recorded, and do they differ?", "kind": "provenance", "answer_data": [ "as-of time of the assessed state", "time the estimate was recorded", "explanation where the gap is material" ] }, { "id": "rctl-risk-q-scope-currency", "text": "Until when is this assessment treated as current, and what triggers an out-of-date state?", "kind": "state", "answer_data": [ "validity or review-due time", "triggers that force re-assessment", "current currency state code" ] }, { "id": "rctl-risk-q-scope-purpose", "text": "Which decision or reporting purpose was this assessment produced for?", "kind": "decision", "answer_data": [ "stated assessment purpose", "intended consumer or forum reference", "limits on reuse for other purposes" ] } ], "data_elements": [ { "id": "rctl-risk-de-scope-statement", "name": "assessment-scope-statement", "description": "Declared boundary of what this assessment covers.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007" ] }, { "id": "rctl-risk-de-scope-exclusion", "name": "scope-exclusion-statement", "description": "An element deliberately outside the assessment boundary, with the reason for exclusion.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "rctl-risk-de-likelihood-horizon", "name": "likelihood-time-horizon", "description": "Period over which the likelihood or frequency dimension is expressed.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-009" ] }, { "id": "rctl-risk-de-as-of-time", "name": "assessment-as-of-time", "description": "Time of the assessed state that the estimate describes, recorded in RFC 3339 with seconds and an explicit offset or Z.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005" ] }, { "id": "rctl-risk-de-recorded-time", "name": "assessment-recorded-time", "description": "Time the estimate was produced and stored, held separately from the as-of time.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-002" ] }, { "id": "rctl-risk-de-validity-until", "name": "validity-or-review-due-time", "description": "Time after which the assessment is treated as no longer current absent revalidation.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-010" ] }, { "id": "rctl-risk-de-assessment-purpose", "name": "assessment-purpose", "description": "The decision or reporting purpose the assessment was produced to serve.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-011" ] } ], "artifacts": [], "inline_only_rationale": "Scope, horizon and the three distinct time fields are structured attributes of the assessment context itself and must remain queryable alongside every estimate. Splitting them into a separate document would let a value be read without its horizon, which is the specific failure this finding exists to prevent." }, { "id": "rctl-risk-criteria-method-pin", "name": "Criteria, method and expression-mode pin", "description": "Pins the risk criteria set, the assessment method or technique and their versions, plus the expression mode under which values are recorded, so that a level of risk stays interpretable and so that comparison can be refused when pins differ. The mixin references method definitions and never restates technique semantics.", "source_refs": [ "SRC-001", "SRC-008", "SRC-003", "SRC-009", "SRC-010" ], "questions": [ { "id": "rctl-risk-q-criteria-set", "text": "Which risk criteria set, at which version, defines the scales and thresholds used here?", "kind": "definition", "answer_data": [ "criteria set reference", "criteria set version token", "owning criteria registry" ] }, { "id": "rctl-risk-q-method-identity", "text": "Which assessment technique or method was applied, and where is its normative definition held?", "kind": "provenance", "answer_data": [ "method or technique reference", "method version", "locator of the normative technique definition" ] }, { "id": "rctl-risk-q-expression-mode", "text": "Is the expression qualitative, ordinal, semi-quantitative, quantitative, probabilistic or scenario-based?", "kind": "classification", "answer_data": [ "expression mode code", "scale type such as nominal, ordinal, interval or ratio", "permitted operations for that scale type" ] }, { "id": "rctl-risk-q-pin-match-rule", "text": "What must match before two records assessed under different pins may be compared?", "kind": "validation", "answer_data": [ "required matching pin set", "tolerated differences", "action when pins do not match" ] }, { "id": "rctl-risk-q-criteria-approval", "text": "Who approved the criteria set for use in this assessment context?", "kind": "authority", "answer_data": [ "approving role reference", "approval time", "scope of the approval" ] } ], "data_elements": [ { "id": "rctl-risk-de-criteria-set-reference", "name": "criteria-set-reference", "description": "Reference to the versioned criteria set defining scales and thresholds for this context.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-007" ] }, { "id": "rctl-risk-de-criteria-set-version", "name": "criteria-set-version", "description": "Immutable version token of the criteria set in force.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "rctl-risk-de-method-reference", "name": "method-reference", "description": "Reference to the assessment method or technique applied.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-001" ] }, { "id": "rctl-risk-de-method-version", "name": "method-version", "description": "Version or edition of the applied method or technique.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-009" ] }, { "id": "rctl-risk-de-expression-mode", "name": "expression-mode", "description": "How values are expressed: qualitative, ordinal, semi-quantitative, quantitative, probabilistic or scenario-based.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-010" ] }, { "id": "rctl-risk-de-method-locator", "name": "method-definition-locator", "description": "Resolvable locator of the normative definition of the pinned technique, held by its publisher.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-009" ] } ], "artifacts": [ { "id": "rctl-risk-criteria-pin-record", "name": "Pinned criteria and method record", "description": "A retrievable snapshot or resolvable citation of the criteria set, its scales and thresholds, and the method definition in force for this assessment context, sufficient for a reader to re-read a recorded level of risk long after the live criteria have been revised.", "media_or_form": [ "structured record", "tabular criteria scale", "controlled document reference" ], "serial": false, "identity_strategy": "Authoritative criteria-set identifier issued by the owning criteria registry; where none exists, a governed IRI for the criteria set combined with its immutable version token; where neither exists, a UUID assigned by the adopting Dimension bound to a content digest. A criteria review date or cycle name is never used as the identifier.", "source_refs": [ "SRC-001", "SRC-008", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "rctl-risk-estimation-bundle", "name": "Estimation and evidential basis", "description": "The dimension declarations that give likelihood and consequence their meaning, the inherent estimate and its exclusion statement, and the assumptions, information sources, estimation basis and uncertainty qualification that make the estimate falsifiable.", "rationale": "NIST SP 800-30 separates likelihood of initiation, likelihood of adverse impact and level of impact, and requires assumptions, constraints and information sources to be documented with results. The AI RMF records that risk measurement is genuinely hard and that some risks are emergent or poorly measurable. An estimate presented without its dimension declarations and its basis is therefore not defensible context.", "source_refs": [ "SRC-001", "SRC-003", "SRC-010", "SRC-009" ], "layers": [ { "id": "rctl-risk-dimension-layer", "name": "Likelihood and consequence dimension declarations", "description": "Declares the form, unit and scale of each side of the estimate, admitting ordinal bands, probabilities, frequencies, distributions and multi-dimensional impact without imposing any single matrix.", "source_refs": [ "SRC-001", "SRC-003", "SRC-007", "SRC-009", "SRC-010" ], "findings": [ { "id": "rctl-risk-likelihood-dimension", "name": "Likelihood and frequency expression", "description": "Declares how the likelihood side is expressed - ordinal band, probability, frequency per unit time, qualitative descriptor or distribution - with its unit, scale reference, horizon dependency and the operations its scale type forbids.", "source_refs": [ "SRC-001", "SRC-003", "SRC-007", "SRC-009" ], "questions": [ { "id": "rctl-risk-q-likelihood-form", "text": "In what form is likelihood expressed and against which scale or unit?", "kind": "measurement", "answer_data": [ "likelihood expression mode", "scale reference or unit", "band label set where ordinal" ] }, { "id": "rctl-risk-q-likelihood-decomposition", "text": "Does this record separate likelihood of event occurrence from likelihood of adverse consequence?", "kind": "composition", "answer_data": [ "likelihood of initiation or occurrence", "likelihood of adverse impact given occurrence", "whether the two are combined and how" ] }, { "id": "rctl-risk-q-likelihood-distribution", "text": "If a range or distribution is used, which parameters, bounds and confidence level are stored?", "kind": "quality", "answer_data": [ "distribution family or range type", "stored parameters and bounds", "confidence level associated with the range" ] }, { "id": "rctl-risk-q-likelihood-operations", "text": "Which operations on the likelihood value are prohibited by its scale type?", "kind": "constraint", "answer_data": [ "scale type", "prohibited operations such as multiplication or averaging of ordinals", "permitted aggregation operations" ] } ], "data_elements": [ { "id": "rctl-risk-de-likelihood-mode", "name": "likelihood-expression-mode", "description": "Form in which the likelihood side is expressed for this record.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "rctl-risk-de-likelihood-band", "name": "likelihood-ordinal-band", "description": "Scale-referenced ordinal band value, stored as a code so that arithmetic is not implied by the encoding.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-007" ] }, { "id": "rctl-risk-de-likelihood-quantity", "name": "likelihood-quantitative-value", "description": "Probability or frequency value with its unit, where a quantitative or probabilistic mode is pinned.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009", "SRC-001" ] }, { "id": "rctl-risk-de-likelihood-scale-ref", "name": "likelihood-scale-reference", "description": "Reference to the scale definition in the pinned criteria set that gives the value meaning.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-007" ] }, { "id": "rctl-risk-de-likelihood-decomposition", "name": "likelihood-decomposition", "description": "Separate storage of likelihood of occurrence and likelihood of adverse impact where the pinned method distinguishes them.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-009" ] }, { "id": "rctl-risk-de-likelihood-distribution", "name": "likelihood-distribution-parameters", "description": "Parameters and bounds of a distribution or range representation of likelihood.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009", "SRC-001" ] } ], "artifacts": [], "inline_only_rationale": "Dimension declarations must be stored with the value they qualify, because a likelihood detached from its mode, unit and scale is the exact defect this finding guards against. Any supporting analysis output is captured by the derivation record in the basis finding rather than duplicated here." }, { "id": "rctl-risk-consequence-dimension", "name": "Impact and consequence dimensions", "description": "Declares the impact side, which may be multi-dimensional across financial, safety, health, fundamental-rights, environmental, operational, reputational and regulatory effects, each with its own scale, and states how or whether dimensions are combined and which parties bear each consequence.", "source_refs": [ "SRC-001", "SRC-003", "SRC-007", "SRC-010", "SRC-012", "SRC-009" ], "questions": [ { "id": "rctl-risk-q-impact-dimensions", "text": "Which impact dimensions are scored, and on which scale is each one expressed?", "kind": "measurement", "answer_data": [ "impact dimension set", "per-dimension scale reference", "per-dimension value" ] }, { "id": "rctl-risk-q-impact-combination", "text": "How are multiple impact dimensions combined, or is combination explicitly withheld?", "kind": "constraint", "answer_data": [ "combination rule reference or none", "dominant-dimension rule where used", "statement that no combined value is asserted" ] }, { "id": "rctl-risk-q-impact-nonfinancial", "text": "Are safety, health, environmental or fundamental-rights harms represented as first-class dimensions rather than monetized proxies?", "kind": "requirement", "answer_data": [ "non-financial dimension list", "legal or policy basis requiring the dimension", "monetization statement where a proxy is used" ] }, { "id": "rctl-risk-q-impact-bearers", "text": "Which affected parties bear each recorded consequence?", "kind": "relationship", "answer_data": [ "affected party reference per dimension", "whether the party is internal or external", "vulnerable-group indicator where applicable" ] }, { "id": "rctl-risk-q-impact-order", "text": "How are secondary or downstream consequences distinguished from primary consequences?", "kind": "classification", "answer_data": [ "consequence order code", "basis for treating a loss as secondary", "whether secondary effects are inside the estimate" ] } ], "data_elements": [ { "id": "rctl-risk-de-impact-dimension-set", "name": "impact-dimension-set", "description": "The set of impact dimensions scored in this assessment context.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-003" ] }, { "id": "rctl-risk-de-impact-value", "name": "impact-value-per-dimension", "description": "Value recorded for one impact dimension together with its scale reference and unit.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "rctl-risk-de-impact-combination-rule", "name": "impact-combination-rule", "description": "Declared rule for combining dimensions, or an explicit statement that no combined value is asserted.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-010" ] }, { "id": "rctl-risk-de-affected-party", "name": "affected-party-reference", "description": "Reference to a party bearing a recorded consequence, including external and vulnerable groups where relevant.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012", "SRC-010" ] }, { "id": "rctl-risk-de-consequence-order", "name": "consequence-order", "description": "Whether a recorded consequence is primary or secondary or downstream under the pinned method.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009", "SRC-001" ] } ], "artifacts": [], "inline_only_rationale": "Impact dimensions are structured values that must travel with the estimate and stay queryable per dimension. Externalising them would encourage reading a single headline severity without its dimension set, and the affected-party detail is a reference into party registries owned elsewhere." }, { "id": "rctl-risk-inherent-estimate", "name": "Inherent estimate and its exclusion statement", "description": "Records the estimate produced before, or excluding, the effect of the referenced controls, together with an explicit statement of what inherent was taken to mean, because the term is not uniformly defined and some authorities do not require it at all. Omission must be recorded with a ground rather than left implicit.", "source_refs": [ "SRC-002", "SRC-003", "SRC-005", "SRC-007", "SRC-001" ], "questions": [ { "id": "rctl-risk-q-inherent-definition", "text": "What definition of inherent or gross risk was used, and which control effects were excluded from it?", "kind": "definition", "answer_data": [ "inherent definition statement", "controls or control classes excluded", "whether any controls were assumed present" ] }, { "id": "rctl-risk-q-inherent-value", "text": "What is the recorded inherent level, and how does it relate the likelihood and impact dimensions?", "kind": "measurement", "answer_data": [ "inherent estimate value per dimension", "relation or combination applied", "scale reference used" ] }, { "id": "rctl-risk-q-inherent-omission", "text": "Was an inherent estimate produced at all, and if not, on what documented ground was it omitted?", "kind": "exception", "answer_data": [ "inherent estimate state code", "omission ground statement", "approving role reference for the omission" ] }, { "id": "rctl-risk-q-inherent-evidence", "text": "What derivation or evidence supports the inherent value?", "kind": "evidence", "answer_data": [ "derivation record reference", "cited observation or dataset references", "identity of the analyst or tool that produced it" ] } ], "data_elements": [ { "id": "rctl-risk-de-inherent-definition", "name": "inherent-definition-statement", "description": "Explicit statement of what inherent meant in this context, including which control effects were excluded.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-007" ] }, { "id": "rctl-risk-de-inherent-value", "name": "inherent-estimate-value", "description": "The inherent estimate expressed under the pinned criteria, dimension by dimension.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-001" ] }, { "id": "rctl-risk-de-inherent-state", "name": "inherent-estimate-state", "description": "Whether an inherent estimate is present, is an initial characterization, or was deliberately not produced.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-002" ] }, { "id": "rctl-risk-de-inherent-omission-ground", "name": "inherent-omission-ground", "description": "Documented ground for omitting an inherent estimate where none was produced.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-001" ] }, { "id": "rctl-risk-de-inherent-derivation-ref", "name": "inherent-derivation-reference", "description": "Reference to the derivation record supporting the inherent value.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] } ], "artifacts": [], "inline_only_rationale": "The inherent estimate is a role-tagged value slot on the assessment context, and its exclusion statement must be inseparable from it. The supporting derivation is captured once as an artifact under the basis finding, so declaring a second artifact here would duplicate the same evidence object." } ] }, { "id": "rctl-risk-basis-layer", "name": "Assessment basis, assumptions and uncertainty", "description": "The evidential qualification of the estimate: assumptions that must hold, the information sources and their currency, whether the value came from judgement, data or a model, the constraints on the analysis, and how much confidence and precision the result can bear.", "source_refs": [ "SRC-001", "SRC-003", "SRC-010", "SRC-009" ], "findings": [ { "id": "rctl-risk-basis-and-uncertainty", "name": "Assumptions, data basis and uncertainty qualification", "description": "Captures the assumptions, information sources, data currency, estimation basis kind and analysis constraints behind the estimate, together with confidence or data-quality grading, uncertainty representation, unmeasurable aspects and precision caveats. This is what allows a reader to judge whether a value rests on incident history, expert judgement, modelled data or a vendor claim, and how far it may be trusted.", "source_refs": [ "SRC-001", "SRC-003", "SRC-010", "SRC-007", "SRC-009" ], "questions": [ { "id": "rctl-risk-q-basis-assumptions", "text": "Which explicit assumptions must hold for this estimate to remain valid?", "kind": "constraint", "answer_data": [ "assumption statements", "assumption owner or source", "which assumption is flagged critical" ] }, { "id": "rctl-risk-q-basis-sources", "text": "Which information sources and datasets were used, and how current were they at the as-of time?", "kind": "provenance", "answer_data": [ "information source references", "data currency time per source", "known gaps in the source coverage" ] }, { "id": "rctl-risk-q-basis-kind", "text": "Was the estimate elicited from expert judgement, derived from historical data, or produced by a model run?", "kind": "evidence", "answer_data": [ "estimation basis kind", "number and qualification of estimators where elicited", "model or tool identity and version where modelled" ] }, { "id": "rctl-risk-q-basis-confidence", "text": "What confidence or data-quality grade is attached to this estimate, and on which scale?", "kind": "quality", "answer_data": [ "confidence or data-quality grade", "confidence scale reference", "uncertainty representation such as range, interval, distribution or narrative caveat" ] }, { "id": "rctl-risk-q-basis-precision", "text": "What precision may downstream consumers infer from the stored notation, and which aspects are effectively unmeasurable?", "kind": "validation", "answer_data": [ "precision caveat statement", "unmeasurable or weakly evidenced aspects", "rounding or significant-figure rule" ] } ], "data_elements": [ { "id": "rctl-risk-de-assumption-statement", "name": "assumption-statement", "description": "An explicit assumption whose falsification would change or invalidate the estimate.", "value_kind": "text", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-010" ] }, { "id": "rctl-risk-de-critical-assumption-flag", "name": "critical-assumption-flag", "description": "Marks the assumption whose falsification would most change the recorded result.", "value_kind": "boolean", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-010" ] }, { "id": "rctl-risk-de-information-source-ref", "name": "information-source-reference", "description": "Reference to a dataset, observation set, report or elicitation used as an input.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] }, { "id": "rctl-risk-de-data-currency-time", "name": "data-currency-time", "description": "Currency time of an information source, recorded separately from the assessment as-of and recording times.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] }, { "id": "rctl-risk-de-estimation-basis-kind", "name": "estimation-basis-kind", "description": "Whether the estimate is judgement-elicited, data-derived, model-produced or a declared hybrid.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-009" ] }, { "id": "rctl-risk-de-analysis-constraint", "name": "analysis-constraint-statement", "description": "A constraint on the analysis such as limited time, access or data availability.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "rctl-risk-de-confidence-grade", "name": "confidence-grade", "description": "Confidence or data-quality grade with its scale reference.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "rctl-risk-de-uncertainty-representation", "name": "uncertainty-representation", "description": "How uncertainty is expressed: range, interval, distribution, narrative caveat or none stated.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-010", "SRC-009" ] }, { "id": "rctl-risk-de-unmeasurable-aspect", "name": "unmeasurable-aspect-statement", "description": "Aspect of the risk acknowledged as emergent, inscrutable or not measurable to the implied precision.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010" ] }, { "id": "rctl-risk-de-precision-caveat", "name": "precision-caveat", "description": "Statement limiting the precision downstream consumers may infer from the stored notation.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-004" ] } ], "artifacts": [ { "id": "rctl-risk-basis-statement", "name": "Assessment basis statement", "description": "A retained statement of purpose, scope, assumptions, constraints and information sources for one assessment context, corresponding to the documented content that a risk assessment report is expected to carry alongside its results.", "media_or_form": [ "narrative document", "structured record", "report section" ], "serial": true, "identity_strategy": "Identifier issued by the assessment system of record where one exists; otherwise a governed IRI under the adopting Dimension's namespace; otherwise a UUID assigned by the adopting Dimension and bound to the assessment-context identifier plus its recorded time. The assessment date alone is never the identifier.", "source_refs": [ "SRC-001", "SRC-003", "SRC-007" ] }, { "id": "rctl-risk-estimate-derivation-record", "name": "Estimate derivation record", "description": "A record of the inputs, technique run and intermediate results that produced a recorded estimate, retained so the value can be re-read and challenged without re-running the analysis, and so the origin of a characterization is traceable to a human or automated actor.", "media_or_form": [ "structured record", "analysis worksheet", "model run output", "narrative derivation note" ], "serial": true, "identity_strategy": "Identifier issued by the analysis system of record where one exists; otherwise a governed IRI under the adopting Dimension's namespace; otherwise a ULID assigned by the adopting Dimension and ordered by recording time. A review cycle name or period label is never used as the identifier.", "source_refs": [ "SRC-005", "SRC-001", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "rctl-risk-residual-bundle", "name": "Residual position and comparability", "description": "The post-control estimate with its control linkage and change explanation, the comparison against referenced appetite or tolerance with its governance stamps, and the comparability, aggregation and scenario-dependence controls that stop values from being combined when their pins do not match.", "rationale": "Residual risk is the concept that closes the risk-control loop: OSCAL expresses it as an adjusted characterization citing mitigating factors linked to implementation statements, the AI RMF requires residual risk to be documented and disclosed, and EU law requires residual risk per hazard to be judged acceptable. Roll-up guidance stages registers into an enterprise profile, which makes an explicit comparability gate necessary rather than optional.", "source_refs": [ "SRC-005", "SRC-010", "SRC-012", "SRC-004", "SRC-011" ], "layers": [ { "id": "rctl-risk-residual-layer", "name": "Residual estimate, control linkage and appetite comparison", "description": "Fields that record the post-control estimate, the controls relied on and the effectiveness determinations cited for them, the explanation of change, and the outcome of comparing the residual position against a referenced tolerance statement.", "source_refs": [ "SRC-005", "SRC-006", "SRC-011", "SRC-012", "SRC-003" ], "findings": [ { "id": "rctl-risk-residual-estimate", "name": "Residual estimate, control linkage and change explanation", "description": "Records the estimate after the referenced controls are taken into account, the control references relied on, the effectiveness determinations cited for each of them, which dimension changed, and why. Effectiveness is cited by reference and is produced by the control assessment model; this finding never derives, revises or re-opens it.", "source_refs": [ "SRC-005", "SRC-006", "SRC-011", "SRC-002", "SRC-012", "SRC-007" ], "questions": [ { "id": "rctl-risk-q-residual-controls", "text": "Which controls were relied on when producing the residual estimate, and by which reference?", "kind": "relationship", "answer_data": [ "relied-on control reference set", "control implementation statement reference", "scope of reliance placed on each control" ] }, { "id": "rctl-risk-q-residual-effectiveness", "text": "Which effectiveness determination is cited for each relied-on control, and who produced it?", "kind": "evidence", "answer_data": [ "effectiveness determination reference", "determination outcome as recorded by its owner", "producing role and determination time" ] }, { "id": "rctl-risk-q-residual-change", "text": "Which dimension changed between the inherent and residual estimates - likelihood, consequence, or both?", "kind": "composition", "answer_data": [ "changed dimension set", "per-dimension before and after values", "narrative explanation of the change" ] }, { "id": "rctl-risk-q-residual-characterization", "text": "How is the residual value marked as an adjusted rather than an initial characterization?", "kind": "state", "answer_data": [ "characterization state code", "reference to the initial characterization", "time the adjustment was recorded" ] }, { "id": "rctl-risk-q-residual-missing-determination", "text": "What is recorded when a control is referenced but no effectiveness determination exists for it?", "kind": "exception", "answer_data": [ "reliance-without-determination flag", "assumed effectiveness statement", "effect on the confidence grade" ] } ], "data_elements": [ { "id": "rctl-risk-de-residual-value", "name": "residual-estimate-value", "description": "The residual estimate expressed under the same pinned criteria and dimensions as the inherent estimate.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-005" ] }, { "id": "rctl-risk-de-relied-on-control-ref", "name": "relied-on-control-reference", "description": "Reference to a control relied on when producing the residual estimate, resolving into the control implementation model.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-006" ] }, { "id": "rctl-risk-de-effectiveness-determination-ref", "name": "cited-effectiveness-determination-reference", "description": "Reference to an effectiveness determination produced by the control assessment model and cited here without restatement.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-005" ] }, { "id": "rctl-risk-de-reliance-gap-flag", "name": "reliance-without-determination-flag", "description": "Marks reliance on a control for which no current effectiveness determination is available.", "value_kind": "boolean", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-011" ] }, { "id": "rctl-risk-de-changed-dimension", "name": "changed-dimension", "description": "Which dimension the control effect changed: likelihood, consequence or both.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-005" ] }, { "id": "rctl-risk-de-residual-change-explanation", "name": "residual-change-explanation", "description": "Narrative explanation of what changed between the inherent and residual estimates and why.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-010", "SRC-012" ] }, { "id": "rctl-risk-de-characterization-state", "name": "estimate-characterization-state", "description": "Whether this characterization is initial as first identified or adjusted after control effects were taken into account.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-005" ] } ], "artifacts": [], "inline_only_rationale": "The residual value, its control references and its change explanation are inline fields of the assessment context. The evidence objects behind them - implementation statements and effectiveness determinations - are artifacts of the control implementation and control assessment models, so declaring a local artifact here would claim ownership of documents this model may only cite." }, { "id": "rctl-risk-appetite-comparison", "name": "Appetite or tolerance reference and comparison outcome", "description": "References the appetite or tolerance statement in force, records the outcome of comparing the residual estimate against it, and stamps who recorded the comparison and which acceptance or authorization decision, if any, was taken elsewhere. Setting, approving and enforcing appetite are not performed here.", "source_refs": [ "SRC-003", "SRC-007", "SRC-010", "SRC-011", "SRC-012", "SRC-013" ], "questions": [ { "id": "rctl-risk-q-appetite-reference", "text": "Which appetite or tolerance statement, at which version, was the residual estimate compared against?", "kind": "relationship", "answer_data": [ "appetite or tolerance statement reference", "statement version token", "threshold references applied" ] }, { "id": "rctl-risk-q-appetite-outcome", "text": "What is the recorded comparison outcome and on which scale is it expressed?", "kind": "measurement", "answer_data": [ "comparison outcome code", "distance to threshold where the scale supports it", "scale reference used for the comparison" ] }, { "id": "rctl-risk-q-appetite-stamps", "text": "Who recorded the comparison, and which decision record shows the residual position being accepted?", "kind": "ownership", "answer_data": [ "role reference that recorded the comparison", "acceptance or authorization decision reference", "time each stamp was recorded" ] }, { "id": "rctl-risk-q-appetite-absent", "text": "What is recorded when no applicable tolerance statement exists for the pinned criteria?", "kind": "exception", "answer_data": [ "no-applicable-tolerance flag", "escalation route reference", "effect on the comparison outcome" ] }, { "id": "rctl-risk-q-appetite-disclosure", "text": "Which downstream consumers may read the comparison outcome without access to the underlying estimates?", "kind": "access", "answer_data": [ "consumer role set", "fields released with the outcome", "caveats that must accompany the release" ] } ], "data_elements": [ { "id": "rctl-risk-de-appetite-reference", "name": "appetite-or-tolerance-statement-reference", "description": "Reference to the appetite or tolerance statement in force for this comparison.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-007" ] }, { "id": "rctl-risk-de-appetite-version", "name": "appetite-statement-version", "description": "Version token of the referenced appetite or tolerance statement.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-010" ] }, { "id": "rctl-risk-de-tolerance-threshold-ref", "name": "tolerance-threshold-reference", "description": "Reference to the specific threshold or tolerance line applied to a dimension.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-007" ] }, { "id": "rctl-risk-de-comparison-outcome", "name": "comparison-outcome", "description": "Recorded outcome of comparing the residual estimate with the referenced tolerance, including a no-applicable-tolerance value.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-012", "SRC-003" ] }, { "id": "rctl-risk-de-comparison-recorded-by", "name": "comparison-recorded-by", "description": "Reference to the role or actor that recorded the comparison outcome.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-011" ] }, { "id": "rctl-risk-de-acceptance-decision-ref", "name": "acceptance-decision-reference", "description": "Reference to an acceptance, authorization or exception decision recorded in the model that owns such decisions.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011", "SRC-012" ] } ], "artifacts": [], "inline_only_rationale": "The comparison is a small set of reference and outcome fields. The appetite statement is a governance document owned by enterprise risk governance, and the acceptance decision is an authorization record owned by the decision model, so this finding carries pointers and an outcome code rather than any local document." } ] }, { "id": "rctl-risk-comparability-layer", "name": "Comparability, aggregation and scenario dependence", "description": "The gate that decides whether two assessment contexts may be compared, rolled up or reported together, the caveats any permitted aggregate must carry, and how one risk assessed under several scenarios is represented without collapsing into a single false value.", "source_refs": [ "SRC-004", "SRC-003", "SRC-008", "SRC-010" ], "findings": [ { "id": "rctl-risk-comparability-limits", "name": "Comparability verdicts, aggregation caveats and scenario dependence", "description": "Records whether records may be placed on a common scale, which pins failed to match when they may not, which caveats must travel with any permitted aggregate, and how scenario variants and a designated reference case are represented. The model refuses to define a normalization algorithm it has no authority to assert.", "source_refs": [ "SRC-004", "SRC-003", "SRC-008", "SRC-010", "SRC-001" ], "questions": [ { "id": "rctl-risk-q-comparability-conditions", "text": "Under what conditions may two assessment contexts be placed on the same scale?", "kind": "validation", "answer_data": [ "required matching pin set", "comparability verdict code", "named mismatched pins where the verdict is negative" ] }, { "id": "rctl-risk-q-comparability-caveats", "text": "Which caveats must travel with any aggregate produced from these records?", "kind": "constraint", "answer_data": [ "aggregation caveat statements", "permitted aggregation operations for the scale type", "prohibition on stripping caveats downstream" ] }, { "id": "rctl-risk-q-comparability-scenarios", "text": "How is scenario dependence recorded when one risk is assessed under several scenarios?", "kind": "composition", "answer_data": [ "scenario identifier set", "per-scenario estimate references", "scenario definition reference and version" ] }, { "id": "rctl-risk-q-comparability-reference-case", "text": "Which scenario or variant is designated the reference case for reporting, and by which role?", "kind": "decision", "answer_data": [ "reference case flag", "designating role reference", "basis for the designation" ] }, { "id": "rctl-risk-q-comparability-superseded", "text": "How are records assessed under a superseded criteria version handled in a current roll-up?", "kind": "lifecycle", "answer_data": [ "superseded-criteria handling code", "migration or restatement reference", "exclusion from the aggregate where no migration exists" ] } ], "data_elements": [ { "id": "rctl-risk-de-comparability-verdict", "name": "comparability-verdict", "description": "Whether the compared records are comparable, comparable with caveats, or not comparable.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-004", "SRC-003" ] }, { "id": "rctl-risk-de-mismatched-pins", "name": "mismatched-pin-list", "description": "The specific pins that failed to match, naming criteria set, method, expression mode, scope, horizon or taxonomy.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-008" ] }, { "id": "rctl-risk-de-aggregation-caveat", "name": "aggregation-caveat", "description": "A caveat that must accompany any aggregate or roll-up built from this record.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-010" ] }, { "id": "rctl-risk-de-scenario-identifier", "name": "scenario-identifier", "description": "Identifier of a scenario under which this estimate was produced.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008", "SRC-001" ] }, { "id": "rctl-risk-de-scenario-definition-ref", "name": "scenario-definition-reference", "description": "Reference to the versioned scenario definition owned by the scenario or method registry.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008", "SRC-009" ] }, { "id": "rctl-risk-de-reference-case-flag", "name": "reference-case-flag", "description": "Marks the scenario variant designated as the reference case for reporting.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-010" ] }, { "id": "rctl-risk-de-superseded-criteria-handling", "name": "superseded-criteria-handling", "description": "How a record pinned to a withdrawn criteria version is treated in a current roll-up.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "Comparability verdicts and caveats are computed conclusions about this record's own fields and must remain attached to it so they cannot be separated from any value they qualify. The aggregate itself is produced and owned by the enterprise reporting model, so no local aggregate artifact is declared." } ] } ] }, { "id": "rctl-control-definition-binding", "name": "Control reference, classification and applicability", "description": "What control is being talked about, how it is characterised, where it applies to the host subject, and who is accountable for it.", "rationale": "Every downstream assertion about linkage, implementation and effectiveness is meaningless unless the control is bound to one authoritative catalogue entry at a known revision, classified on declared vocabularies, scoped to a stated population and attached to named accountable parties. NIST SP 800-53 and the OSCAL implementation layer both key implementation assertions to a control identifier resolved against a named catalogue source, and the internal-control standards make management responsibility and documented scoping a precondition of any effectiveness claim.", "source_refs": [ "SRC-014", "SRC-015", "SRC-017", "SRC-020" ], "layers": [ { "id": "rctl-control-authoritative-reference", "name": "Authoritative control reference and characterisation", "description": "The revision-pinned binding to an external control definition, and the objective and classification facets projected onto it for this subject.", "source_refs": [ "SRC-014", "SRC-015", "SRC-021" ], "findings": [ { "id": "rctl-control-catalogue-binding", "name": "Authoritative control reference and revision binding", "description": "Binds this assertion set to exactly one control definition in an external catalogue, pinned to a named catalogue source and revision, with the parameter values selected and any tailoring declared for the host subject. Catalogue text, families, enhancements and parameter definitions remain owned by the catalogue model.", "source_refs": [ "SRC-014", "SRC-015", "SRC-017", "SRC-011" ], "questions": [ { "id": "rctl-control-q-binding-identity", "text": "Which single authoritative catalogue entry does this assertion set bind to, and under which identifier scheme?", "kind": "identity", "answer_data": [ "Control identifier as issued by the catalogue", "Catalogue source identifier or URI", "Identifier scheme name" ] }, { "id": "rctl-control-q-binding-revision", "text": "Which catalogue release or revision was in force when the binding was made, and how is that pin preserved?", "kind": "provenance", "answer_data": [ "Catalogue release or revision label", "Pin timestamp in RFC 3339", "Digest of the referenced catalogue entry at pin time" ] }, { "id": "rctl-control-q-binding-parts", "text": "Which control statement parts or enhancements are in scope for this binding, and which parameter values were selected?", "kind": "composition", "answer_data": [ "Statement or part identifiers", "Enhancement identifiers", "Parameter identifier and selected value pairs" ] }, { "id": "rctl-control-q-binding-tailoring", "text": "What tailoring or deviation from the catalogue baseline does this binding assert, and on whose authority?", "kind": "constraint", "answer_data": [ "Tailoring action code", "Justification text", "Approving party reference" ] }, { "id": "rctl-control-q-binding-resolution", "text": "How can a consumer resolve this binding without importing the catalogue text into local storage?", "kind": "interoperability", "answer_data": [ "Resolvable reference form", "Catalogue source link", "Retrieval and caching rule" ] } ], "data_elements": [ { "id": "rctl-control-de-control-ref", "name": "Control reference", "description": "Resolvable reference to the authoritative control definition, carried in the issuing catalogue's namespace.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-014", "SRC-015" ] }, { "id": "rctl-control-de-catalogue-source", "name": "Catalogue source reference", "description": "Identifier or URI of the catalogue, profile or baseline from which the control reference is drawn.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-015", "SRC-017" ] }, { "id": "rctl-control-de-catalogue-revision", "name": "Catalogue revision pin", "description": "Release, revision or version label of the catalogue in force at binding time.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-014", "SRC-015" ] }, { "id": "rctl-control-de-parameter-setting", "name": "Selected parameter values", "description": "Parameter identifier and value pairs chosen for this subject, mirroring catalogue parameter definitions without redefining them.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-015", "SRC-017" ] }, { "id": "rctl-control-de-binding-recorded-at", "name": "Binding observation time", "description": "Time at which the binding was captured into this model, distinct from any catalogue publication date.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-015", "SRC-016" ] } ], "artifacts": [], "inline_only_rationale": "This finding is a pure reference binding. Its whole content is an external identifier, a catalogue source, a revision pin, parameter selections and a digest; the control definition itself is an artifact of the catalogue model and reproducing it locally would duplicate a target-owned lifecycle." }, { "id": "rctl-control-objective-classification", "name": "Control objective and classification projection", "description": "The objective the control is claimed to achieve for the host subject plus classification facets: functional type (preventive, detective, corrective), execution mode (manual, automated, hybrid), operating level (entity or process/transaction) and key designation. Values are source-qualified; where a catalogue publishes its own attribute values they are carried unchanged.", "source_refs": [ "SRC-021", "SRC-020", "SRC-019", "SRC-014" ], "questions": [ { "id": "rctl-control-q-objective-statement", "text": "What control objective is the control claimed to achieve for this specific host subject?", "kind": "definition", "answer_data": [ "Objective statement text", "Reference to the catalogue objective it specialises", "Scope qualifier" ] }, { "id": "rctl-control-q-functional-type", "text": "Is the control preventive, detective or corrective, and which vocabulary and source supply that value?", "kind": "classification", "answer_data": [ "Functional type code, possibly multi-valued", "Vocabulary identifier and version", "Source reference for the value" ] }, { "id": "rctl-control-q-execution-mode", "text": "Is the control executed manually, automatically or as a hybrid, and which part is automated?", "kind": "classification", "answer_data": [ "Execution mode code", "Automated portion description", "Executing system reference" ] }, { "id": "rctl-control-q-operating-level", "text": "Does the control operate at entity level or at process and transaction level for this subject?", "kind": "relationship", "answer_data": [ "Operating level code", "Affected process or account reference", "Rationale text" ] }, { "id": "rctl-control-q-key-designation", "text": "Has the control been designated key or non-key for this subject, and who made that determination?", "kind": "decision", "answer_data": [ "Key designation boolean", "Determining party reference", "Determination time in RFC 3339" ] } ], "data_elements": [ { "id": "rctl-control-de-objective-statement", "name": "Subject control objective", "description": "Locally authored statement of what the control is claimed to achieve for this subject.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-019", "SRC-021" ] }, { "id": "rctl-control-de-functional-type", "name": "Functional type", "description": "Preventive, detective or corrective classification; multi-valued where a control acts in more than one mode.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-021", "SRC-020" ] }, { "id": "rctl-control-de-execution-mode", "name": "Execution mode", "description": "Manual, automated or hybrid execution of the control.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-019", "SRC-015" ] }, { "id": "rctl-control-de-operating-level", "name": "Operating level", "description": "Entity-level or process/transaction-level operation of the control.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-019" ] }, { "id": "rctl-control-de-key-designation", "name": "Key control designation", "description": "Whether the control is designated key for the subject, with the determining party recorded in provenance.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-019", "SRC-026" ] }, { "id": "rctl-control-de-classification-vocabulary", "name": "Classification vocabulary reference", "description": "Identifier and version of the controlled vocabulary each classification value is drawn from.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-022", "SRC-025" ] } ], "artifacts": [], "inline_only_rationale": "Classification is a small set of source-qualified coded values projected onto an externally owned control definition. It carries no document of its own, and materialising it as an artifact would invite it to drift from the catalogue attributes it qualifies." } ] }, { "id": "rctl-control-applicability-accountability", "name": "Applicability, scope and accountability", "description": "Whether and where the control applies to the host subject, and which parties own, operate, assess and approve the assertions about it.", "source_refs": [ "SRC-017", "SRC-020", "SRC-027", "SRC-015" ], "findings": [ { "id": "rctl-control-applicability-scope", "name": "Applicability, covered population and exclusion determination", "description": "Declares whether the control applies to the host subject, the population or boundary it covers, the basis for that determination, and any not-applicable or partially applicable determination with justification, approval and validity window.", "source_refs": [ "SRC-017", "SRC-014", "SRC-027", "SRC-020" ], "questions": [ { "id": "rctl-control-q-applies-basis", "text": "Does this control apply to the host subject, and on what documented basis was that determined?", "kind": "requirement", "answer_data": [ "Applicability status code", "Basis text and reference", "Determining party reference" ] }, { "id": "rctl-control-q-covered-population", "text": "What population, boundary or component set does the control cover within the subject?", "kind": "spatial", "answer_data": [ "Covered population references", "Boundary description", "Excluded component references" ] }, { "id": "rctl-control-q-not-applicable", "text": "If the control is declared not applicable or only partially applicable, what justification and approval support that?", "kind": "exception", "answer_data": [ "Exclusion justification text", "Approving party reference", "Approval time in RFC 3339" ] }, { "id": "rctl-control-q-applicability-window", "text": "From when until when does this applicability determination hold?", "kind": "temporal", "answer_data": [ "Effective-from timestamp", "Effective-to timestamp or open-ended marker", "Scheduled review date" ] }, { "id": "rctl-control-q-applicability-authority", "text": "Which obligation or authority makes this control mandatory rather than discretionary for the subject?", "kind": "authority", "answer_data": [ "Obligation reference", "Obligation type code", "Jurisdiction or regime identifier" ] } ], "data_elements": [ { "id": "rctl-control-de-applicability-status", "name": "Applicability status", "description": "Applicable, partially applicable or not applicable determination for the subject.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-017", "SRC-014" ] }, { "id": "rctl-control-de-applicability-basis", "name": "Applicability basis", "description": "Documented reason the control applies, including scoping rule or obligation reference.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-020", "SRC-014" ] }, { "id": "rctl-control-de-covered-population-ref", "name": "Covered population reference", "description": "References to the components, records or process instances the control is claimed to cover.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-017", "SRC-015" ] }, { "id": "rctl-control-de-exclusion-justification", "name": "Exclusion justification", "description": "Justification recorded when applicability is denied or narrowed, with approver in provenance.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-017", "SRC-027" ] }, { "id": "rctl-control-de-applicability-effective-from", "name": "Applicability effective-from", "description": "Event time from which the applicability determination holds, distinct from the time it was recorded.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-016", "SRC-018" ] } ], "artifacts": [ { "id": "rctl-control-artifact-applicability-statement", "name": "Control applicability statement", "description": "A versioned, subject-scoped statement of applicability recording, per control, the applicability status, basis, covered population, exclusion justification and approval. It is the reviewable unit that scoping and certification consumers read.", "media_or_form": [ "structured applicability record", "statement-of-applicability style tabular entry", "human-readable narrative rendering" ], "serial": true, "identity_strategy": "Authoritative master-system applicability record identifier where the adopting Dimension operates a governance system of record; otherwise a governed IRI in the Dimension namespace; otherwise a UUID or ULID minted at first record. No date, control title or framework code is used as the identifier.", "source_refs": [ "SRC-017", "SRC-014", "SRC-020" ] } ], "inline_only_rationale": null }, { "id": "rctl-control-accountability-references", "name": "Owner, operator, assessor and approver references", "description": "Role-scoped references to the parties accountable for the control and its assertions, including shared, provided and inherited responsibility splits, competence and authority assertions for the performer, and independence flags for the assessor and approver. Party master data stays in the directory model.", "source_refs": [ "SRC-015", "SRC-017", "SRC-019", "SRC-011" ], "questions": [ { "id": "rctl-control-q-owner-party", "text": "Which party is accountable for the control's continued operation for this subject?", "kind": "ownership", "answer_data": [ "Control owner party reference", "Role code", "Accountability effective-from timestamp" ] }, { "id": "rctl-control-q-approval-independence", "text": "Who is authorised to approve the effectiveness conclusion, and are they independent of the operator?", "kind": "authority", "answer_data": [ "Approver party reference", "Independence flag", "Independence basis text" ] }, { "id": "rctl-control-q-responsibility-split", "text": "How is responsibility divided between the subject owner, a shared service and any external provider?", "kind": "composition", "answer_data": [ "Responsibility split record", "Provided and inherited responsibility references", "Customer responsibility statement reference" ] }, { "id": "rctl-control-q-performer-competence", "text": "What competence and authority are asserted for the party performing the control?", "kind": "quality", "answer_data": [ "Competence assertion text", "Authority assertion text", "Supporting reference" ] }, { "id": "rctl-control-q-assertion-access", "text": "Which parties may read or amend this control assertion set, and under which role?", "kind": "access", "answer_data": [ "Role to permission mapping", "Scope of grant", "Grant expiry timestamp" ] } ], "data_elements": [ { "id": "rctl-control-de-owner-ref", "name": "Control owner reference", "description": "Reference to the accountable owner party or organisational unit.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-015", "SRC-020" ] }, { "id": "rctl-control-de-operator-ref", "name": "Control operator reference", "description": "References to the parties or systems that perform the control.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-017", "SRC-019" ] }, { "id": "rctl-control-de-assessor-ref", "name": "Assessor reference", "description": "References to the parties that assess the control, with independence recorded separately.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011", "SRC-018" ] }, { "id": "rctl-control-de-responsibility-split", "name": "Responsibility split", "description": "Structured allocation of provided, inherited and customer responsibility across parties.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-017", "SRC-015" ] }, { "id": "rctl-control-de-independence-flag", "name": "Assessor independence flag", "description": "Whether the assessing or approving party is independent of the party operating the control.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011", "SRC-019" ] } ], "artifacts": [], "inline_only_rationale": "Accountability here is a set of role-scoped pointers into the party and organisation directory plus two local qualifiers. Holding it inline prevents this model from becoming a shadow party register with its own identity lifecycle." } ] } ] }, { "id": "rctl-control-linkage-topology", "name": "Risk-to-control linkage, coverage and framework alignment", "description": "The graph that connects risk statements to controls, the aggregate coverage it produces, dependency edges between controls, and crosswalks to other frameworks that carry no conformance meaning.", "rationale": "The registered purpose of this mixin is risk-control linkage, and linkage semantics must be stated explicitly rather than implied by co-location. NIST IR 8286 and SP 800-37 tie controls to a risk response and to the residual position that rolls up into an enterprise risk profile, the internal-control standards derive control activities from an assessed risk, and CSF 2.0 and the NCSC CAF establish that a mapping between frameworks is an alignment and not evidence of an achieved outcome.", "source_refs": [ "SRC-002", "SRC-011", "SRC-026", "SRC-022", "SRC-025" ], "layers": [ { "id": "rctl-control-treatment-linkage", "name": "Treatment linkage and coverage topology", "description": "Individual risk-to-control links with their claimed treatment mechanism, and the aggregate many-to-many coverage and dependency structure they form.", "source_refs": [ "SRC-002", "SRC-011", "SRC-019", "SRC-017" ], "findings": [ { "id": "rctl-control-link-record", "name": "Risk-to-control link and claimed treatment mechanism", "description": "One directed link from a risk statement reference to a control reference, carrying the claimed treatment mechanism, the risk-response type it serves, any claimed magnitude of reduction, the basis of the claim and its provenance. The risk record and its own lifecycle stay in the risk model.", "source_refs": [ "SRC-002", "SRC-011", "SRC-026", "SRC-020" ], "questions": [ { "id": "rctl-control-q-link-target", "text": "Which risk statement does this control link to, and in which direction does the treatment claim run?", "kind": "relationship", "answer_data": [ "Risk statement reference", "Control reference", "Link direction code" ] }, { "id": "rctl-control-q-link-mechanism", "text": "By what mechanism is the control claimed to treat the risk: likelihood, impact, detection latency or transfer support?", "kind": "definition", "answer_data": [ "Treatment mechanism code, possibly multi-valued", "Mechanism description text", "Risk response type code" ] }, { "id": "rctl-control-q-link-magnitude", "text": "What magnitude of reduction is claimed, on what scale, and is the claim estimated or demonstrated?", "kind": "measurement", "answer_data": [ "Claimed reduction quantity and unit", "Scale or model identifier", "Claim basis code: estimated, analysed or tested" ] }, { "id": "rctl-control-q-link-provenance", "text": "Who asserted this linkage, from which analysis, and at what event and observation times?", "kind": "provenance", "answer_data": [ "Asserting party reference", "Source analysis reference", "Event time and observation time in RFC 3339" ] }, { "id": "rctl-control-q-link-retirement", "text": "What causes this linkage to be superseded or retired, and how is the prior link preserved?", "kind": "lifecycle", "answer_data": [ "Retirement trigger codes", "Superseding link reference", "Superseded-at timestamp and reason code" ] } ], "data_elements": [ { "id": "rctl-control-de-risk-ref", "name": "Risk statement reference", "description": "Resolvable reference to the risk record in the owning risk register.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-011" ] }, { "id": "rctl-control-de-treatment-mechanism", "name": "Claimed treatment mechanism", "description": "How the control is claimed to act on the risk: reduce likelihood, reduce impact, shorten detection or containment time, or support transfer.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-002", "SRC-021" ] }, { "id": "rctl-control-de-risk-response-type", "name": "Risk response type served", "description": "The risk response the link serves, drawn from the risk model's response vocabulary.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-011" ] }, { "id": "rctl-control-de-claim-basis", "name": "Claim basis", "description": "Whether the treatment claim is estimated, analytically derived or demonstrated by testing.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-019", "SRC-006" ] }, { "id": "rctl-control-de-link-asserted-at", "name": "Link assertion event time", "description": "Event time at which the linkage was asserted, recorded separately from the ingestion time of the record.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-016", "SRC-015" ] } ], "artifacts": [], "inline_only_rationale": "A link is a relationship assertion between two externally owned records. Both endpoints are artifacts of other models, so the only local content is the qualified edge itself, which is best held as inline reference data that can be traversed without materialising a document." }, { "id": "rctl-control-coverage-dependency", "name": "Many-to-many coverage and control dependency structure", "description": "The aggregate view over links: which control sets cover which risks and vice versa, coverage completeness and precision, uncovered risks and unlinked controls, plus dependency and reliance edges between controls including reliance on general IT controls, shared services and inherited controls.", "source_refs": [ "SRC-019", "SRC-017", "SRC-014", "SRC-015" ], "questions": [ { "id": "rctl-control-q-coverage-set", "text": "Which controls together are claimed to cover a given risk, and can any one of them cover it alone?", "kind": "composition", "answer_data": [ "Coverage edge set", "Sufficiency flag per control", "Capability grouping reference" ] }, { "id": "rctl-control-q-coverage-precision", "text": "At what level of precision does the control set operate relative to the risk it is claimed to cover?", "kind": "quality", "answer_data": [ "Precision statement text", "Threshold or tolerance value", "Assessing party reference" ] }, { "id": "rctl-control-q-dependency-edges", "text": "Which other controls must operate for this control to be effective, and what happens when they fail?", "kind": "relationship", "answer_data": [ "Dependency control references", "Dependency type code", "Failure propagation description" ] }, { "id": "rctl-control-q-coverage-gaps", "text": "Which linked risks currently have no operating control, and which controls have no linked risk?", "kind": "validation", "answer_data": [ "Uncovered risk references", "Unlinked control references", "Evaluation timestamp" ] }, { "id": "rctl-control-q-coverage-traversal", "text": "How is the coverage set expressed so a consumer can traverse it without loading the full catalogue?", "kind": "interoperability", "answer_data": [ "Edge-list projection form", "Reference resolution rule", "Pagination or partition strategy" ] } ], "data_elements": [ { "id": "rctl-control-de-coverage-edge", "name": "Coverage edge set", "description": "The set of risk-to-control edges scoped to the host subject, each carrying a sufficiency flag.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-002", "SRC-015" ] }, { "id": "rctl-control-de-coverage-completeness", "name": "Coverage completeness", "description": "Assessed completeness of the control set against the linked risk, on a declared vocabulary.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-019", "SRC-026" ] }, { "id": "rctl-control-de-coverage-precision", "name": "Coverage precision note", "description": "Statement of the level of precision at which the control set acts relative to the risk.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-019" ] }, { "id": "rctl-control-de-dependency-ref", "name": "Control dependency reference", "description": "References to controls, shared services or inherited controls this control relies on, with dependency type.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014", "SRC-017", "SRC-019" ] }, { "id": "rctl-control-de-uncovered-risk-ref", "name": "Uncovered risk reference", "description": "References to in-scope risks with no linked control in an operating state.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-026" ] } ], "artifacts": [ { "id": "rctl-control-artifact-coverage-matrix", "name": "Risk-to-control coverage matrix", "description": "A versioned projection of the many-to-many coverage and dependency graph for one host subject, showing per-risk control sets, sufficiency flags, dependency edges, uncovered risks and unlinked controls at a stated evaluation time.", "media_or_form": [ "many-to-many matrix", "edge-list record set", "graph projection" ], "serial": true, "identity_strategy": "Authoritative master-system matrix identifier where a governance system of record issues one; otherwise a governed IRI in the Dimension namespace; otherwise a UUID or ULID minted at first generation. The evaluation time is an attribute, never part of the identifier.", "source_refs": [ "SRC-015", "SRC-002", "SRC-019" ] } ], "inline_only_rationale": null } ] }, { "id": "rctl-control-framework-crosswalk", "name": "External framework alignment", "description": "Secondary mappings from the bound control to entries in other catalogues and outcome frameworks, held strictly as alignment.", "source_refs": [ "SRC-022", "SRC-025", "SRC-014" ], "findings": [ { "id": "rctl-control-crosswalk-alignment", "name": "Framework crosswalk without conformance claim", "description": "Mappings from the bound control to entries in other frameworks, each carrying relation strength, the target framework version, the mapping author and date, and an explicit disclaimer that the mapping asserts alignment only and never conformance, implementation or effectiveness.", "source_refs": [ "SRC-022", "SRC-025", "SRC-014", "SRC-015" ], "questions": [ { "id": "rctl-control-q-crosswalk-targets", "text": "To which entries in other frameworks is this control mapped, and with what relation strength?", "kind": "interoperability", "answer_data": [ "Target framework entry references", "Relation strength code: equivalent, subset, superset, related, no-match", "Target framework identifier" ] }, { "id": "rctl-control-q-crosswalk-provenance", "text": "Who authored each mapping, against which target framework version, and when?", "kind": "provenance", "answer_data": [ "Mapping author reference", "Target framework version label", "Authoring timestamp in RFC 3339" ] }, { "id": "rctl-control-q-crosswalk-disclaimer", "text": "What does this mapping explicitly not assert about conformance, implementation or effectiveness?", "kind": "constraint", "answer_data": [ "Non-conformance disclaimer flag", "Prohibited inference list", "Reference to the governing policy" ] }, { "id": "rctl-control-q-crosswalk-revalidation", "text": "How is a mapping revalidated when either the source or the target framework version changes?", "kind": "validation", "answer_data": [ "Revalidation trigger codes", "Last revalidation timestamp", "Revalidation outcome code" ] } ], "data_elements": [ { "id": "rctl-control-de-crosswalk-target", "name": "Crosswalk target reference", "description": "Reference to an entry in another catalogue or outcome framework.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-022", "SRC-014" ] }, { "id": "rctl-control-de-crosswalk-relation", "name": "Crosswalk relation strength", "description": "Declared relation between the bound control and the target entry.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-022", "SRC-025" ] }, { "id": "rctl-control-de-crosswalk-target-version", "name": "Crosswalk target version", "description": "Version label of the target framework the mapping was authored against.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-022", "SRC-015" ] }, { "id": "rctl-control-de-crosswalk-disclaimer", "name": "Non-conformance disclaimer", "description": "Mandatory flag asserting that the mapping establishes alignment only and confers no conformance or effectiveness meaning.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-022", "SRC-025" ] } ], "artifacts": [], "inline_only_rationale": "Crosswalks are pure reference data pointing at externally governed framework entries. Publishing them as a local artifact would encourage downstream consumers to treat a mapping table as an assurance deliverable, which is precisely the inference this model forbids." } ] } ] }, { "id": "rctl-control-assurance", "name": "Design, implementation, operation, evidence and tested effectiveness", "description": "The five separately recorded states of a control for the host subject, the assessment and evidence that support them, and the contribution the result makes to residual risk.", "rationale": "Every consulted assurance source separates the question of whether a control is designed adequately from whether it is implemented, whether it operates and whether its operation has been tested. PCAOB AS 2201 distinguishes design testing from operating-effectiveness testing and grades deficiencies accordingly; SP 800-53A and OSCAL separate implementation status from assessed objective status and attach expiry to results; the internal-control standards require components to be present and functioning rather than merely documented. Collapsing these states is the single most common failure this bundle exists to prevent.", "source_refs": [ "SRC-019", "SRC-006", "SRC-016", "SRC-017", "SRC-026" ], "layers": [ { "id": "rctl-control-state-assertions", "name": "Design, implementation and operating assertions", "description": "Three distinct status assertions about the control for this subject, each with its own basis, determining party and time, and none derivable from another.", "source_refs": [ "SRC-019", "SRC-017", "SRC-011", "SRC-018" ], "findings": [ { "id": "rctl-control-design-assertion", "name": "Design adequacy assertion", "description": "The assertion that the control, if operated as prescribed, would achieve its objective: design status, design rationale, the threshold or precision at which it would act, the determining party and time, and any recorded design limitation or design deficiency reference. Explicitly independent of whether the control is implemented or operating.", "source_refs": [ "SRC-019", "SRC-021", "SRC-020", "SRC-006" ], "questions": [ { "id": "rctl-control-q-design-status", "text": "What is the current design status of the control for this subject, and what does that value deliberately exclude?", "kind": "state", "answer_data": [ "Design status code", "Excluded inferences statement", "Vocabulary identifier" ] }, { "id": "rctl-control-q-design-coverage", "text": "If operated exactly as prescribed, which part of the objective would the control achieve and which part would it not?", "kind": "requirement", "answer_data": [ "Achieved objective portion text", "Residual objective gap text", "Supporting reference" ] }, { "id": "rctl-control-q-design-precision", "text": "At what threshold, tolerance or level of precision is the control designed to act?", "kind": "measurement", "answer_data": [ "Threshold value and unit", "Tolerance description", "Basis for the threshold" ] }, { "id": "rctl-control-q-design-determination", "text": "Who determined that the design is adequate, on what date, and against which criteria?", "kind": "decision", "answer_data": [ "Determining party reference", "Determination event time in RFC 3339", "Criteria reference" ] }, { "id": "rctl-control-q-design-limitation", "text": "What known design limitation or design deficiency is recorded, and which external record tracks it?", "kind": "exception", "answer_data": [ "Design limitation text", "Design deficiency severity code", "External tracking record reference" ] } ], "data_elements": [ { "id": "rctl-control-de-design-status", "name": "Design status", "description": "Assertion of design adequacy on a declared vocabulary, independent of implementation and operation.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-019", "SRC-021" ] }, { "id": "rctl-control-de-design-rationale", "name": "Design rationale", "description": "Locally authored reasoning for the design determination, referencing but not reproducing the procedure or configuration.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-019", "SRC-020" ] }, { "id": "rctl-control-de-design-precision", "name": "Design precision or threshold", "description": "The threshold, tolerance or precision at which the control is designed to act.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-019" ] }, { "id": "rctl-control-de-design-determined-at", "name": "Design determination event time", "description": "Event time of the design determination, recorded separately from ingestion time.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-016", "SRC-018" ] }, { "id": "rctl-control-de-design-deficiency-ref", "name": "Design deficiency reference", "description": "Reference to a record in the deficiency and remediation model describing a design shortfall.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-019", "SRC-011" ] } ], "artifacts": [], "inline_only_rationale": "The design description itself lives in the policy, procedure or configuration model. What is asserted here is a status, a rationale and a threshold, and keeping it inline makes clear that this model judges an externally owned design rather than publishing one." }, { "id": "rctl-control-implementation-assertion", "name": "Implementation state, deviations, exceptions and compensating controls", "description": "Whether the designed control is actually in place for the subject: implementation status and scope of partial implementation, recorded deviations from the design, approved exceptions or waivers with expiry, and references to compensating or alternative controls together with the documented constraint that justifies them. Compensating control definitions and remediation workflow stay in their owning models.", "source_refs": [ "SRC-017", "SRC-011", "SRC-023", "SRC-027", "SRC-019" ], "questions": [ { "id": "rctl-control-q-implementation-status", "text": "What implementation status is recorded for the subject, and what scope does a partial status actually cover?", "kind": "state", "answer_data": [ "Implementation status code", "Partial-scope description", "Vocabulary identifier and version" ] }, { "id": "rctl-control-q-implementation-exception", "text": "Which approved exception or waiver permits a gap in implementation, who approved it, and when does it expire?", "kind": "exception", "answer_data": [ "Exception record reference", "Approving party reference", "Exception expiry timestamp" ] }, { "id": "rctl-control-q-compensating-control", "text": "Which compensating or alternative control is relied on, and against which defined requirement?", "kind": "relationship", "answer_data": [ "Compensating control reference", "Target requirement reference", "Compensating-sense code distinguishing baseline-alternative from deficiency-mitigating" ] }, { "id": "rctl-control-q-implementation-constraint", "text": "What documented technical or business constraint justifies the compensating or alternative approach?", "kind": "constraint", "answer_data": [ "Constraint statement text", "Constraint type code", "Supporting reference and approval" ] }, { "id": "rctl-control-q-implementation-change", "text": "Which change to the subject last altered the implementation state, and when was that change recorded?", "kind": "event", "answer_data": [ "Change record reference", "Change event time in RFC 3339", "Observation time of the resulting assertion" ] } ], "data_elements": [ { "id": "rctl-control-de-implementation-status", "name": "Implementation status", "description": "Status such as implemented, partial, planned, alternative implementation or not applicable, drawn from a declared vocabulary.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-017", "SRC-015" ] }, { "id": "rctl-control-de-deviation-record", "name": "Deviation record", "description": "Recorded departures from the designed implementation, each with a reason and approval reference.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011", "SRC-014" ] }, { "id": "rctl-control-de-exception-ref", "name": "Exception or waiver reference", "description": "Reference to an approved exception permitting non-implementation, held in the governance model.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-027", "SRC-011" ] }, { "id": "rctl-control-de-exception-expires-at", "name": "Exception expiry", "description": "Time at which the approved exception lapses and the gap reverts to unmitigated.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-027", "SRC-016" ] }, { "id": "rctl-control-de-compensating-control-ref", "name": "Compensating control reference", "description": "Reference to the compensating or alternative control relied on, with an explicit sense code.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-023", "SRC-019", "SRC-027" ] }, { "id": "rctl-control-de-constraint-statement", "name": "Documented constraint", "description": "The technical or business constraint that justifies a compensating or alternative approach.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-027" ] } ], "artifacts": [ { "id": "rctl-control-artifact-implementation-assertion-record", "name": "Control implementation assertion record", "description": "A versioned record stating, for one control and one host subject, the implementation status, partial scope, deviations, exceptions with expiry, and compensating or alternative control references with their justifying constraint.", "media_or_form": [ "structured assertion record", "component-scoped implementation statement", "narrative implementation description" ], "serial": true, "identity_strategy": "Authoritative master-system assertion identifier where a governance system of record issues one; otherwise a governed IRI in the Dimension namespace; otherwise a UUID or ULID minted at first assertion. Revision is a separate integer, never encoded as a date.", "source_refs": [ "SRC-017", "SRC-015", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "rctl-control-operating-cadence", "name": "Operating status, frequency and triggers", "description": "How the control actually runs: operating status kept distinct from implementation status, declared frequency or event triggers, the expected occurrence population for a stated period, observed occurrence counts obtained by reference, and suspension or dormancy handling. Execution records belong to the executing system.", "source_refs": [ "SRC-019", "SRC-018", "SRC-028", "SRC-021" ], "questions": [ { "id": "rctl-control-q-operating-status", "text": "Is the control currently operating, and how does that value differ from being implemented?", "kind": "state", "answer_data": [ "Operating status code", "Distinction statement from implementation status", "Status effective-from timestamp" ] }, { "id": "rctl-control-q-operating-frequency", "text": "At what frequency, or on which event triggers, is the control expected to operate?", "kind": "temporal", "answer_data": [ "Frequency code or interval expression", "Event trigger list", "Timing form: on-date, within-date-range or at-frequency" ] }, { "id": "rctl-control-q-operating-occurrences", "text": "How many occurrences were expected and how many observed in the stated period?", "kind": "measurement", "answer_data": [ "Expected occurrence count", "Observed occurrence count", "Period start and end in RFC 3339" ] }, { "id": "rctl-control-q-operating-executor", "text": "Which system or party executes the control, and where is that execution recorded?", "kind": "process", "answer_data": [ "Executing system or party reference", "Execution record location reference", "Retrieval method" ] }, { "id": "rctl-control-q-operating-suspension", "text": "What suspends or resumes operation of the control, and how is a dormant period represented?", "kind": "lifecycle", "answer_data": [ "Suspension trigger codes", "Suspension and resumption timestamps", "Dormancy representation rule" ] } ], "data_elements": [ { "id": "rctl-control-de-operating-status", "name": "Operating status", "description": "Whether the control is operating, suspended or not operating, distinct from implementation status.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-019", "SRC-021" ] }, { "id": "rctl-control-de-operating-frequency", "name": "Operating frequency", "description": "Declared cadence at which the control is expected to operate.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-018", "SRC-028" ] }, { "id": "rctl-control-de-operating-trigger", "name": "Operating trigger", "description": "Events that cause the control to operate where it is not periodic.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-018", "SRC-028" ] }, { "id": "rctl-control-de-expected-occurrences", "name": "Expected occurrence count", "description": "Population of expected control occurrences in the stated period.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-019" ] }, { "id": "rctl-control-de-observed-occurrences", "name": "Observed occurrence count", "description": "Count of occurrences obtained by reference from the executing system, with its retrieval time.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-028", "SRC-019" ] }, { "id": "rctl-control-de-operating-period", "name": "Operating period", "description": "Start and end of the period over which operation is claimed, both RFC 3339 with offset.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-018", "SRC-016" ] } ], "artifacts": [], "inline_only_rationale": "Execution records, logs and telemetry are produced and owned by the executing system and the monitoring model. Only the declared cadence, trigger set and referenced counts belong here, and holding them inline keeps this model from accreting an operational record store." } ] }, { "id": "rctl-control-evidence-assessment", "name": "Assessment and evidence binding", "description": "The binding between an effectiveness assertion and the assessment activity and evidence objects that support it, held as references, methods, times and digests only.", "source_refs": [ "SRC-006", "SRC-024", "SRC-016", "SRC-019" ], "findings": [ { "id": "rctl-control-assessment-evidence-binding", "name": "Assessment method, timing and evidence binding", "description": "Binds an effectiveness assertion to the assessment activity and its evidence: assessment method (examine, interview, test), depth and coverage attributes, sample or population basis, assessment event time and the operating period covered, assessor reference, and evidence references with integrity digests, collection times and expiry. Test cases, results and evidence payloads remain in their owning models.", "source_refs": [ "SRC-006", "SRC-024", "SRC-016", "SRC-018", "SRC-019" ], "questions": [ { "id": "rctl-control-q-evidence-refs", "text": "Which evidence objects support the assertion, and how is each referenced and integrity-bound?", "kind": "evidence", "answer_data": [ "Evidence object references", "Digest value and algorithm at binding time", "Evidence collection time in RFC 3339" ] }, { "id": "rctl-control-q-assessment-method", "text": "Which assessment methods were applied, and at what depth and coverage?", "kind": "process", "answer_data": [ "Method codes: examine, interview, test", "Depth attribute value", "Coverage attribute value" ] }, { "id": "rctl-control-q-assessment-timing", "text": "When was the assessment performed, and which period of control operation does its conclusion cover?", "kind": "temporal", "answer_data": [ "Assessment event time in RFC 3339", "Covered period start and end", "Observation or ingestion time of the binding" ] }, { "id": "rctl-control-q-evidence-sufficiency", "text": "Why is the bound evidence sufficient given the risk associated with this control?", "kind": "quality", "answer_data": [ "Sufficiency rationale text", "Control risk rating used", "Sample size and selection basis" ] }, { "id": "rctl-control-q-interim-rollforward", "text": "If testing was performed at an interim date, what supports extending the conclusion to the end of the period?", "kind": "validation", "answer_data": [ "Rollforward procedure description", "Remaining-period length", "Change-in-control assertion and supporting reference" ] } ], "data_elements": [ { "id": "rctl-control-de-assessment-ref", "name": "Assessment reference", "description": "Reference to the assessment plan, activity or result record in the owning assessment model.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-018", "SRC-016" ] }, { "id": "rctl-control-de-assessment-method", "name": "Assessment method", "description": "One or more of examine, interview and test, as defined by the assessment vocabulary.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-024", "SRC-006" ] }, { "id": "rctl-control-de-assessment-depth-coverage", "name": "Depth and coverage attributes", "description": "Rigour and breadth attributes attached to the applied assessment methods.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006", "SRC-019" ] }, { "id": "rctl-control-de-sample-basis", "name": "Sample basis", "description": "Population, sample size and selection method used for the assessment.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-019", "SRC-006" ] }, { "id": "rctl-control-de-assessment-performed-at", "name": "Assessment event time", "description": "Event time at which the assessment was performed, distinct from the binding's ingestion time.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-016", "SRC-018" ] }, { "id": "rctl-control-de-evidence-ref", "name": "Evidence reference", "description": "Reference to an evidence object held by the evidence model.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016", "SRC-019" ] }, { "id": "rctl-control-de-evidence-digest", "name": "Evidence integrity digest", "description": "Digest asserted by the owning evidence model at binding time, with algorithm identifier.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016", "SRC-015" ] } ], "artifacts": [ { "id": "rctl-control-artifact-assessment-evidence-manifest", "name": "Assessment and evidence binding manifest", "description": "A versioned manifest listing, for one effectiveness assertion, the assessment references, applied methods, depth and coverage, sample basis, timing, assessor reference and each bound evidence reference with its digest and collection time.", "media_or_form": [ "reference manifest", "digest-bound evidence index", "assessment binding record" ], "serial": true, "identity_strategy": "Authoritative master-system manifest identifier where an assessment system of record issues one; otherwise a governed IRI in the Dimension namespace; otherwise a UUID or ULID minted at first binding. Assessment dates are attributes, never identifier components.", "source_refs": [ "SRC-016", "SRC-018", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "rctl-control-effectiveness-residual", "name": "Tested effectiveness and residual contribution", "description": "The conclusion drawn about operating effectiveness with its confidence and expiry, and the contribution that conclusion makes to the residual position of the linked risk.", "source_refs": [ "SRC-019", "SRC-016", "SRC-002", "SRC-025" ], "findings": [ { "id": "rctl-control-effectiveness-conclusion", "name": "Tested effectiveness conclusion, confidence and validity", "description": "The conclusion about operating effectiveness on a named vocabulary, with its scope, the assessment and evidence bindings that are its only permitted basis, an attached confidence and its limits, a validity window with invalidation triggers, and any deficiency severity with a reference to the record tracking remediation.", "source_refs": [ "SRC-019", "SRC-016", "SRC-006", "SRC-025", "SRC-029" ], "questions": [ { "id": "rctl-control-q-conclusion-value", "text": "What effectiveness conclusion was reached, on which named vocabulary, and over what scope?", "kind": "decision", "answer_data": [ "Conclusion code", "Vocabulary identifier and version", "Conclusion scope statement" ] }, { "id": "rctl-control-q-conclusion-basis", "text": "Which assessment and evidence bindings form the sole permitted basis for this conclusion?", "kind": "evidence", "answer_data": [ "Binding manifest references", "Prohibited-basis attestation", "Concluding party reference" ] }, { "id": "rctl-control-q-conclusion-confidence", "text": "What confidence is attached to the conclusion, and what limits that confidence?", "kind": "quality", "answer_data": [ "Confidence value and scale", "Limiting factors text", "Sample or coverage shortfall note" ] }, { "id": "rctl-control-q-conclusion-validity", "text": "Until when is the conclusion valid, and which events invalidate it before that time?", "kind": "temporal", "answer_data": [ "Valid-until timestamp in RFC 3339", "Invalidation trigger codes", "Behaviour on expiry" ] }, { "id": "rctl-control-q-conclusion-deficiency", "text": "If the conclusion is adverse, what deficiency severity is recorded and which external record tracks remediation?", "kind": "exception", "answer_data": [ "Deficiency severity code and vocabulary", "External remediation record reference", "Severity determination time" ] } ], "data_elements": [ { "id": "rctl-control-de-effectiveness-conclusion", "name": "Effectiveness conclusion", "description": "Conclusion value on a named vocabulary, never derived from documentation, mapping or incident absence.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-019", "SRC-006", "SRC-025" ] }, { "id": "rctl-control-de-conclusion-vocabulary", "name": "Conclusion vocabulary", "description": "Identifier and version of the vocabulary the conclusion value is drawn from.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-006", "SRC-025", "SRC-019" ] }, { "id": "rctl-control-de-conclusion-basis-ref", "name": "Conclusion basis reference", "description": "References to the assessment and evidence binding manifests that support the conclusion.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-016", "SRC-006" ] }, { "id": "rctl-control-de-conclusion-confidence", "name": "Conclusion confidence", "description": "Declared confidence in the conclusion together with the factors limiting it.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-019", "SRC-025" ] }, { "id": "rctl-control-de-conclusion-valid-until", "name": "Conclusion validity expiry", "description": "Time after which the conclusion is no longer current and degrades to unknown.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-016", "SRC-028" ] }, { "id": "rctl-control-de-deficiency-severity", "name": "Deficiency severity", "description": "Severity value recorded for an adverse conclusion, on the declared severity vocabulary.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-019", "SRC-011" ] } ], "artifacts": [ { "id": "rctl-control-artifact-effectiveness-conclusion-statement", "name": "Control effectiveness conclusion statement", "description": "A versioned statement recording the effectiveness conclusion for one control and subject, its vocabulary, scope, basis references, confidence, validity window, invalidation triggers, deficiency severity and approving party.", "media_or_form": [ "structured conclusion record", "approved assurance statement", "human-readable conclusion note" ], "serial": true, "identity_strategy": "Authoritative master-system conclusion identifier where an assurance system of record issues one; otherwise a governed IRI in the Dimension namespace; otherwise a UUID or ULID minted at first conclusion. Validity dates are attributes, never identifier components.", "source_refs": [ "SRC-016", "SRC-019", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "rctl-control-residual-contribution", "name": "Residual contribution and acceptance linkage", "description": "How the assessed effectiveness of this control contributes to the residual position of the linked risk: the attributed change from inherent to residual, the attribution method and its effective time, the attribution status, and references to the residual risk record and any acceptance decision. Residual values, appetite thresholds and acceptance decisions are owned by the risk model.", "source_refs": [ "SRC-002", "SRC-011", "SRC-026", "SRC-029", "SRC-020" ], "questions": [ { "id": "rctl-control-q-residual-delta", "text": "What change from the inherent to the residual position is attributed to this control, and on which scale?", "kind": "measurement", "answer_data": [ "Attributed reduction quantity and unit", "Scale or scoring model reference", "Inherent and residual reference points" ] }, { "id": "rctl-control-q-residual-method", "text": "Which effectiveness conclusion and which attribution method produced the attributed change?", "kind": "provenance", "answer_data": [ "Conclusion statement reference", "Attribution method code", "Attributing party and event time" ] }, { "id": "rctl-control-q-residual-acceptance", "text": "Which residual risk record does this contribution feed, and has the risk model accepted the attribution?", "kind": "relationship", "answer_data": [ "Residual risk record reference", "Attribution acceptance status", "Acceptance decision reference" ] }, { "id": "rctl-control-q-residual-guardrail", "text": "What prevents an untested or ineffective control from reducing the recorded residual position?", "kind": "constraint", "answer_data": [ "Guardrail rule statement", "Minimum conclusion value required", "Rejection behaviour on failure" ] }, { "id": "rctl-control-q-residual-expiry", "text": "When the supporting conclusion expires, what happens to this residual contribution?", "kind": "lifecycle", "answer_data": [ "Suspension rule on expiry", "Notification target reference", "Reinstatement condition" ] } ], "data_elements": [ { "id": "rctl-control-de-residual-risk-ref", "name": "Residual risk record reference", "description": "Reference to the residual risk record in the owning risk model that this contribution feeds.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-011" ] }, { "id": "rctl-control-de-attributed-reduction", "name": "Attributed reduction", "description": "Quantified or ordinal change from inherent to residual attributed to this control.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-026" ] }, { "id": "rctl-control-de-attribution-method", "name": "Attribution method", "description": "Method used to derive the attributed change, drawn from a declared vocabulary.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-029" ] }, { "id": "rctl-control-de-attribution-status", "name": "Attribution status", "description": "Whether the attribution is claimed, accepted by the risk owner, suspended on expiry or rejected.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-011" ] }, { "id": "rctl-control-de-attribution-effective-at", "name": "Attribution effective time", "description": "Event time from which the attribution applies, recorded separately from ingestion time.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-016", "SRC-002" ] }, { "id": "rctl-control-de-acceptance-decision-ref", "name": "Acceptance decision reference", "description": "Reference to the risk acceptance or authorization decision recorded in the risk model.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011", "SRC-002" ] } ], "artifacts": [], "inline_only_rationale": "The residual value, the appetite thresholds and the acceptance decision are all owned by the risk model. What is held here is an attribution claim plus pointers, and publishing it as an artifact would create a second, competing statement of residual risk." } ] } ] }, { "id": "rctl-gov-accountability-bundle", "name": "Accountability, authority and assurance basis", "description": "Who is accountable for a risk-control binding, who may assert or accept it, which duties must stay separated, and on what criteria and assurance basis its conclusions rest.", "rationale": "Risk records are only decision-usable if the accountable party, the authority that accepted residual risk, the independence of the reviewer and the criteria applied are all recoverable. Standards require named risk owners approving treatment and accepting residual risk, named authorizing officials making risk acceptance decisions, and independence of assurance from management.", "source_refs": [ "SRC-030", "SRC-031", "SRC-011", "SRC-035", "SRC-037" ], "layers": [ { "id": "rctl-gov-ownership-authority-layer", "name": "Ownership, assertion authority and duty separation", "description": "Accountability assignment for the binding, the authority conditions governing its assertion and acceptance, and the incompatible-duty constraints applied to those acts.", "source_refs": [ "SRC-031", "SRC-011", "SRC-035" ], "findings": [ { "id": "rctl-gov-accountable-owner", "name": "Accountable owner of the projected risk and of each linked control", "description": "Identifies the party accountable for the residual risk conclusion on this host and the party accountable for each linked control, distinguishes accountability from delegated operational execution, and places each party in a governance line.", "source_refs": [ "SRC-031", "SRC-011", "SRC-035" ], "questions": [ { "id": "rctl-gov-q-owner-party", "text": "Which party holds accountability for the residual risk conclusion on this host record, and which party holds accountability for each linked control?", "kind": "ownership", "answer_data": [ "risk owner party reference", "control owner party reference per linked control", "basis on which accountability was assigned" ] }, { "id": "rctl-gov-q-owner-delegation", "text": "How is operational execution delegated to another party without transferring accountability for the binding?", "kind": "authority", "answer_data": [ "delegation instrument reference", "delegated scope", "retained accountability statement", "delegation effective period" ] }, { "id": "rctl-gov-q-owner-line", "text": "Which governance line does each named party occupy for this binding, and does any party occupy more than one line?", "kind": "classification", "answer_data": [ "governance line code per party", "multi-line occupancy flag", "declared mitigation where lines overlap" ] }, { "id": "rctl-gov-q-owner-vacancy", "text": "What becomes of the binding when the accountable owner role is vacant, reassigned, or the owning organisational unit is dissolved?", "kind": "exception", "answer_data": [ "interim owner reference", "escalation target", "maximum permitted vacancy duration", "binding state applied during vacancy" ] } ], "data_elements": [ { "id": "rctl-gov-de-risk-owner-ref", "name": "Risk owner reference", "description": "Typed reference to the party accountable for the residual risk conclusion on this host record.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-031", "SRC-011" ] }, { "id": "rctl-gov-de-control-owner-ref", "name": "Control owner reference", "description": "Typed reference to the party accountable for each control linked to the projected risk.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-031", "SRC-035" ] }, { "id": "rctl-gov-de-delegation-ref", "name": "Delegation reference", "description": "Reference to the instrument delegating operational execution without transferring accountability.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-035" ] }, { "id": "rctl-gov-de-governance-line", "name": "Governance line code", "description": "Code placing a named party in a governing-body, first-line, second-line or independent-assurance role for this binding.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-035" ] }, { "id": "rctl-gov-de-owner-effective-from", "name": "Owner effective from", "description": "Instant from which the recorded accountability assignment applies to this binding.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-011" ] } ], "artifacts": [], "inline_only_rationale": "Accountable-owner context is a set of typed references into the adopting Dimension's party and organisational-role registry plus a delegation reference and an effective period. Materialising an ownership artifact here would duplicate party records and delegation instruments that are owned by the referenced identity and authority models, and would create a second, drifting copy of organisational structure." }, { "id": "rctl-gov-assertion-authority", "name": "Authority to assert, change, accept or retire a binding", "description": "Separates authority to assert a control linkage from authority to accept the residual risk that remains, ties each act to a versioned authority threshold table, and defines admissibility preconditions for changing an already accepted binding.", "source_refs": [ "SRC-031", "SRC-011", "SRC-034" ], "questions": [ { "id": "rctl-gov-q-authority-threshold", "text": "Which authority level is required to accept a residual risk in each severity band, and in which versioned threshold table is that requirement defined?", "kind": "authority", "answer_data": [ "required authority level per severity band", "threshold table identifier and version", "effective period of the table" ] }, { "id": "rctl-gov-q-authority-split", "text": "What distinguishes authority to assert a control linkage from authority to accept the residual risk that remains after it?", "kind": "decision", "answer_data": [ "assertion authority level", "acceptance authority level", "rule preventing one actor from holding both for the same binding" ] }, { "id": "rctl-gov-q-authority-precondition", "text": "Which preconditions must be satisfied before a change to an already accepted binding is admissible?", "kind": "constraint", "answer_data": [ "current lifecycle state", "matching base revision identifier", "absence of blocking legal hold", "re-acceptance requirement flag" ] }, { "id": "rctl-gov-q-authority-stale", "text": "How is an acceptance made under a superseded threshold table detected and re-validated?", "kind": "validation", "answer_data": [ "threshold table version recorded at acceptance", "current table version", "re-validation due indicator", "re-validation outcome reference" ] } ], "data_elements": [ { "id": "rctl-gov-de-required-authority-level", "name": "Required authority level", "description": "Authority level that the acting party had to hold for the recorded act on this binding.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-011" ] }, { "id": "rctl-gov-de-acceptance-decision-ref", "name": "Risk acceptance decision reference", "description": "Reference to the authoritative decision accepting the residual risk for this host record.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-031", "SRC-011" ] }, { "id": "rctl-gov-de-authority-basis-ref", "name": "Authority basis reference", "description": "Reference to the policy, charter or delegation that confers the authority exercised.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-035" ] }, { "id": "rctl-gov-de-threshold-table-version", "name": "Authority threshold table version", "description": "Identifier and version of the table mapping residual severity bands to required authority levels.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-030", "SRC-034" ] }, { "id": "rctl-gov-de-authorization-time", "name": "Authorization time", "description": "Instant at which the authorising act occurred, recorded separately from the instant it was ingested into this model.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-011", "SRC-032" ] } ], "artifacts": [ { "id": "rctl-gov-art-authorization-statement", "name": "Binding authorization statement", "description": "Immutable statement recording which actor authorised which binding revision, under which authority basis and threshold table version, and with what admissibility verdict. It records the decision about this model's own record; it is not a general-purpose access token and confers no runtime privilege.", "media_or_form": [ "structured record", "signed statement", "append-only ledger entry" ], "serial": true, "identity_strategy": "Authoritative master-system identifier issued by the governing GRC or ISMS system of record when present; otherwise the governed IRI of the binding revision; otherwise a Dimension-assigned UUID or ULID. Never a date, cycle label or table version.", "source_refs": [ "SRC-011", "SRC-014" ] } ], "inline_only_rationale": null }, { "id": "rctl-gov-duty-separation", "name": "Segregation of duties and reviewer independence", "description": "Declares which combinations of asserting, reviewing, approving and accepting the same binding are incompatible for one actor, what establishes reviewer independence from control design and operation, and how overrides and after-the-fact breaches are handled.", "source_refs": [ "SRC-035", "SRC-037", "SRC-014" ], "questions": [ { "id": "rctl-gov-q-sod-incompatible", "text": "Which combinations of asserting, reviewing, approving and accepting the same binding are declared incompatible for one actor?", "kind": "constraint", "answer_data": [ "incompatible duty pair set", "scope of the constraint", "enforcement point reference" ] }, { "id": "rctl-gov-q-sod-independence", "text": "What establishes that the reviewer of a binding is independent of the party that designed or operates the linked control?", "kind": "evidence", "answer_data": [ "independence basis code", "identified threats to independence", "applied safeguards", "independence attestation reference" ] }, { "id": "rctl-gov-q-sod-override", "text": "Under what documented circumstances may a duty-separation constraint be overridden, and who may grant that override?", "kind": "exception", "answer_data": [ "override authority level", "permitted grounds", "override expiry", "compensating condition" ] }, { "id": "rctl-gov-q-sod-detect", "text": "How are duty-separation breaches detected after the fact when they were not blocked at write time?", "kind": "quality", "answer_data": [ "detection method", "detection interval", "breach disposition", "effect on affected assertions" ] } ], "data_elements": [ { "id": "rctl-gov-de-incompatible-duty-pair", "name": "Incompatible duty pair", "description": "Declared pair of acts on the same binding that one actor may not perform.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-035", "SRC-014" ] }, { "id": "rctl-gov-de-reviewer-independence-basis", "name": "Reviewer independence basis", "description": "Code stating the basis on which the reviewer is independent of control design and operation, with identified threats and safeguards.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-037", "SRC-035" ] }, { "id": "rctl-gov-de-sod-override-ref", "name": "Duty-separation override reference", "description": "Reference to a time-bounded, authorised override of a declared incompatible duty pair.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014" ] } ], "artifacts": [], "inline_only_rationale": "Incompatible-duty constraints and independence bases are declarative parameters attached to the binding and to the roles acting on it. The rules are evaluated at write time by the referenced authorization model and monitored by the referenced audit capability; emitting a separate rule artifact here would create a second rule store competing with the policy model's own, and would imply that this mixin performs enforcement." } ] }, { "id": "rctl-gov-assurance-basis-layer", "name": "Criteria, conflicts and assurance limitations", "description": "The versioned criteria and scales against which residual risk and control effectiveness are judged, how competing criteria are resolved, and what limits reliance on the recorded conclusion.", "source_refs": [ "SRC-030", "SRC-006", "SRC-037" ], "findings": [ { "id": "rctl-gov-criteria-basis", "name": "Assessment criteria binding and conflict resolution", "description": "Records which versioned criteria, scale and risk-appetite statement produced the residual conclusion, what makes those criteria suitable, and which verdict prevails when two applicable frameworks disagree on the same binding.", "source_refs": [ "SRC-030", "SRC-031", "SRC-034", "SRC-037" ], "questions": [ { "id": "rctl-gov-q-criteria-version", "text": "Which versioned criteria, scale and risk-appetite statement were used to derive this residual risk conclusion?", "kind": "measurement", "answer_data": [ "criteria reference and version", "scale identifier and band definitions", "risk appetite or acceptance threshold reference" ] }, { "id": "rctl-gov-q-criteria-conflict", "text": "When two applicable frameworks assign different acceptability verdicts to the same binding, which verdict prevails and on what recorded basis?", "kind": "decision", "answer_data": [ "prevailing framework code", "precedence rule reference", "non-prevailing verdicts retained", "conflict resolution rationale" ] }, { "id": "rctl-gov-q-criteria-suitability", "text": "What makes the chosen criteria suitable, and how are relevance, completeness, reliability and neutrality demonstrated?", "kind": "quality", "answer_data": [ "criteria suitability assertion", "availability of criteria to intended users", "known criteria weaknesses" ] }, { "id": "rctl-gov-q-criteria-change", "text": "How does a change to the criteria or scale version affect conclusions already recorded under the previous version?", "kind": "lifecycle", "answer_data": [ "restatement obligation flag", "grace period", "affected binding set reference", "re-derivation outcome" ] } ], "data_elements": [ { "id": "rctl-gov-de-criteria-ref", "name": "Criteria reference", "description": "Reference to the versioned risk and effectiveness criteria applied to this binding.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-030", "SRC-037" ] }, { "id": "rctl-gov-de-scale-version", "name": "Scale version", "description": "Identifier and version of the severity, likelihood or effectiveness scale used.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-030" ] }, { "id": "rctl-gov-de-appetite-ref", "name": "Risk appetite reference", "description": "Reference to the appetite or acceptance threshold statement against which residual risk was judged acceptable.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-034", "SRC-030" ] }, { "id": "rctl-gov-de-prevailing-framework", "name": "Prevailing framework code", "description": "Code naming the framework whose verdict governs where applicable criteria conflict.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-031", "SRC-034" ] }, { "id": "rctl-gov-de-conflict-resolution-basis", "name": "Conflict resolution basis", "description": "Recorded rationale and precedence rule applied when criteria produced divergent verdicts.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-037" ] } ], "artifacts": [ { "id": "rctl-gov-art-criteria-binding", "name": "Criteria binding record", "description": "Record fixing the criteria, scale, appetite reference and precedence rule in force for a specific binding revision, so that a conclusion remains interpretable after the criteria themselves change.", "media_or_form": [ "structured record", "versioned parameter set" ], "serial": true, "identity_strategy": "Authoritative master-system identifier from the criteria-governing system of record when present; otherwise the governed IRI of the criteria version combined with the binding revision IRI; otherwise a Dimension-assigned UUID or ULID.", "source_refs": [ "SRC-030", "SRC-037" ] } ], "inline_only_rationale": null }, { "id": "rctl-gov-assurance-limitation", "name": "Assurance level, scope limitations and inherited reliance", "description": "Records the level of assurance a control effectiveness conclusion carries, the methods and objects actually examined, what was excluded from scope, and the carve-outs limiting reliance on third-party reports.", "source_refs": [ "SRC-006", "SRC-037", "SRC-016" ], "questions": [ { "id": "rctl-gov-q-assurance-level", "text": "What level of assurance does this effectiveness conclusion carry, and what procedures produced it?", "kind": "quality", "answer_data": [ "assurance level code", "procedure summary", "practitioner or assessor reference", "conclusion wording form" ] }, { "id": "rctl-gov-q-assurance-scope", "text": "Which parts of the control population, period or environment were excluded from the assessment scope?", "kind": "constraint", "answer_data": [ "scope exclusion statements", "sampling basis", "coverage period start and end", "untested population share" ] }, { "id": "rctl-gov-q-assurance-method", "text": "Which assessment methods and objects were applied, and what did each method actually examine?", "kind": "process", "answer_data": [ "assessment method codes", "assessment object references", "determination statement outcomes" ] }, { "id": "rctl-gov-q-assurance-inherited", "text": "When effectiveness is inherited from a third-party report, what carve-outs and complementary user-entity controls limit reliance?", "kind": "evidence", "answer_data": [ "inherited report reference", "carve-out description", "complementary control obligations", "report period and its overlap with this binding" ] } ], "data_elements": [ { "id": "rctl-gov-de-assurance-level", "name": "Assurance level", "description": "Declared level of assurance carried by the effectiveness conclusion, distinguishing reasonable from limited assurance and unassured self-assertion.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-037" ] }, { "id": "rctl-gov-de-assessment-method", "name": "Assessment method", "description": "Method applied to reach the conclusion, such as examine, interview or test, with the objects to which it was applied.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "rctl-gov-de-scope-exclusion", "name": "Scope exclusion", "description": "Statement of a population, period or environment segment excluded from the assessment.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-037" ] }, { "id": "rctl-gov-de-inherited-report-ref", "name": "Inherited assurance report reference", "description": "Reference to an external assurance or attestation report relied upon for this conclusion.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-037", "SRC-016" ] }, { "id": "rctl-gov-de-coverage-period", "name": "Assessment coverage period", "description": "Start and end of the period the conclusion covers, distinct from the instant the conclusion was reached.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006", "SRC-037" ] } ], "artifacts": [ { "id": "rctl-gov-art-assurance-statement", "name": "Assurance limitation statement", "description": "Statement accompanying an effectiveness conclusion that declares assurance level, methods and objects, coverage period, scope exclusions, and carve-outs on any inherited report, so that a consumer can bound its reliance.", "media_or_form": [ "structured record", "narrative statement" ], "serial": true, "identity_strategy": "Authoritative master-system identifier from the assurance provider's engagement system when present; otherwise the governed IRI of the assessment result; otherwise a Dimension-assigned UUID or ULID.", "source_refs": [ "SRC-037", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "rctl-gov-lifecycle-bundle", "name": "Host-scoped lifecycle, currency, provenance and evidence", "description": "How a binding moves through its host-scoped states, how long a conclusion stays current, how corrections are made by supersession, and how each assertion is attributed and bound to evidence.", "rationale": "A risk management system must be a continuous iterative process with regular systematic review and updating, and risk management activities must be traceable. That requires explicit states, an expiry semantics for conclusions, correction without silent mutation, and attribution of every assertion to an agent and activity.", "source_refs": [ "SRC-030", "SRC-011", "SRC-032", "SRC-034" ], "layers": [ { "id": "rctl-gov-state-currency-layer", "name": "Binding state, assessment currency and supersession", "description": "The permitted states of a binding on its host, the validity window and expiry of its assessment, and the rules for correcting a relied-upon assertion by issuing a successor.", "source_refs": [ "SRC-011", "SRC-034", "SRC-030" ], "findings": [ { "id": "rctl-gov-binding-state", "name": "Host-scoped lifecycle state of the binding", "description": "Enumerates the states a risk-control binding may occupy on its host record, the permitted transitions, the constraint the host lifecycle imposes, and how duplicate active bindings between the same risk and control are resolved.", "source_refs": [ "SRC-011", "SRC-031", "SRC-034" ], "questions": [ { "id": "rctl-gov-q-state-enum", "text": "Which lifecycle states may a risk-control binding occupy on its host record, and which transitions between them are permitted?", "kind": "state", "answer_data": [ "state enumeration", "permitted transition set", "required actor authority per transition" ] }, { "id": "rctl-gov-q-state-host", "text": "How does the host record's own lifecycle constrain or terminate the state of the binding?", "kind": "lifecycle", "answer_data": [ "host state to binding state mapping", "cascade rule on host retirement", "orphan handling rule" ] }, { "id": "rctl-gov-q-state-terminal", "text": "Which states are terminal, and which obligations survive after a binding leaves the active state?", "kind": "requirement", "answer_data": [ "terminal state set", "surviving retention obligation", "surviving disclosure obligation", "surviving notification obligation" ] }, { "id": "rctl-gov-q-state-concurrent", "text": "May more than one active binding exist between the same risk and the same control on one host, and how is that resolved?", "kind": "relationship", "answer_data": [ "uniqueness constraint", "discriminator attribute", "duplicate resolution rule" ] } ], "data_elements": [ { "id": "rctl-gov-de-binding-state", "name": "Binding state", "description": "Current host-scoped state of the binding, such as draft, asserted, under review, accepted, expired, superseded, withdrawn or tombstoned.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-011" ] }, { "id": "rctl-gov-de-state-entered-at", "name": "State entered at", "description": "Instant at which the binding entered its current state.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-011", "SRC-032" ] }, { "id": "rctl-gov-de-transition-reason", "name": "Transition reason", "description": "Code explaining why the binding moved to its current state.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-030" ] }, { "id": "rctl-gov-de-host-record-ref", "name": "Host record reference", "description": "Reference to the record onto which this risk-control binding is projected.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-031", "SRC-016" ] } ], "artifacts": [], "inline_only_rationale": "The binding state and its transition metadata are inline attributes of the mixin as projected on its host record; because the mixin is host-scoped by default, no separate lifecycle document exists to materialise. Emitting a state artifact would imply a standalone risk or control lifecycle that this model explicitly does not own, and would compete with the host record's own state representation." }, { "id": "rctl-gov-assessment-currency", "name": "Assessment currency, expiry and reassessment triggers", "description": "Defines how long a residual risk and effectiveness conclusion remains valid, which events force reassessment ahead of schedule, what status an expired but unreassessed binding carries, and which timestamp starts the currency clock.", "source_refs": [ "SRC-034", "SRC-011", "SRC-030", "SRC-032" ], "questions": [ { "id": "rctl-gov-q-currency-window", "text": "For how long is this residual risk conclusion valid, and what fixes the end of its validity window?", "kind": "temporal", "answer_data": [ "valid-until instant", "review interval", "rule fixing the window", "source of the interval" ] }, { "id": "rctl-gov-q-currency-trigger", "text": "Which events force reassessment of this binding before its scheduled expiry?", "kind": "event", "answer_data": [ "trigger event codes", "trigger detection source", "reassessment deadline after trigger" ] }, { "id": "rctl-gov-q-currency-expired", "text": "What status does a binding carry once its assessment has expired but has not yet been reassessed?", "kind": "state", "answer_data": [ "currency status code", "permitted reliance on an expired conclusion", "escalation target" ] }, { "id": "rctl-gov-q-currency-clock", "text": "Which timestamp starts the currency clock: the observed condition, the assessor's conclusion, or the recording of the assertion?", "kind": "provenance", "answer_data": [ "observed-condition instant", "conclusion instant", "recording instant", "declared clock-start selection" ] } ], "data_elements": [ { "id": "rctl-gov-de-assessed-at", "name": "Assessed at", "description": "Instant at which the assessor reached the recorded conclusion, distinct from the instant the conclusion was ingested.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-006", "SRC-032" ] }, { "id": "rctl-gov-de-valid-until", "name": "Valid until", "description": "Instant after which the recorded conclusion is no longer current absent reassessment.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-034", "SRC-011" ] }, { "id": "rctl-gov-de-review-interval", "name": "Review interval", "description": "Maximum interval between systematic reviews of this binding.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-034", "SRC-030" ] }, { "id": "rctl-gov-de-currency-status", "name": "Currency status", "description": "Derived status expressing whether the conclusion is current, approaching expiry, expired or invalidated.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-011" ] }, { "id": "rctl-gov-de-reassessment-trigger", "name": "Reassessment trigger", "description": "Code identifying an event that obliges reassessment before scheduled expiry, such as a host change, control failure, post-market signal or criteria change.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-034", "SRC-030" ] } ], "artifacts": [], "inline_only_rationale": "Currency is a computed property over inline timestamps, an interval and a trigger set; it is derived by the expiration function rather than authored. Persisting it as an artifact would freeze a value that must be re-derived whenever the clock advances or a trigger fires, and reassessment results themselves are carried as new assertion revisions, not as currency documents." }, { "id": "rctl-gov-supersession-correction", "name": "Revision, supersession and correction of relied-upon assertions", "description": "Determines whether a corrected assertion keeps its identifier with a new revision or receives a successor identifier, what a supersession record must state, which fields may never be edited in place, and who must be notified downstream.", "source_refs": [ "SRC-032", "SRC-016", "SRC-037", "SRC-030" ], "questions": [ { "id": "rctl-gov-q-supersede-identity", "text": "Does a corrected assertion keep the binding identifier and gain a new revision, or does it receive a new identifier that supersedes the prior one?", "kind": "identity", "answer_data": [ "identifier continuity rule", "revision identifier scheme", "successor identifier where issued" ] }, { "id": "rctl-gov-q-supersede-record", "text": "What must a supersession record state about the defect corrected and the period during which the superseded assertion was relied upon?", "kind": "process", "answer_data": [ "defect description", "reliance period start and end", "corrective action reference", "notification obligation" ] }, { "id": "rctl-gov-q-supersede-downstream", "text": "Which downstream consumers must be notified when an accepted binding is superseded, and within what interval?", "kind": "interoperability", "answer_data": [ "subscriber references", "notification interval", "notification payload fields", "acknowledgement requirement" ] }, { "id": "rctl-gov-q-supersede-mutate", "text": "Which fields may never be edited in place, forcing correction by supersession instead?", "kind": "constraint", "answer_data": [ "immutable field set", "mutable field set", "rejection reason code for an in-place edit attempt" ] } ], "data_elements": [ { "id": "rctl-gov-de-revision-id", "name": "Revision identifier", "description": "Monotonic identifier of this revision of the binding, used for optimistic concurrency and for citing a specific state of the record.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-032", "SRC-016" ] }, { "id": "rctl-gov-de-supersedes-ref", "name": "Supersedes reference", "description": "Reference to the assertion revision that this revision replaces.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-032" ] }, { "id": "rctl-gov-de-superseded-by-ref", "name": "Superseded by reference", "description": "Back-reference from a superseded assertion to its successor.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-032" ] }, { "id": "rctl-gov-de-correction-reason", "name": "Correction reason", "description": "Code classifying the defect that made supersession necessary, such as factual error, criteria change, scope error or evidence withdrawal.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-037" ] }, { "id": "rctl-gov-de-reliance-period", "name": "Reliance period", "description": "Period during which the superseded assertion was published and could have been relied upon.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-037", "SRC-030" ] } ], "artifacts": [ { "id": "rctl-gov-art-supersession-record", "name": "Supersession record", "description": "Record linking a superseded assertion revision to its successor, stating the defect corrected, the reliance period and the notification obligation discharged, so that historical decisions remain interpretable.", "media_or_form": [ "structured record", "append-only ledger entry" ], "serial": true, "identity_strategy": "Authoritative master-system identifier of the correction transaction in the system of record when present; otherwise the governed IRI of the successor revision; otherwise a Dimension-assigned UUID or ULID.", "source_refs": [ "SRC-032", "SRC-037" ] } ], "inline_only_rationale": null } ] }, { "id": "rctl-gov-provenance-evidence-layer", "name": "Provenance and evidence integrity", "description": "Attribution of each assertion to an agent and activity, and the integrity binding between an assertion and the evidence it relies on.", "source_refs": [ "SRC-032", "SRC-006", "SRC-016", "SRC-037" ], "findings": [ { "id": "rctl-gov-provenance-attribution", "name": "Provenance and attribution of the assertion", "description": "Records which agent asserted the binding, on whose behalf it acted, which assessment activity generated the conclusion, what it was derived from, and whether the assertion is human-attested or machine-generated.", "source_refs": [ "SRC-032", "SRC-006", "SRC-030" ], "questions": [ { "id": "rctl-gov-q-prov-agent", "text": "Which agent asserted this binding, on whose behalf did that agent act, and was the agent human, organisational or automated?", "kind": "provenance", "answer_data": [ "asserting agent reference", "acted-on-behalf-of reference", "agent kind code" ] }, { "id": "rctl-gov-q-prov-activity", "text": "Which assessment activity generated this conclusion, and which inputs did that activity use?", "kind": "process", "answer_data": [ "activity reference", "activity start and end", "used input references", "tool or method identifier" ] }, { "id": "rctl-gov-q-prov-derivation", "text": "From which prior assertion or external report was this conclusion derived, and what changed relative to it?", "kind": "relationship", "answer_data": [ "derived-from references", "changed field set", "derivation type" ] }, { "id": "rctl-gov-q-prov-machine", "text": "How is an automated or model-generated assertion distinguished from a human-attested one for reliance purposes?", "kind": "classification", "answer_data": [ "agent kind code", "human review indicator", "reliance restriction applied to machine assertions" ] } ], "data_elements": [ { "id": "rctl-gov-de-asserting-agent-ref", "name": "Asserting agent reference", "description": "Reference to the agent that asserted this binding revision.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-032" ] }, { "id": "rctl-gov-de-on-behalf-of-ref", "name": "Acted on behalf of reference", "description": "Reference to the party on whose behalf the asserting agent acted.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-032" ] }, { "id": "rctl-gov-de-assertion-activity-ref", "name": "Assertion activity reference", "description": "Reference to the assessment or review activity that generated the conclusion.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-032", "SRC-006" ] }, { "id": "rctl-gov-de-derived-from-ref", "name": "Derived from reference", "description": "Reference to a prior assertion, external report or dataset from which this conclusion was derived.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-032" ] }, { "id": "rctl-gov-de-agent-kind", "name": "Agent kind", "description": "Code distinguishing a human, organisational or software agent as the author of the assertion.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-032", "SRC-034" ] }, { "id": "rctl-gov-de-recorded-at", "name": "Recorded at", "description": "Instant at which this model ingested the assertion, held separately from the instant the assessed condition or decision occurred.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-032", "SRC-006" ] } ], "artifacts": [], "inline_only_rationale": "Provenance here is a bounded set of typed attributes on the assertion itself, aligned to entity, activity and agent semantics and to attribution, derivation and revision relations. The general provenance graph, its qualified-influence instances and any long-term provenance store are owned by the referenced provenance capability; producing a provenance artifact in this mixin would fork that graph and create competing authorities over the same statements." }, { "id": "rctl-gov-evidence-integrity", "name": "Evidence reference integrity and immutability", "description": "Binds each item of supporting evidence to the assertion so that later substitution is detectable, fixes which attributes become immutable at approval, and defines the treatment of evidence that becomes unavailable or is lawfully destroyed.", "source_refs": [ "SRC-006", "SRC-016", "SRC-037", "SRC-014" ], "questions": [ { "id": "rctl-gov-q-evidence-bind", "text": "How is each item of supporting evidence bound to the assertion so that later substitution is detectable?", "kind": "evidence", "answer_data": [ "evidence reference", "digest algorithm and value", "instant the digest was computed", "binding scope" ] }, { "id": "rctl-gov-q-evidence-immutable", "text": "Which evidence attributes become immutable once the assertion is approved, and what follows if the evidence store mutates them?", "kind": "security", "answer_data": [ "immutable attribute set", "mismatch detection rule", "effect on currency status", "escalation path" ] }, { "id": "rctl-gov-q-evidence-missing", "text": "How is an assertion treated when referenced evidence becomes unavailable, unreadable or is lawfully destroyed?", "kind": "exception", "answer_data": [ "availability status code", "permitted continued reliance", "reassessment obligation", "substitute evidence reference" ] }, { "id": "rctl-gov-q-evidence-sufficiency", "text": "What makes the referenced evidence sufficient and appropriate for the asserted assurance level?", "kind": "quality", "answer_data": [ "sufficiency rationale", "appropriateness rationale", "evidence type mix", "known evidence limitations" ] } ], "data_elements": [ { "id": "rctl-gov-de-evidence-ref", "name": "Evidence reference", "description": "Reference to an evidence object supporting the assertion; required from the reviewed state onward.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006", "SRC-016" ] }, { "id": "rctl-gov-de-evidence-digest", "name": "Evidence digest", "description": "Cryptographic digest of the referenced evidence object as observed at assertion time.", "value_kind": "text", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-014", "SRC-037" ] }, { "id": "rctl-gov-de-digest-algorithm", "name": "Digest algorithm", "description": "Identifier of the algorithm used to compute the evidence digest.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-014" ] }, { "id": "rctl-gov-de-evidence-observed-at", "name": "Evidence observed at", "description": "Instant at which the evidence object was observed and its digest computed.", "value_kind": "timestamp", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-032", "SRC-006" ] }, { "id": "rctl-gov-de-evidence-availability-status", "name": "Evidence availability status", "description": "Code stating whether referenced evidence remains retrievable, is withheld, is disposed of, or fails digest verification.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-036", "SRC-037" ] } ], "artifacts": [ { "id": "rctl-gov-art-evidence-manifest", "name": "Evidence manifest", "description": "Manifest listing every evidence reference relied upon by an assertion revision with its digest, algorithm and observation instant. It carries references and integrity values only; the evidence objects themselves remain in the referenced evidence store.", "media_or_form": [ "structured record", "digest list", "attached manifest file" ], "serial": true, "identity_strategy": "Authoritative master-system identifier of the evidence package in the evidence system of record when present; otherwise the governed IRI of the assertion revision the manifest describes; otherwise a Dimension-assigned UUID or ULID.", "source_refs": [ "SRC-006", "SRC-014", "SRC-016" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "rctl-gov-stewardship-bundle", "name": "Disclosure, interoperability and continuity stewardship", "description": "How sensitive risk information is labelled, redacted and exported, which regional or sector profiles and exceptions apply, and how records are retained, held and tombstoned.", "rationale": "Risk-control records concentrate exploitable weakness information and often personal data, must be exchangeable with external assessment schemas, and are subject to statutory retention periods and litigation holds that suspend normal disposition.", "source_refs": [ "SRC-033", "SRC-016", "SRC-034", "SRC-036" ], "layers": [ { "id": "rctl-gov-disclosure-layer", "name": "Sensitivity, disclosure and external profiles", "description": "Sensitivity labelling and field-level disclosure control over risk information, and the regional, sector and exchange profiles that govern a binding.", "source_refs": [ "SRC-033", "SRC-016", "SRC-034" ], "findings": [ { "id": "rctl-gov-sensitivity-disclosure", "name": "Sensitivity labelling and disclosure-profiled export", "description": "Assigns handling labels to the binding and its parts, defines which fields are withheld, generalised or hashed for each audience, identifies personal data, and governs authorisation of out-of-profile release and re-identification checks.", "source_refs": [ "SRC-033", "SRC-014", "SRC-034" ], "questions": [ { "id": "rctl-gov-q-sens-label", "text": "Which sensitivity label applies to this binding, and does the label differ between the risk statement, the control description and the evidence?", "kind": "classification", "answer_data": [ "label per element", "label vocabulary and version", "label placement obligation", "source responsible for the label" ] }, { "id": "rctl-gov-q-sens-field", "text": "Which individual fields must be withheld, generalised or hashed when this record is disclosed to a less-privileged audience?", "kind": "privacy", "answer_data": [ "field disclosure rule set", "transformation per field", "minimum disclosable subset" ] }, { "id": "rctl-gov-q-sens-audience", "text": "Which audiences may receive which disclosure profile, and who authorises a release outside the profile?", "kind": "access", "answer_data": [ "audience reference", "permitted profile per audience", "out-of-profile release authority", "release authorization reference" ] }, { "id": "rctl-gov-q-sens-reidentify", "text": "How is it verified that a redacted export cannot be re-identified by combining it with previously released exports?", "kind": "validation", "answer_data": [ "linkage risk check method", "prior release inventory reference", "check outcome", "residual disclosure risk statement" ] } ], "data_elements": [ { "id": "rctl-gov-de-sensitivity-label", "name": "Sensitivity label", "description": "Handling label governing onward sharing of the binding or one of its elements, drawn from a versioned label vocabulary.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-033" ] }, { "id": "rctl-gov-de-field-disclosure-rule", "name": "Field disclosure rule", "description": "Rule stating, per field, whether it is released, withheld, generalised or hashed for a given disclosure profile.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-033", "SRC-014" ] }, { "id": "rctl-gov-de-audience-ref", "name": "Audience reference", "description": "Reference to the audience or recipient community entitled to a disclosure profile.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-033" ] }, { "id": "rctl-gov-de-personal-data-flag", "name": "Personal data indicator", "description": "Indicates whether the binding contains data relating to identified or identifiable individuals.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-014", "SRC-034" ] }, { "id": "rctl-gov-de-release-authorization-ref", "name": "Release authorization reference", "description": "Reference to the authorisation permitting a release outside the audience's normal disclosure profile.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-033", "SRC-014" ] } ], "artifacts": [ { "id": "rctl-gov-art-disclosure-profile", "name": "Disclosure profile", "description": "Named, versioned profile mapping each field and evidence reference of the mixin to a disclosure treatment for a stated audience, with the sensitivity label that must be carried on any output produced under it.", "media_or_form": [ "structured record", "versioned rule set" ], "serial": false, "identity_strategy": "Governed identifier of the profile in the adopting Dimension's disclosure registry when present; otherwise the master-system identifier from the disclosure-governing system; otherwise a Dimension-assigned UUID or ULID plus a semantic version.", "source_refs": [ "SRC-033", "SRC-014" ] }, { "id": "rctl-gov-art-redacted-export", "name": "Disclosure-profiled export package", "description": "Immutable export of one or more bindings produced under a named disclosure profile, carrying its sensitivity label, the profile identifier and version, the requester and the export instant, so that any later disclosure can be traced to a profile decision.", "media_or_form": [ "structured export document", "labelled file with header and footer marking", "exchange payload" ], "serial": true, "identity_strategy": "Master-system identifier of the export transaction when present; otherwise the governed IRI of the export; otherwise a Dimension-assigned UUID or ULID. The export instant is metadata, never the identifier.", "source_refs": [ "SRC-033", "SRC-016" ] } ], "inline_only_rationale": null }, { "id": "rctl-gov-interop-profile", "name": "Regional and sector profiles, exceptions and external mappings", "description": "Declares which regional or sector profile is in force over what period, which profile requirements are formally excepted and on what compensating condition, how profile conflicts are resolved, and how the binding maps to external assessment exchange schemas.", "source_refs": [ "SRC-034", "SRC-016", "SRC-031", "SRC-036" ], "questions": [ { "id": "rctl-gov-q-interop-map", "text": "To which external assessment or risk exchange schema is this binding mapped, and which of its fields have no equivalent there?", "kind": "interoperability", "answer_data": [ "target schema identifier and version", "field mapping table", "unmapped field list", "lossiness statement" ] }, { "id": "rctl-gov-q-interop-profile", "text": "Which regional or sector profile is in force for this binding, and over what effective period?", "kind": "spatial", "answer_data": [ "profile reference and version", "jurisdiction or sector scope", "effective from and effective to" ] }, { "id": "rctl-gov-q-interop-exception", "text": "Which profile requirements are formally excepted for this binding, by whom, until when, and with what compensating condition?", "kind": "exception", "answer_data": [ "excepted requirement reference", "granting authority", "exception expiry", "compensating condition" ] }, { "id": "rctl-gov-q-interop-conflict", "text": "When a regional profile and a sector profile impose contradictory obligations on the same field, which one governs?", "kind": "decision", "answer_data": [ "precedence rule", "governing profile", "recorded rationale", "escalation route where no rule exists" ] } ], "data_elements": [ { "id": "rctl-gov-de-profile-ref", "name": "Profile reference", "description": "Reference to a regional or sector profile constraining this binding.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-034", "SRC-031" ] }, { "id": "rctl-gov-de-profile-effective-period", "name": "Profile effective period", "description": "Period over which the referenced profile applies to this binding.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-034" ] }, { "id": "rctl-gov-de-external-mapping", "name": "External schema mapping", "description": "Mapping from this mixin's fields to an external assessment or risk exchange schema, with its version.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "rctl-gov-de-unmapped-field", "name": "Unmapped field", "description": "Field with no equivalent in the target exchange schema, recorded to make export lossiness explicit.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "rctl-gov-de-exception-ref", "name": "Profile exception reference", "description": "Reference to a granted, time-bounded exception from a profile requirement.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-031", "SRC-034" ] } ], "artifacts": [], "inline_only_rationale": "Profiles, exceptions and schema mappings are governed elsewhere: the profile text belongs to the issuing jurisdiction or sector body, the exception instrument belongs to the adopting Dimension's exception register, and the target schema belongs to its publisher. This finding carries only the binding-scoped references, effective periods and lossiness notes; materialising them as artifacts would republish externally owned normative content under this model's authority." } ] }, { "id": "rctl-gov-continuity-layer", "name": "Retention, legal hold and tombstoning", "description": "Retention schedules and clock start for the mixin's own records, suspension of disposition under legal hold, and the minimum information that survives disposition.", "source_refs": [ "SRC-036", "SRC-034", "SRC-030" ], "findings": [ { "id": "rctl-gov-retention-hold", "name": "Retention, legal hold and tombstone semantics", "description": "Records which retention schedule and disposition authority govern the binding, when the retention clock starts, how a hold suspends the normal disposition cycle, what survives in a tombstone, and which external owner actually executes destruction.", "source_refs": [ "SRC-036", "SRC-034", "SRC-014" ], "questions": [ { "id": "rctl-gov-q-ret-schedule", "text": "Which retention schedule and disposition authority govern this binding's records, and when does the retention clock start?", "kind": "retention", "answer_data": [ "retention schedule reference", "disposition authority reference", "clock start instant", "retention period length" ] }, { "id": "rctl-gov-q-ret-hold", "text": "How is a legal hold applied to a binding, who may apply and release it, and what does the hold suspend?", "kind": "authority", "answer_data": [ "hold reference and scope", "applying and releasing authority", "suspended operations", "written release requirement" ] }, { "id": "rctl-gov-q-ret-tombstone", "text": "What minimum information survives in a tombstone after disposition, and what must be irreversibly removed?", "kind": "lifecycle", "answer_data": [ "surviving field set", "removed field set", "tombstone identifier", "digest of the disposed record" ] }, { "id": "rctl-gov-q-ret-exec", "text": "Which model or policy owner actually executes destruction, and how does this mixin record that the execution occurred?", "kind": "process", "answer_data": [ "executing owner reference", "disposition request reference", "confirmation instant", "disposition status code" ] } ], "data_elements": [ { "id": "rctl-gov-de-retention-schedule-ref", "name": "Retention schedule reference", "description": "Reference to the approved schedule and disposition authority governing this binding's records.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-036" ] }, { "id": "rctl-gov-de-retention-clock-start", "name": "Retention clock start", "description": "Instant from which the retention period is counted, such as the binding reaching a terminal state or the host being withdrawn from service.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-036", "SRC-034" ] }, { "id": "rctl-gov-de-legal-hold-ref", "name": "Legal hold reference", "description": "Reference to an active hold or freeze suspending the normal disposition cycle for this binding and its evidence manifest.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-036" ] }, { "id": "rctl-gov-de-disposition-status", "name": "Disposition status", "description": "Code stating whether the record is retained, eligible for disposition, held, disposition requested, or disposed of.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-036" ] }, { "id": "rctl-gov-de-tombstone-id", "name": "Tombstone identifier", "description": "Identifier of the surviving marker left after disposition of the substantive record.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-036", "SRC-032" ] } ], "artifacts": [ { "id": "rctl-gov-art-tombstone-record", "name": "Tombstone record", "description": "Minimal surviving marker created when a binding's substantive content is disposed of, carrying the binding identifier, host reference, terminal state, disposition authority reference, disposition instant and the digest of the disposed record, and no risk statement, control description, evidence content or free text.", "media_or_form": [ "structured record", "append-only ledger entry" ], "serial": true, "identity_strategy": "The binding's original authoritative master-system identifier is retained verbatim so that references do not dangle; where none existed, the governed IRI or the Dimension-assigned UUID or ULID of the disposed record is retained. The disposition instant is metadata, never the identifier.", "source_refs": [ "SRC-036", "SRC-032" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "rctl-risk-fn-bind-assessment-context", "name": "Bind an assessment context to a referenced risk", "description": "Creates a revision-pinned binding between one host record and one referenced risk, capturing anchors, taxonomy pin, scope, horizon and criteria/method pins. It establishes context only and never creates, alters or advances the referenced risk entity.", "inputs": [ "risk reference and exact revision pin", "assessment anchor set (objectives, assets, processes, context conditions, jurisdiction or site)", "causal anchors (risk source, event, consequences and exclusions)", "taxonomy system identifier and version with category values", "assessment scope statement, exclusions, likelihood horizon and as-of time", "criteria set reference and version, method reference and version, expression mode" ], "outputs": [ "bound assessment-context record with binding validity state set to current", "recorded as-of time and recorded time as separate values", "rejection result naming any required pin or reference that failed to resolve" ], "preconditions": [ "the risk reference resolves in the model that owns the risk entity", "the criteria set and method references resolve at the stated versions", "a scope statement and an as-of time are supplied", "at least one anchor reference resolves" ], "effects": [ "establishes a stable binding that is invalidated rather than silently re-pointed when the upstream revision changes", "sets binding validity state and records the detection time when supersession is later observed", "does not create, modify, approve or advance the referenced risk entity or its register status" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-005", "SRC-007" ] }, { "id": "rctl-risk-fn-record-estimate", "name": "Record an estimate under a pinned method", "description": "Stores an estimate in either the inherent or residual role exactly as produced by the pinned method, together with its dimensions, units, scale references and expression mode. It performs no method-specific computation and invents no scale semantics.", "inputs": [ "bound assessment context", "estimate role (inherent or residual)", "likelihood expression with mode, unit or scale reference and any distribution parameters", "impact values per declared dimension with their scale references", "characterization state (initial or adjusted) and derivation reference" ], "outputs": [ "stored estimate with role tag, characterization state and full dimension declarations", "validation errors where the expression does not match the pinned criteria scale", "recorded time distinct from the assessment as-of time" ], "preconditions": [ "a criteria set and method pin are present with versions", "the expression mode is declared and the referenced scale resolves", "for the inherent role, an inherent definition statement or a documented omission ground is present" ], "effects": [ "stores values only in the form the pinned method produced them", "stores ordinal values as scale-referenced codes so that arithmetic is not implied by the encoding", "refuses operations the declared scale type does not support", "never derives a value the pinned method did not produce" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-005", "SRC-008" ] }, { "id": "rctl-risk-fn-compare-inherent-residual", "name": "Compare inherent and residual estimates", "description": "Records the difference between an inherent and a residual estimate, the dimensions that changed, the controls relied on and the effectiveness determinations cited, and the outcome of comparing the residual position with a referenced tolerance statement.", "inputs": [ "inherent estimate and residual estimate for the same bound context", "relied-on control references and cited effectiveness determination references", "appetite or tolerance statement reference and version" ], "outputs": [ "changed-dimension set with per-dimension before and after values", "residual change explanation", "comparison outcome against the referenced tolerance, including a no-applicable-tolerance value" ], "preconditions": [ "both estimates share criteria set, method, expression mode, scope, horizon and taxonomy pins", "the residual estimate carries an adjusted characterization state", "each cited effectiveness determination resolves, or a reliance-without-determination flag is set" ], "effects": [ "records the delta and its explanation as assessment context", "cites control effectiveness determinations without computing, revising or re-opening them", "records a comparison outcome without granting, approving or enforcing acceptance of the residual position", "refuses to produce a comparison when the pin sets differ, returning the mismatched pins instead" ], "source_refs": [ "SRC-005", "SRC-006", "SRC-011", "SRC-012" ] }, { "id": "rctl-risk-fn-explain-basis", "name": "Explain assumptions and evidential basis", "description": "Assembles and records the assumptions, information sources, data currency, estimation basis kind, analysis constraints and uncertainty qualification behind an estimate, and emits the basis statement and derivation record artifacts.", "inputs": [ "assumption statements with critical-assumption flags", "information source references and their data currency times", "estimation basis kind and, where modelled, tool identity and version", "analysis constraint statements", "confidence grade, uncertainty representation and precision caveat" ], "outputs": [ "assessment basis statement artifact", "estimate derivation record artifact where a derivation exists", "inline uncertainty qualification attached to the estimate", "list of assumptions whose falsification would most change the result" ], "preconditions": [ "at least one assumption statement is supplied", "an estimation basis kind and an uncertainty representation are declared", "the bound assessment context exists" ], "effects": [ "makes the estimate falsifiable by naming what it depends on", "records data currency separately from the assessment as-of and recorded times", "does not evaluate, score or rank the quality of the cited sources beyond the declared grade" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-010" ] }, { "id": "rctl-risk-fn-check-comparability", "name": "Check comparability before comparison, reuse or aggregation", "description": "Compares the pin sets of two or more assessment-context records against a requested comparison or aggregation operation and returns a verdict, the mismatched pins and the caveat set that any permitted result must carry.", "inputs": [ "two or more assessment-context records with their pin sets", "requested operation (pairwise comparison, trend reuse, or aggregation)", "scale type and permitted operations from the pinned criteria" ], "outputs": [ "comparability verdict: comparable, comparable with caveats, or not comparable", "named list of mismatched pins where the verdict is negative", "caveat set to attach to any permitted result", "handling code for records pinned to a withdrawn criteria version" ], "preconditions": [ "each record carries criteria, method, expression-mode, scope, horizon and taxonomy pins", "the requested operation is named", "the scale type of each value is resolvable" ], "effects": [ "blocks silent aggregation of ordinal or differently pinned estimates", "attaches caveats that downstream consumers are prohibited from stripping", "asserts no normalization or roll-up algorithm; the enterprise reporting model owns any aggregate it chooses to build under the returned verdict" ], "source_refs": [ "SRC-004", "SRC-003", "SRC-008", "SRC-010" ] }, { "id": "rctl-control-fn-link-risk-to-control", "name": "Link risk to control", "description": "Create a directed risk-to-control link carrying the claimed treatment mechanism, the risk response type it serves and the basis of the claim.", "inputs": [ "Risk statement reference", "Control reference with catalogue source and revision pin", "Treatment mechanism code and claim basis", "Asserting party reference and event time" ], "outputs": [ "Persisted link record with local identifier", "Updated coverage edge set for the host subject" ], "preconditions": [ "Both endpoints resolve in their owning models", "The control reference is pinned to a named catalogue revision", "The treatment mechanism value exists in the declared vocabulary" ], "effects": [ "A new link record is added with event time and observation time recorded separately", "The coverage matrix projection is marked stale for regeneration", "No risk score, residual value or control definition is modified" ], "source_refs": [ "SRC-002", "SRC-011", "SRC-015" ] }, { "id": "rctl-control-fn-retire-risk-control-link", "name": "Retire risk-to-control link", "description": "Retire or supersede an existing link without destroying it, recording the reason and any replacement link.", "inputs": [ "Link record identifier", "Retirement reason code", "Optional superseding link reference", "Actor reference and event time" ], "outputs": [ "Link record marked superseded or retired", "Recomputed uncovered-risk list" ], "preconditions": [ "The link record exists and is not already retired", "The actor holds a write role for linkage records" ], "effects": [ "The prior link remains readable with superseded-at timestamp and reason", "Any residual contribution depending on the link is suspended", "The remediation workflow in the owning model is notified by reference only" ], "source_refs": [ "SRC-002", "SRC-016", "SRC-011" ] }, { "id": "rctl-control-fn-record-applicability", "name": "Record control applicability", "description": "Record or revise an applicability, partial-applicability or not-applicable determination for a control against the host subject, with basis, covered population and approval.", "inputs": [ "Control reference", "Host subject reference", "Applicability status, basis and covered population references", "Approving party reference and effective-from time" ], "outputs": [ "New revision of the control applicability statement", "Updated applicability status on the assertion set" ], "preconditions": [ "The control reference resolves and is revision-pinned", "A not-applicable or partial status carries a justification and an approver" ], "effects": [ "A serial applicability statement revision is created; the prior revision remains readable", "Dependent implementation and effectiveness assertions are flagged for review", "Scoping authority and obligation records in other models are unchanged" ], "source_refs": [ "SRC-017", "SRC-014", "SRC-027" ] }, { "id": "rctl-control-fn-record-implementation-assertion", "name": "Record design, implementation and operating assertion", "description": "Record or revise the three state assertions for a control and subject, each with its own basis, determining party and event time, including deviations, exceptions and compensating control references.", "inputs": [ "Control reference and host subject reference", "Design status and rationale", "Implementation status, deviations, exception and compensating control references", "Operating status, frequency or triggers", "Determining party reference and event time" ], "outputs": [ "New revision of the control implementation assertion record", "Independent design, implementation and operating status values" ], "preconditions": [ "Applicability is recorded as applicable or partially applicable", "Each status value exists in its declared vocabulary", "A compensating control reference carries a sense code and a documented constraint" ], "effects": [ "Three status values are stored independently; none is derived from another", "Any dependent effectiveness conclusion is marked for revalidation", "No policy text, procedure or configuration is created or altered" ], "source_refs": [ "SRC-017", "SRC-019", "SRC-011", "SRC-027", "SRC-023" ] }, { "id": "rctl-control-fn-bind-assessment-evidence", "name": "Bind assessment and evidence references", "description": "Bind assessment references, applied methods, depth, coverage, sample basis, timing and assessor to a control assertion, together with evidence references and their integrity digests.", "inputs": [ "Control assertion reference", "Assessment reference, method codes, depth and coverage", "Sample basis and covered operating period", "Evidence references with digests and collection times", "Assessor reference and assessment event time" ], "outputs": [ "New revision of the assessment and evidence binding manifest", "Digest verification result per bound evidence reference" ], "preconditions": [ "Every assessment and evidence reference resolves in its owning model", "Each method code is one of examine, interview or test", "The assessor reference is present and its independence flag is set" ], "effects": [ "References and digests are stored; no evidence payload, test case or test result is copied or executed", "A digest mismatch marks the binding unverified and blocks its use as a conclusion basis", "Evidence retention and custody remain governed by the evidence model" ], "source_refs": [ "SRC-006", "SRC-024", "SRC-016", "SRC-018" ] }, { "id": "rctl-control-fn-record-effectiveness-conclusion", "name": "Record effectiveness conclusion", "description": "Record an effectiveness conclusion with its vocabulary, scope, basis references, confidence, validity window, invalidation triggers and any deficiency severity.", "inputs": [ "Control assertion reference", "Conclusion code and vocabulary identifier", "Basis manifest references", "Confidence value and limiting factors", "Valid-until time, invalidation triggers, optional deficiency severity", "Concluding and approving party references" ], "outputs": [ "New revision of the control effectiveness conclusion statement", "Expiry schedule entry for the conclusion" ], "preconditions": [ "At least one verified assessment or evidence binding manifest resolves", "The approving party is distinct from the operating party where independence is required", "The conclusion vocabulary is declared and versioned" ], "effects": [ "The conclusion is stored with its basis references and cannot be created without them", "Conclusions derived from documentation, framework mapping or incident absence are rejected", "On reaching valid-until the conclusion is read as expired rather than effective", "Deficiency remediation is tracked by reference only, in the owning model" ], "source_refs": [ "SRC-019", "SRC-016", "SRC-006", "SRC-025" ] }, { "id": "rctl-control-fn-explain-residual-contribution", "name": "Explain residual contribution", "description": "Produce a traceable explanation of how a control's assessed effectiveness contributes to the residual position of a linked risk, and submit the attribution to the risk model.", "inputs": [ "Link record reference", "Effectiveness conclusion reference", "Attribution method code", "Attribution effective time" ], "outputs": [ "Residual contribution record with attributed change and status", "Explanation trace from evidence binding through conclusion to attribution" ], "preconditions": [ "A non-expired effectiveness conclusion exists for the linked control", "The attribution method is declared and the risk model exposes a compatible scale", "The link record is active and not superseded" ], "effects": [ "An attribution claim is recorded with status claimed until the risk owner accepts it", "An untested, expired or adverse conclusion yields no reduction attribution", "The authoritative residual value, appetite thresholds and acceptance decision remain computed and owned by the risk model" ], "source_refs": [ "SRC-002", "SRC-011", "SRC-026", "SRC-020" ] }, { "id": "rctl-gov-fn-authorize-binding-change", "name": "Authorize a binding change", "description": "Determines whether a proposed create, link, unlink, update, accept or retire action on a WM-XCT-027 binding is admissible, by checking the acting party's authority level against the versioned threshold table and the declared incompatible-duty set. This decides admissibility for this model's own records only; runtime policy evaluation and enforcement remain with the referenced authorization model.", "inputs": [ "proposed change document with base revision identifier", "acting party and delegation references", "declared authority level and authority basis reference", "authority threshold table identifier and version", "incompatible-duty pair set", "current binding state, residual band and hold status" ], "outputs": [ "admissibility verdict with machine-readable reason code", "required authority level actually applied", "binding authorization statement on admission", "refusal reason on rejection" ], "preconditions": [ "the acting party reference resolves in the referenced party registry", "the base revision identifier matches the current revision of the binding", "the threshold table version resolves and is in force at the authorization time", "no active legal hold blocks the requested operation" ], "effects": [ "on admission an immutable authorization statement is appended and the revision identifier increments", "on refusal no state change occurs and the refusal reason is returned to the caller", "repeating the same request with the same base revision and idempotency key returns the original verdict without creating a second statement", "an authorization event is emitted to the referenced audit trail model, whose record structure and retention this model does not own" ], "source_refs": [ "SRC-011", "SRC-031", "SRC-014", "SRC-035" ] }, { "id": "rctl-gov-fn-review-and-approve", "name": "Review and approve or reject an assertion", "description": "Records an independent review of an asserted binding and the resulting approval, rejection or return for rework, capturing the reviewer's independence basis, the assurance level reached and any scope limitation.", "inputs": [ "binding revision under review", "reviewer reference and independence basis", "assessment methods and objects applied", "evidence manifest reference", "criteria binding record reference" ], "outputs": [ "review outcome code with rationale", "assurance limitation statement", "updated binding state and currency status", "reviewer attribution recorded on the revision" ], "preconditions": [ "the binding is in a state that admits review", "the reviewer does not appear in the asserting or operating roles for the same binding unless an authorised duty-separation override is in force", "every referenced evidence item verifies against its recorded digest", "the criteria binding record is present and its version is in force" ], "effects": [ "the binding transitions to reviewed, approved or returned, with the transition instant recorded", "an assurance limitation statement is created and linked to the revision", "a digest mismatch or unresolvable evidence reference aborts the review and sets the currency status to invalidated", "the review outcome is emitted as an event to the referenced audit trail model" ], "source_refs": [ "SRC-006", "SRC-037", "SRC-035", "SRC-031" ] }, { "id": "rctl-gov-fn-reconcile-bindings", "name": "Reconcile bindings against host and referenced registries", "description": "Checks referential integrity of every binding against its host record, the referenced risk register, the control catalogue, the party registry and the evidence store, and reports orphans, retired references, duplicate active bindings and unjustified control exclusions.", "inputs": [ "binding set in scope", "host record set and their states", "risk register and control catalogue versions", "party registry snapshot reference", "evidence availability responses" ], "outputs": [ "reconciliation report listing each discrepancy with a classification and severity", "proposed disposition per discrepancy", "count of bindings whose currency was invalidated by the run", "run parameters and coverage statement" ], "preconditions": [ "each referenced registry exposes a resolvable version or snapshot identifier", "the run scope and cut-off instant are declared before execution" ], "effects": [ "discrepancies are recorded against the affected bindings without silently altering their substantive content", "bindings whose risk or control reference has been retired are flagged and their currency status set to invalidated", "the reconciliation report is retained as evidence that recording and reporting obligations were discharged", "remediation of a discrepancy is performed by the owning party or referenced model, not by this function" ], "source_refs": [ "SRC-030", "SRC-031", "SRC-016", "SRC-014" ] }, { "id": "rctl-gov-fn-evaluate-currency", "name": "Evaluate assessment currency and expire stale conclusions", "description": "Derives the currency status of each binding from its assessment instant, review interval, validity window and fired reassessment triggers, and marks conclusions approaching expiry, expired or invalidated.", "inputs": [ "assessed-at instant and valid-until instant", "review interval and its source", "fired reassessment trigger events", "evaluation cut-off instant", "profile-specific maximum review interval" ], "outputs": [ "currency status per binding", "time remaining or overdue duration", "reassessment obligation with its deadline", "list of bindings whose acceptance must be re-taken" ], "preconditions": [ "the assessed-at instant is present and expressed with an explicit offset", "the clock-start selection is declared for the binding", "the evaluation cut-off instant is supplied by the caller rather than assumed" ], "effects": [ "currency status is recomputed and stored as a derived value, leaving the underlying conclusion unchanged", "expiry sets a reassessment obligation on the accountable owner but never silently changes a residual risk level", "an expired conclusion remains readable and citable, marked as not current", "repeated runs at the same cut-off instant produce identical results" ], "source_refs": [ "SRC-034", "SRC-011", "SRC-030" ] }, { "id": "rctl-gov-fn-supersede-assertion", "name": "Supersede or correct an assertion", "description": "Issues a successor revision that replaces a relied-upon assertion, records the defect corrected and the reliance period, and notifies declared downstream consumers. Immutable fields are never edited in place.", "inputs": [ "assertion revision to supersede", "corrected content", "correction reason code", "reliance period", "downstream subscriber references" ], "outputs": [ "successor revision with supersedes reference", "supersession record", "back-reference on the superseded revision", "notification set with acknowledgement status" ], "preconditions": [ "the revision to supersede exists and is not already superseded", "the acting party holds authority at least equal to that used for the original acceptance", "an attempt to modify an immutable field in place is rejected with an explicit reason code" ], "effects": [ "the superseded revision becomes read-only and is retained for its full retention period", "the successor revision carries a new revision identifier while the binding identifier follows the declared continuity rule", "notifications are dispatched to declared subscribers within the profile's interval", "the supersession is emitted as an event to the referenced audit trail model" ], "source_refs": [ "SRC-032", "SRC-037", "SRC-016" ] }, { "id": "rctl-gov-fn-export-redacted-view", "name": "Produce a disclosure-profiled export", "description": "Generates an export of one or more bindings under a named disclosure profile, applying field-level withholding, generalisation or hashing, carrying the sensitivity label on the output and recording the release.", "inputs": [ "binding selection", "named disclosure profile and version", "requester and audience references", "target exchange schema where a mapping is requested", "out-of-profile release authorization where applicable" ], "outputs": [ "disclosure-profiled export package", "applied sensitivity label and its placement", "list of withheld or transformed fields", "lossiness statement for any external schema mapping" ], "preconditions": [ "the requester's audience is entitled to the named profile, or a valid out-of-profile release authorization is supplied", "the profile version is in force at the export instant", "no field marked non-disclosable under the governing regional or sector profile is included" ], "effects": [ "the export package is created immutably with its profile identifier, requester, audience and export instant", "the release is recorded so a later disclosure can be traced to a specific profile decision", "requesting an export that would breach the profile fails with an explicit reason and produces no partial output", "the export event is emitted to the referenced audit trail model" ], "source_refs": [ "SRC-033", "SRC-016", "SRC-014" ] }, { "id": "rctl-gov-fn-apply-legal-hold", "name": "Apply or release a legal hold", "description": "Places a binding and its evidence manifest under a hold that suspends the normal disposition cycle, or releases that hold on written instruction from the authorised party.", "inputs": [ "hold or release instruction with its authority reference", "binding and evidence scope of the hold", "hold reason and matter reference", "instruction instant" ], "outputs": [ "hold status per affected binding", "suspended operation list", "hold or release confirmation with its instant", "unaffected scope report" ], "preconditions": [ "the instructing party is authorised under the adopting Dimension's records policy to apply or release holds", "the scope of the hold is expressed in resolvable references rather than free text", "release is supported by a written instruction from the authorised party" ], "effects": [ "disposition eligibility for the held scope is suspended regardless of the retention schedule", "held records may still be read and superseded but never disposed of or hard-deleted", "releasing a hold restores normal disposition eligibility computation and does not itself dispose of anything", "hold application and release are recorded with explicit instants and authority references" ], "source_refs": [ "SRC-036", "SRC-014" ] }, { "id": "rctl-gov-fn-request-disposition", "name": "Compute disposition eligibility and request disposition", "description": "Determines whether a binding's records have reached the end of their retention period with no active hold, issues a disposition request to the owning records capability, and records the confirmed outcome as a tombstone. This function never performs destruction itself.", "inputs": [ "retention schedule reference and clock start", "active hold set", "current disposition status", "evaluation instant", "confirmation returned by the executing records capability" ], "outputs": [ "disposition eligibility verdict with reason", "disposition request reference", "tombstone record on confirmed disposition", "refusal reason where a hold or open obligation blocks disposition" ], "preconditions": [ "the retention schedule reference resolves to an approved disposition authority", "no active legal hold covers the binding or its evidence manifest", "no successor revision depends on the record for an unexpired reliance period" ], "effects": [ "an eligibility verdict is produced as advisory input, not as an instruction that anything be destroyed", "a disposition request is issued to the referenced records retention and disposition model, which owns execution together with the adopting Dimension's records policy", "on confirmation a tombstone is written retaining only identifier, host reference, terminal state, authority reference, instant and digest, and inbound references resolve to that tombstone rather than dangling", "if no confirmation is returned the disposition status remains requested and the substantive record is retained" ], "source_refs": [ "SRC-036", "SRC-034", "SRC-032" ] } ], "composition": [ { "target": "WM-KNW-015 - Risk / Opportunity entity and lifecycle", "relation": "CHILD", "purpose": "The parent model owns risk identity, statement, register membership, status and lifecycle transitions. This mixin attaches one assessment context to a pinned revision of that entity, carries only its own binding validity state, and reproduces no risk lifecycle or register operations.", "required": true, "source_refs": [ "SRC-002", "SRC-007" ] }, { "target": "Host record of the adopting Dimension that carries risk-control linkage fields", "relation": "MIX-IN", "purpose": "Defines how this field group is embedded on a host entity, event or decision record so a Dimension can carry a defensible assessment context without standing up a separate register.", "required": true, "source_refs": [ "SRC-002", "SRC-005" ] }, { "target": "Control implementation and control assessment records (control register, implemented requirements, effectiveness determinations)", "relation": "REFERENCE", "purpose": "Supplies control identity, implementation statements and effectiveness determinations that the residual estimate cites. Assessment procedures, objectives, methods and the production of determinations remain wholly with that model; this mixin carries only the reference and the reliance parameters specific to this assessment.", "required": true, "source_refs": [ "SRC-005", "SRC-006" ] }, { "target": "Risk criteria and assessment-method registry (criteria sets, scales, thresholds, technique definitions)", "relation": "REFERENCE", "purpose": "Supplies the versioned criteria scales and technique definitions that this mixin pins. The mixin stores the pin, the version token and the expression mode; it never defines, parameterizes or re-implements technique semantics.", "required": true, "source_refs": [ "SRC-008", "SRC-001" ] }, { "target": "Risk appetite and tolerance statements", "relation": "REFERENCE", "purpose": "Supplies the versioned thresholds the residual estimate is compared against. Determining, approving, publishing and enforcing appetite and tolerance remain with enterprise governance; this mixin records the reference and the comparison outcome only.", "required": false, "source_refs": [ "SRC-003", "SRC-007", "SRC-010" ] }, { "target": "Objective, asset, process and organizational-unit registries", "relation": "REFERENCE", "purpose": "Supplies the anchors an assessment is scoped against. The mixin holds anchor references and assessment-specific scoping parameters; master data, anchor lifecycle and ownership stay in those registries.", "required": false, "source_refs": [ "SRC-001", "SRC-007" ] }, { "target": "Acceptance, authorization and exception decision records", "relation": "REFERENCE", "purpose": "Receives a pointer from the comparison outcome to the decision in which a residual position was accepted. Decision authority, approval workflow and the validity of the decision belong to that model; this mixin never grants or derives acceptance.", "required": false, "source_refs": [ "SRC-011", "SRC-012" ] }, { "target": "Risk treatment, remediation and plan-of-action records", "relation": "REFERENCE", "purpose": "Consumes the residual position as an input to treatment planning. Treatment option selection, milestones, scheduling, cost and closure are owned there and are not represented in this field group.", "required": false, "source_refs": [ "SRC-002", "SRC-005" ] }, { "target": "Assessment observation and evidence records", "relation": "REFERENCE", "purpose": "Supplies observations and evidence cited as information sources for an estimate. Evidence collection, assessment execution and result logging are owned there; this mixin cites references and records their currency.", "required": false, "source_refs": [ "SRC-005", "SRC-006" ] }, { "target": "IEC 31010:2019 risk assessment technique catalogue", "relation": "ALIGN", "purpose": "External alignment for naming and selecting the applied technique. The mixin records which technique and version were used and makes no conformance claim to the standard, whose normative text is not reproduced here.", "required": false, "source_refs": [ "SRC-008" ] }, { "target": "NIST IR 8286 cybersecurity risk register and risk detail record schemas", "relation": "ALIGN", "purpose": "External alignment for register field naming and for enterprise roll-up expectations. Adoption is a projection of this field group into that schema, not a conformance claim, and the register's own lifecycle stays with the register model.", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-004" ] }, { "target": "OSCAL Assessment Results risk characterization (characterization, facet, mitigating-factor)", "relation": "ALIGN", "purpose": "External alignment for expressing initial versus adjusted characterizations and control-based mitigating factors in machine-readable form. The mixin maps its fields onto those assemblies without adopting the assessment-results model's observation, risk-log or remediation semantics.", "required": false, "source_refs": [ "SRC-005" ] }, { "target": "The Open Group Risk Taxonomy (O-RT) Version 3.1", "relation": "ALIGN", "purpose": "Alignment for a frequency-and-magnitude decomposition where a Dimension pins a FAIR-family method. The mixin carries the pin and the resulting values; the taxonomy and its analysis process stay with the standard and its companion Risk Analysis standard.", "required": false, "source_refs": [ "SRC-009" ] }, { "target": "Regulation (EU) 2024/1689 Article 9 risk management system for high-risk AI systems", "relation": "ALIGN", "purpose": "Jurisdiction-scoped alignment evidencing a legal requirement that residual risk per hazard be judged acceptable and that estimation cover reasonably foreseeable misuse. The mixin records the reference and the comparison outcome; conformity assessment and enforcement are outside it.", "required": false, "source_refs": [ "SRC-012" ] }, { "target": "WM-KNW-015 (registered parent model for vr.wm-xct-027)", "relation": "CHILD", "purpose": "Inherit record metadata, versioning, change-detection and provenance obligations that every control assertion record must satisfy, rather than restating them locally.", "required": true, "source_refs": [ "SRC-015", "SRC-017" ] }, { "target": "Host subject model (system, process, service, supplier, asset or product to which this mixin attaches)", "relation": "MIX-IN", "purpose": "Attach the risk-and-control assurance surface to a subject without altering that subject's own identity, classification or lifecycle.", "required": true, "source_refs": [ "SRC-015", "SRC-017" ] }, { "target": "Control catalogue / control framework model", "relation": "REFERENCE", "purpose": "Resolve control definitions, families, enhancements, parameter definitions, baselines and revisions; this model carries the reference, revision pin, selected parameter values and declared tailoring only.", "required": true, "source_refs": [ "SRC-014", "SRC-015", "SRC-017" ] }, { "target": "Risk statement and risk register model", "relation": "REFERENCE", "purpose": "Resolve risk statements, response types, appetite and tolerance, residual values and acceptance decisions; this model carries the risk reference, treatment claim and attributed contribution only.", "required": true, "source_refs": [ "SRC-002", "SRC-011" ] }, { "target": "Policy and procedure model", "relation": "REFERENCE", "purpose": "Point at the policy or procedure that documents a control without importing its text or approval lifecycle, and without letting its existence set any status value here.", "required": false, "source_refs": [ "SRC-020", "SRC-026" ] }, { "target": "Technical configuration and baseline model", "relation": "REFERENCE", "purpose": "Identify the component or configuration by which a control is implemented, leaving configuration content, drift detection and enforcement in that model.", "required": false, "source_refs": [ "SRC-015", "SRC-014" ] }, { "target": "Test and assessment execution model", "relation": "REFERENCE", "purpose": "Bind assessment activities, methods and timing by reference; assessment procedures, test cases, execution and raw results stay in that model.", "required": true, "source_refs": [ "SRC-006", "SRC-018", "SRC-024" ] }, { "target": "Evidence object model", "relation": "REFERENCE", "purpose": "Bind evidence by reference and digest with a local sufficiency rationale; evidence payloads, custody, integrity maintenance and retention execution stay in that model.", "required": true, "source_refs": [ "SRC-016", "SRC-019" ] }, { "target": "Issue, deficiency and remediation model (plan of action and milestones)", "relation": "REFERENCE", "purpose": "Record a deficiency severity value and point at the record that tracks remediation; milestones, owners, workflow states and closure decisions stay in that model.", "required": false, "source_refs": [ "SRC-016", "SRC-011", "SRC-019" ] }, { "target": "Audit engagement and audit-trail model", "relation": "REFERENCE", "purpose": "Emit access and change events and retain the emission reference; audit records, log retention and trail immutability semantics are owned entirely by that model.", "required": false, "source_refs": [ "SRC-019", "SRC-020" ] }, { "target": "Party, role and organisation directory model", "relation": "REFERENCE", "purpose": "Resolve owner, operator, assessor and approver identities; this model stores role-scoped references and independence flags only.", "required": true, "source_refs": [ "SRC-015", "SRC-017" ] }, { "target": "Runtime enforcement, monitoring and telemetry model", "relation": "REFERENCE", "purpose": "Obtain observed occurrence counts and monitoring signals by reference; policy evaluation, enforcement decisions and execution records remain owned there.", "required": false, "source_refs": [ "SRC-028", "SRC-011" ] }, { "target": "NIST SP 800-53 Rev. 5 control catalogue with the OSCAL implementation and assessment layers", "relation": "ALIGN", "purpose": "Align local field semantics for control reference, parameter setting, implementation status, assessment method, finding and result expiry with a published machine-readable representation, without claiming conformance.", "required": false, "source_refs": [ "SRC-014", "SRC-015", "SRC-016", "SRC-017" ] }, { "target": "COSO Internal Control - Integrated Framework (ICIF-2013) and GAO Standards for Internal Control in the Federal Government", "relation": "ALIGN", "purpose": "Align the design, implementation, operation and deficiency vocabulary with recognised internal-control criteria; the frameworks' own assessment of an entity's internal control remains external.", "required": false, "source_refs": [ "SRC-026", "SRC-020", "SRC-021" ] }, { "target": "NIST Cybersecurity Framework 2.0 outcome taxonomy and NCSC Cyber Assessment Framework outcomes", "relation": "ALIGN", "purpose": "Offer selectable outcome vocabularies for effectiveness conclusions and crosswalk targets, with an explicit rule that a mapping to an outcome is never evidence that the outcome is achieved.", "required": false, "source_refs": [ "SRC-022", "SRC-025" ] }, { "target": "WM-KNW-015", "relation": "CHILD", "purpose": "Places the risk-control mixin under its registered parent knowledge model so that recorded risk information is governed as an organisational knowledge asset and remains traceable across the system and organisation levels.", "required": true, "source_refs": [ "SRC-030", "SRC-011" ] }, { "target": "Host record model to which the mixin is applied", "relation": "MIX-IN", "purpose": "Attaches the risk projection and control linkage to a system, process, asset, supplier, dataset, decision, product or organisational unit; the host owns the lifecycle that scopes the binding's lifecycle verbs.", "required": true, "source_refs": [ "SRC-031", "SRC-011" ] }, { "target": "Risk register and risk taxonomy model", "relation": "REFERENCE", "purpose": "Supplies the identified risk that this mixin projects onto a host, together with its governed identifier. Risk identification, definition and register lifecycle stay with that model; only the host-specific framing, residual level and acceptance are carried here.", "required": true, "source_refs": [ "SRC-030", "SRC-016" ] }, { "target": "Control catalogue and requirement source model", "relation": "REFERENCE", "purpose": "Supplies control identity, text and baselines by governed identifier. This mixin carries only the linkage, applicability and the justification for inclusion or exclusion on this host, and never reproduces catalogue content or catalogue versioning.", "required": true, "source_refs": [ "SRC-031", "SRC-014" ] }, { "target": "Party, role and organisational-unit registry of the adopting Dimension", "relation": "REFERENCE", "purpose": "Resolves accountable owners, delegates, reviewers and acceptance authorities. Party identity and its lifecycle are owned there; this mixin carries only references, governance-line codes and effective periods.", "required": true, "source_refs": [ "SRC-035", "SRC-011" ] }, { "target": "Evidence and document artifact model", "relation": "REFERENCE", "purpose": "Holds the evidence objects that support assertions. This mixin carries references, digests and observation instants for integrity binding; capture, storage and evidence lifecycle remain external.", "required": true, "source_refs": [ "SRC-006", "SRC-016" ] }, { "target": "Authorization and policy-decision model of the adopting Dimension", "relation": "REFERENCE", "purpose": "Evaluates and enforces access and write decisions at runtime. This mixin declares the required authority level, incompatible-duty constraints and sensitivity conditions as parameters, and never performs evaluation, decision or enforcement.", "required": true, "source_refs": [ "SRC-014", "SRC-011" ] }, { "target": "Audit trail and event record model of the adopting Dimension", "relation": "REFERENCE", "purpose": "Receives governance events emitted by this mixin and holds the durable audit entries referenced from bindings. Audit record structure, immutability guarantees, non-repudiation services, query and audit retention are owned there.", "required": true, "source_refs": [ "SRC-014" ] }, { "target": "Records retention schedule and disposition model", "relation": "REFERENCE", "purpose": "Supplies approved retention schedules and disposition authority and executes destruction. This mixin carries schedule references, clock starts, hold flags and tombstones, and issues disposition requests without executing them.", "required": true, "source_refs": [ "SRC-036", "SRC-034" ] }, { "target": "PROV-O: The PROV Ontology (W3C Recommendation, 30 April 2013)", "relation": "ALIGN", "purpose": "Aligns the mixin's attribution fields to entity, activity, agent, wasAttributedTo, wasGeneratedBy, wasDerivedFrom, wasRevisionOf and actedOnBehalfOf. The alignment is a mapping claim only; no conformance to the ontology is asserted.", "required": false, "source_refs": [ "SRC-032" ] }, { "target": "NIST OSCAL assessment results model", "relation": "ALIGN", "purpose": "Maps residual conclusions, control linkage and evidence references onto observations, risks and findings for exchange with assessment tooling. Mapping is declared with an explicit lossiness statement; assessment execution is not owned here.", "required": false, "source_refs": [ "SRC-016", "SRC-006" ] }, { "target": "FIRST Traffic Light Protocol version 2.0", "relation": "ALIGN", "purpose": "Adopts a published label vocabulary and its handling and placement rules for sensitive risk information rather than inventing a local one. Recipient compliance and community definition remain outside this model.", "required": false, "source_refs": [ "SRC-033" ] }, { "target": "Assessment criteria, scale and risk appetite model of the adopting Dimension", "relation": "REFERENCE", "purpose": "Supplies the versioned criteria, severity and likelihood scales and appetite thresholds against which residual risk is judged acceptable. This mixin binds a conclusion to a criteria version and records precedence when criteria conflict.", "required": true, "source_refs": [ "SRC-030", "SRC-034", "SRC-037" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "The adopting Dimension must designate one accountable owner package for WM-XCT-027 records, name the responsible party in AGENTS.md, and keep that designation current; the mixin does not create or maintain party records itself.", "The owner package must publish the versioned authority threshold table mapping residual severity bands to required authority levels, and the incompatible-duty pair set, before any binding may reach an accepted state.", "The owner package must declare, with a resolvable identifier and version for each, the risk register, control catalogue, criteria and scale source, party registry, evidence store, authorization model, audit trail model and retention schedule that it binds to.", "The owner package must declare the regional and sector profiles in force, their effective periods, and the precedence rule applied when two profiles conflict on the same field.", "The owner package must nominate an independent review function that is not accountable for designing or operating the controls it reviews, and record the basis of that independence." ], "namespace_guidance": "Local identifiers are lower-kebab-case and stable for the life of the record. The adopting Dimension issues one namespace per owner package and qualifies every code value as namespace plus code plus version, so that a severity band, assurance level, governance line or sensitivity label is never interpreted against the wrong vocabulary. External identifiers are carried verbatim in their own namespace and are never rewritten into local form. Namespaces must not encode dates, environments or storage technology.", "registry_links": [ "The model is registered as vr.wm-xct-027 with model identifier WM-XCT-027, entry kind mixin, under parent WM-KNW-015.", "Each referenced external vocabulary is registered with its publisher identifier, version and retrieval URL, including the control catalogue, the provenance ontology, the assessment exchange schema and the sensitivity label vocabulary.", "Each declared regional or sector profile is registered with its jurisdiction or sector scope, effective period and issuing authority." ] }, "canon_and_patch": { "canonicalization_rules": [ "Serialise with deterministic member ordering and no insignificant whitespace before computing any digest; the digest is taken over the canonical form, not over a storage projection.", "Express every time value in RFC 3339 form with seconds and an explicit offset, preserving the originally recorded offset rather than normalising it away; a separate normalised UTC value may be derived but is never the canonical value.", "Represent code values as namespace-qualified strings with an explicit vocabulary version; bare labels are not canonical.", "Use decimal representation with an explicit scale for scores and levels, without locale-dependent separators; ordinal bands are represented by their code, not by a rendered position.", "Represent absent optional values by omission rather than by an empty string, so that absence and emptiness are distinguishable." ], "patch_rules": [ "Records in draft may be patched in place; records that have been reviewed, accepted or disclosed are append-only and are corrected by supersession.", "Every patch document must carry the base revision identifier and is rejected when that identifier does not match the current revision, providing optimistic concurrency.", "Patches touching an immutable field are rejected with an explicit reason code; immutable fields include the assertion instant, the asserting agent, the acted-on-behalf-of reference, the evidence digest set, the criteria binding and any authorization statement.", "A patch that would change a residual level, an acceptance or an assurance level requires the authority level applicable at the time of the patch, not the authority level used originally.", "Patches are idempotent under a caller-supplied idempotency key: replaying a key with the same base revision returns the original result without producing a second revision." ], "compatibility_rules": [ "The mixin schema carries a semantic version; adding an optional field or an enumeration member is a minor change, while removing a field, narrowing cardinality, tightening a requirement or changing the meaning of an existing code is a major change.", "Consumers must ignore unknown optional fields and must not infer meaning from field order.", "A regional or sector profile may constrain the mixin, for example by making an optional field required or narrowing an enumeration, but may never relax a requirement of the base model.", "Deprecated fields remain readable for at least one major version and are marked with their replacement and the instant of deprecation.", "Exports declare the mixin version, the profile version and the target schema version, and state explicitly which fields could not be mapped." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier issued by the system of record that owns the host record and its risk-control binding, such as the GRC, ISMS or assurance register key, used verbatim and never rewritten.", "Governed global identifier or IRI from a normative registry or published namespace, such as a control catalogue IRI, a published risk register IRI or a governed assessment-result identifier.", "UUID or ULID assigned by the adopting Dimension, used only where neither of the preceding exists, and recorded together with the party and instant of assignment.", "A date, an assessment cycle label, a review period name, a version tag, a file name or a human-readable title is never an identifier and must not be used as one, alone or in combination." ], "timestamp_rule": "All time values are recorded as RFC 3339 date-time values that include seconds and an explicit numeric offset or the literal Z; local times without an offset, dates alone and implied time zones are rejected. Event time and observation or ingestion time are recorded in separate fields whenever they differ: the instant the assessed condition existed or the decision was taken is distinct from the instant the assertion was recorded in this model, and the two are never collapsed into one field. Where an assurance conclusion covers a period, the coverage period start and end are recorded separately from both the conclusion instant and the recording instant, and the currency clock declares which of these instants starts it.", "serial_naming_rule": "Serial artifacts - authorization statements, criteria binding records, assurance limitation statements, supersession records, reconciliation reports, evidence manifests, export packages and tombstones - are named as the binding identifier, then the artifact kind, then a zero-padded sequence number that increases monotonically within that binding and artifact kind. Sequence numbers are never reused after withdrawal, and a gap in the sequence must be explained by a retained withdrawal record rather than silently closed. Dates, cycle labels and environment names never appear in a serial name.", "integrity_rule": "Every artifact carries a cryptographic digest with an explicit algorithm identifier over its canonical form, the digest of the immediately preceding revision where one exists, and the identifier of the asserting agent. Evidence references carry the digest of the referenced object as observed at assertion time together with that observation instant. A digest mismatch on any referenced evidence item, or on a preceding revision, invalidates the currency of the affected assertion and forces reassessment before further reliance; the mismatch is recorded here and reported, while remediation of the underlying store and the audit trail of the detection are owned by the referenced evidence and audit models." }, "policies": [ "Correction is by supersession, never by silent mutation: any assertion that has been reviewed, accepted or disclosed is retained in full for its retention period alongside its successor and the reason for correction.", "No party may both assert and independently review the same binding, and no party may both operate a control and accept the residual risk that control is asserted to reduce, unless a time-bounded override has been granted by an authority above both roles and recorded with a compensating condition.", "Residual risk may be accepted only by a party holding the authority level that the in-force threshold table assigns to the residual band, and the table version used is recorded with the acceptance so that later re-validation is possible.", "An assertion whose evidence fails digest verification, whose referenced risk or control has been retired, or whose validity window has elapsed is marked not current and may not be cited as the basis of a new acceptance until reassessed.", "Sensitivity labels are assigned at the level of the individual element as well as the record, and every output carries the label of the most restrictive element it contains; the party releasing information is responsible for ensuring the recipient can follow the handling rules.", "This model declares governance parameters and records governance decisions about its own content; it never evaluates access at runtime, never enforces a policy, never owns the audit trail, and never executes destruction of records.", "Machine-generated assertions are labelled as such and may not be relied upon at an assurance level above that permitted by the profile in force without a recorded human review." ], "crud": { "read": [ "Read is scoped by sensitivity label and disclosure profile: a principal receives the field projection its audience is entitled to, and fields outside that projection are omitted rather than nulled, so that absence is not mistaken for an assessed value.", "Every read of an assertion returns its revision identifier, currency status and superseded-by reference where present, so that a consumer cannot silently rely on a stale or corrected conclusion.", "Reading a superseded or expired assertion is permitted and returns it clearly marked; reading is never blocked merely because a record is not current.", "Reads that resolve to a tombstone return the tombstone rather than an error, so that inbound references remain resolvable after disposition.", "Bulk reads and exports are subject to the export function's profile checks; a bulk read is not a route around field-level disclosure rules." ], "create": [ "A binding is created in draft state with, at minimum, a resolvable host reference, a resolvable risk reference, at least one control reference or an explicit statement that the treatment is acceptance without control, a risk owner reference and the asserting agent and instant.", "Creation requires the identifier to be taken from the identity priority order; a Dimension-assigned UUID or ULID is used only where no master-system or governed identifier exists, and the assignment is recorded.", "Creation is idempotent under a caller-supplied idempotency key: replaying the key returns the originally created binding rather than a duplicate.", "A binding may not be created in an accepted state; acceptance is a separate authorised transition so that authority and assertion remain separable.", "Creation that would duplicate an existing active binding between the same risk and control on the same host is rejected unless a declared discriminator distinguishes them." ], "update": [ "Updates carry the base revision identifier and are rejected on mismatch; concurrent writers receive an explicit conflict result rather than a last-writer-wins outcome.", "Draft records may be updated in place; reviewed, accepted or disclosed records are append-only and are changed only through the supersession function.", "Changing a control linkage, residual level, criteria binding or acceptance requires re-authorisation at the currently applicable authority level and resets the currency status pending review.", "Unlinking a control from a risk is an update that must record the reason and the resulting residual level, and never removes the historical assertion that the linkage once existed.", "Updates never rewrite provenance, evidence digests or prior authorization statements; an attempt to do so is rejected with an explicit reason code." ], "delete": [ "Assertions that have been reviewed, accepted or disclosed are never hard-deleted from this model; they are withdrawn or superseded and remain readable until their retention period ends.", "Disposition eligibility is computed from the retention schedule reference, the retention clock start and the absence of any active legal hold; the computed eligibility is advisory input to the owning records capability and is not itself an instruction to destroy anything.", "Execution of destruction or erasure is owned by the referenced records retention and disposition model together with the adopting Dimension's records policy; this model issues a disposition request, records the confirmation returned to it, and never performs or claims to have performed the destruction.", "An active legal hold suspends all disposition for the held binding and its evidence manifest until the hold is released in writing by the party authorised under the adopting Dimension's records policy; application and release are recorded with RFC 3339 instants and the authorising party reference.", "On confirmed disposition a tombstone is retained containing only the binding identifier, host record reference, terminal state, disposition authority reference, disposition instant and the digest of the disposed record; risk statements, control descriptions, evidence content and free-text conclusions must not survive in the tombstone.", "Draft assertions never submitted for review may be hard-deleted by their author, provided no external consumer has read them and no hold applies; the deletion is emitted as an event to the referenced audit trail model, whose retention this model does not own.", "Erasure requests arising from data-protection law are routed to the adopting Dimension's privacy policy owner; this model records the request reference and the resulting field-level suppression, and does not adjudicate the request or determine its lawful outcome." ] }, "roles": [ { "name": "Risk owner", "responsibilities": [ "Holds accountability for the residual risk conclusion recorded on the host record and for keeping it current.", "Approves the treatment linkage and requests reassessment when a trigger fires.", "Cannot discharge accountability by delegating operational execution." ] }, { "name": "Control owner", "responsibilities": [ "Holds accountability for the design and operation of a linked control.", "Supplies evidence of operation and notifies the risk owner of control failure or material change.", "Is excluded from independently reviewing the effectiveness of the same control." ] }, { "name": "Independent reviewer or assurance provider", "responsibilities": [ "Reviews assertions from a position independent of those who design or operate the controls, and records the basis of that independence with identified threats and safeguards.", "Declares the assurance level reached, the methods and objects applied, and every scope limitation and carve-out.", "Refuses or qualifies a conclusion where evidence is not sufficient and appropriate for the asserted level." ] }, { "name": "Risk acceptance authority", "responsibilities": [ "Accepts residual risk only within the level the in-force threshold table assigns to that band, and records the table version used.", "Re-takes acceptance when a binding is materially changed, expires or is superseded.", "Escalates where the residual band exceeds the authority held." ] }, { "name": "Records and disposition steward", "responsibilities": [ "Maintains retention schedule references, clock starts and disposition status for the mixin's records.", "Applies and releases legal holds on written instruction from the authorised party and confirms that disposition executed elsewhere has completed.", "Verifies that tombstones retain only the permitted minimum after disposition." ] }, { "name": "Disclosure steward", "responsibilities": [ "Maintains disclosure profiles, sensitivity labels and field-level disclosure rules, and their versions.", "Authorises or refuses out-of-profile releases and records the decision.", "Checks that redacted exports cannot be re-identified by combination with prior releases." ] }, { "name": "Model steward", "responsibilities": [ "Maintains the mixin schema version, profile registrations, external mappings and their lossiness statements.", "Runs reconciliation against referenced registries and publishes the resulting reports.", "Records unresolved boundary questions and conflicts rather than resolving them by local convention." ] } ], "access": { "default_rule": "Deny by default. A principal may read or write a WM-XCT-027 record only where an explicit grant exists for the requested scope and operation and the record's sensitivity label permits that principal's audience. This model declares the required grant, authority level and label; the decision is evaluated and enforced by the adopting Dimension's referenced authorization model, which this model neither implements nor overrides.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Independent reviewers and assurance providers receive read access across findings and artifacts within their engagement scope, including material otherwise restricted to the owning line, because independence requires unfettered access to the people, resources and data needed to complete the work.", "A legally authorised recipient, such as a supervisory or competent authority exercising a documentation-access right, receives the unredacted record for the statutory period regardless of the default disclosure profile, with the release recorded.", "Under an active legal hold, read access is preserved and delete or disposition operations are suspended for all principals, including those who would otherwise hold disposition rights.", "A binding whose risk statement discloses an exploitable, unremediated weakness may be restricted below its owner's normal entitlement until remediation, on the recorded instruction of the disclosure steward.", "Emergency access outside the granted scope is possible only where the adopting Dimension's authorization model supports a break-glass path; this model records the invocation reference and requires post-hoc review, and does not itself grant the access." ], "audit_requirements": [ "Creation, review, approval, acceptance, unlinking, supersession, hold application and release, export and disposition request must each be emitted as an event to the referenced audit trail model, whose record structure, immutability and retention this model does not own.", "Every emitted event carries the binding identifier, revision identifier, acting party, authority basis, event instant and the recording instant, with an explicit offset on each.", "Refusals are emitted as well as successes, including authority refusals, duty-separation refusals, concurrency conflicts, digest mismatches and out-of-profile export refusals.", "Disclosure events carry the disclosure profile identifier and version, the audience and the sensitivity label applied to the output.", "This model retains only the reference to each audit entry; it does not reproduce, reconcile or assert completeness of the audit trail." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL", "Owner package and accountable party reference", "Profiles in force with effective periods", "Referenced model bindings with versions" ], "read_order": [ "Read AGENTS.md first to obtain the model name, type and the four resolvable URLs before touching any record.", "Read the Specification URL to obtain the boundary, in-scope and out-of-scope statements and the composition links, so that target-owned concepts are not modelled or written locally.", "Read the Storage type URL to learn the projection in use, remembering that the projection is not the semantics and that identity, time and integrity rules come from the specification.", "Read the Interface URL to learn the available operations, their idempotency and concurrency semantics and their failure codes.", "Read the Processes URL to learn authorisation, review, reconciliation, expiration, export and disposition procedures and who owns execution where it lies outside this model.", "Read the declared profiles and referenced model bindings last, and refuse to write where a required binding does not resolve." ] } }, "coverage": { "claim": "Audit covers the sole active Claude result for WM-XCT-027 against its own evidence only: 37 declared sources, 9 bundles, 19 layers, 39 findings, 176 questions, 16 artifacts, 20 functions, the frozen registry record (vr.wm-xct-027, mixin, parent WM-KNW-015), the nine boundary notes, and the declared conflicts, omissions and regional assumptions. Coverage is bounded and partial: no live retrieval, no clause-level verification of any cited standard, no second-provider corroboration, and no claim of universal completeness over the risk-and-control domain. Findings below are internal-consistency and boundary defects checkable from the pack alone.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Risk reference plus exact revision pin, taxonomy system identifier, criteria and method references with versions, scenario identifiers and artifact identity strategies. Identity priority puts the authoritative master-system identifier first and forbids dates, cycle names and version labels as identifiers." }, { "dimension": "classification", "status": "covered", "notes": "Category values are always paired with a taxonomy system identifier and version; multiplicity and mapping fidelity are explicit; changing a pinned category after an estimate exists requires an authorized role and supersession." }, { "dimension": "measurement and scale semantics", "status": "covered", "notes": "Expression mode, scale type, unit, scale reference, distribution parameters, per-dimension impact scales and prohibited operations are all first-class. No matrix, band set or default scale is defined by this model." }, { "dimension": "uncertainty and confidence", "status": "covered", "notes": "Uncertainty representation is a required field; confidence or data-quality grade, unmeasurable aspects and precision caveats are captured, following the AI RMF position that some risks resist measurement." }, { "dimension": "comparability and aggregation", "status": "covered", "notes": "A dedicated comparability verdict with named mismatched pins, non-strippable aggregation caveats, scenario variant sets, reference-case designation and withdrawn-criteria handling. No normalization algorithm is asserted." }, { "dimension": "standards conformance evidence", "status": "gap", "notes": "ISO 31000, ISO 31073, ISO/IEC 27005 and the COSO ERM framework texts are paywalled or were not retrievable; IEC 31010 and Open FAIR were verified only at catalogue and publication level, and the EU AI Act text was read via republication rather than EUR-Lex. Alignment is therefore asserted at scope level and no clause-level support is claimed anywhere in this model." }, { "dimension": "relationships", "status": "covered", "notes": "Directed risk-to-control links with claimed mechanism, many-to-many coverage topology, control dependency and reliance edges, and framework crosswalks with relation strength. Fifteen composition links record which neighbour owns each adjacent concept." }, { "dimension": "control classification vocabulary anchor", "status": "gap", "notes": "The most widely used published attribute vocabulary for preventive, detective and corrective control type is ISO/IEC 27002:2022, which could not be retrieved (iso.org returned HTTP 403 to every request). The distinction is anchored instead on the GAO Green Book and PCAOB material, and the canonical vocabulary is left Dimension-declared rather than presented as standardised." }, { "dimension": "quantified risk-reduction attribution", "status": "gap", "notes": "No consulted primary source prescribes a method for quantifying how much of an inherent-to-residual delta is attributable to one control. The model therefore records the attribution method, its scale and an acceptance status by the risk owner, and does not define or endorse a computation." }, { "dimension": "evidence and assurance", "status": "covered", "notes": "Assessment method from examine, interview and test, depth and coverage, assessor independence, evidence references with digests, sufficiency rationale tied to control risk, and a hard rule that a conclusion may cite only verified bindings." }, { "dimension": "exceptions and compensating controls", "status": "covered", "notes": "Approved exceptions with expiry, deviations from design, and compensating or alternative controls carrying a sense code that distinguishes the baseline-alternative meaning from the deficiency-mitigating meaning, plus the documented constraint that justifies them." }, { "dimension": "security and confidentiality of control detail", "status": "covered", "notes": "Access defaults to deny, aggregate statistics can be released without per-control detail where that detail is sensitive, and external disclosure is time-boxed and named." }, { "dimension": "geospatial location", "status": "not-applicable", "notes": "Physical location enters only as a covered-population or component reference resolved in the host subject or asset model; this mixin holds no geometry and defines no spatial semantics of its own." }, { "dimension": "lifecycle", "status": "covered", "notes": "States, permitted transitions, host-lifecycle cascade, terminal states and surviving obligations are modelled as host-scoped obligations. No standalone risk or control lifecycle is created; risk register and catalogue lifecycles stay with the referenced models." }, { "dimension": "temporal", "status": "covered", "notes": "RFC 3339 with seconds and explicit offset is mandated; assessed-at, recorded-at, coverage period, valid-until, state-entered-at, authorization time and disposition instant are separate fields, and the currency clock declares which instant starts it." }, { "dimension": "provenance", "status": "covered", "notes": "Asserting agent, acted-on-behalf-of, generating activity, derivation and agent kind are aligned to the provenance ontology's attribution, generation, derivation and revision relations. The general provenance graph remains external." }, { "dimension": "ownership", "status": "covered", "notes": "Separate accountability for the residual risk conclusion and for each linked control, governance-line placement, delegation without transfer of accountability, and vacancy handling. Party records themselves stay in the referenced registry." }, { "dimension": "validation", "status": "covered", "notes": "Evidence digest verification, base-revision concurrency checks, threshold-table currency re-validation, duty-separation breach detection, criteria suitability and re-identification checks on redacted exports." }, { "dimension": "access", "status": "covered", "notes": "Deny-by-default with sensitivity-label and disclosure-profile scoping over bundle, layer, finding and artifact, five declared exceptions, and explicit delegation of evaluation and enforcement to the referenced authorization model." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Retention schedule reference and clock start, legal hold suspending the disposition cycle with written release, tombstone minimum content, and an explicit statement that execution of destruction is owned by the referenced records model and the adopting Dimension's records policy." }, { "dimension": "interoperability", "status": "covered", "notes": "Mapping to an assessment-results exchange model with an explicit lossiness statement, adoption of a published sensitivity label vocabulary, regional and sector profile declarations with precedence, and compatibility rules for versioned exchange." }, { "dimension": "authority and segregation of duties", "status": "covered", "notes": "Assertion authority is separated from residual-risk acceptance authority, bound to a versioned threshold table, and constrained by a declared incompatible-duty set with time-bounded, authorised overrides." }, { "dimension": "assurance and evidence quality", "status": "covered", "notes": "Assurance level, methods and objects, scope exclusions, coverage period and carve-outs on inherited third-party reports are recorded so a consumer can bound its reliance." }, { "dimension": "privacy and sensitive disclosure", "status": "covered", "notes": "Personal data indicator, field-level withholding, generalisation and hashing, audience entitlement, out-of-profile release authorisation, and routing of statutory erasure requests to the privacy policy owner." }, { "dimension": "jurisdiction and location", "status": "covered", "notes": "Handled through regional and sector profiles with effective periods, jurisdiction scope and a precedence rule; the mixin carries no geospatial semantics of its own because a risk-control binding has no intrinsic geometry." }, { "dimension": "measurement of control effectiveness", "status": "gap", "notes": "No consulted primary source defines a portable, comparable numeric scale for control effectiveness or residual reduction. The model records the criteria and scale version used but cannot guarantee cross-organisation comparability of a residual level." }, { "dimension": "security of the record itself", "status": "covered", "notes": "Digest chaining across revisions, immutable field set, append-only behaviour after review, and detection of evidence substitution. Cryptographic key management and signing services are external." } ], "known_omissions": [ "Numeric matrix definitions, band labels, threshold values and scoring rules are deliberately absent; they are supplied by reference from a Dimension-owned criteria registry.", "No control-effectiveness rating vocabulary is defined; effectiveness determinations are cited from the control assessment model in whatever form that model publishes them.", "Risk treatment options, treatment plans, milestones, cost tracking and closure are not modelled.", "Realized loss events, incidents, issues and near misses are not modelled; loss data may only be cited as an information source.", "Opportunity-side assessment is admitted through an effect-polarity field, but no upside-specific valuation dimensions or benefit scales are enumerated.", "Sector-mandated methods such as prudential capital models, medical-device hazard analysis and safety-integrity-level assignment are not enumerated; they are treated as pinnable methods.", "Technique internals for bow-tie, fault-tree, event-tree, Bayesian and simulation methods are referenced by name and version only.", "Key risk indicator and key performance indicator definitions, monitoring thresholds and trend detection are not modelled here.", "No guidance is given on how many scenarios constitute an adequate scenario set for a given method.", "ISO/IEC 27001:2022 and ISO/IEC 27002:2022 could not be retrieved during research (iso.org and the ISO Online Browsing Platform returned HTTP 403). The Statement of Applicability pattern and the published control attribute set are therefore reflected structurally but not cited, and no ISO conformance is claimed.", "COBIT (ISACA) and the full COSO ICIF-2013 text are paywalled; only COSO's public description of five components, seventeen principles and the present-and-functioning criterion was verified.", "Regulation (EU) 2022/2554 (DORA) and its regulatory technical standards on ICT risk management tools could not be retrieved from EUR-Lex during research, so EU-specific duties to document residual ICT risk and have it approved by the management body are not modelled.", "BCBS d515 was verified only at the publication landing page; three-lines-of-defence role allocation and risk and control self-assessment mechanics are therefore not asserted from it.", "Statistical sampling methodology, sample size determination and confidence computation for control testing are referenced as a sample basis field but not modelled.", "Continuous control monitoring schemas and control-as-code assertion formats are referenced conceptually; no single primary schema was adopted for automated effectiveness signals.", "Control cost, benefit, rationalisation and portfolio optimisation are excluded entirely.", "Sector-specific control taxonomies (for example safety instrumented functions or clinical controls) are not covered; adopters must extend the classification vocabulary locally.", "Maturity models for control processes are not modelled; maturity and effectiveness are treated as different questions and only the latter is in scope.", "No canonical vocabulary is prescribed for control linkage type beyond the preventive, detective and corrective distinction; sector taxonomies differ and none of the consulted primary sources is authoritative across sectors.", "Aggregation semantics are not modelled: how many host-level residual conclusions roll up into a portfolio or entity-level risk position is left to the parent knowledge model and the adopting Dimension.", "Cost, effort and benefit of treatment measures are excluded, although they influence acceptance decisions in practice, because no consulted primary source constrains their representation.", "Bow-tie style causal decomposition of a risk into causes, events and consequences is referenced only through the risk model and is not represented here.", "Threat and vulnerability intelligence linkage is not modelled; only the sensitivity handling of resulting risk information is.", "Continuous control monitoring telemetry is out of scope; only the resulting conclusion and its currency are carried.", "No opinion is offered on whether a binding constitutes a record subject to any particular statutory retention period; the schedule reference is supplied by the records model." ], "conflicts": [ "Inherent or gross risk is not uniformly defined. Some frameworks exclude all controls, others exclude only the controls under assessment, and some public-authority guidance does not require an inherent estimate at all. The model therefore requires an explicit inherent-definition statement and a documented omission ground rather than assuming any single reading.", "Risk appetite and risk tolerance are used interchangeably in parts of the guidance landscape and as distinct constructs elsewhere, with NIST IR 8286A treating tolerance as the expressed, measurable bound and HM Treasury guidance leading with appetite. The model stores a versioned reference and an outcome rather than adopting one vocabulary.", "OSCAL expresses residual risk as an adjusted characterization facet state rather than as a separate residual field, which conflicts with register-style models that hold inherent and residual as parallel columns. The model supports both by pairing a role-tagged estimate with a characterization state.", "Risk as the effect of uncertainty on objectives admits positive effects, whereas the NIST information-security risk model and the Open FAIR taxonomy are loss-oriented. The effect-polarity field records which reading is in force rather than forcing reconciliation.", "Semi-quantitative ordinal scores are routinely multiplied and averaged in practice although ordinal scales do not support arithmetic. The model stores scale-referenced codes and refuses implicit arithmetic, which conflicts with common matrix tooling and will require projection-level accommodation.", "Enterprise roll-up guidance encourages staging registers into a single profile, while measurement guidance warns that risks are not uniformly measurable. The model resolves this in favour of an explicit comparability gate and non-strippable caveats rather than an unsupported normalization rule.", "Assessment-outcome vocabularies conflict across sources: NIST SP 800-53A resolves determinations to satisfied or other than satisfied, PCAOB AS 2201 grades design and operating deficiencies as deficiency, significant deficiency or material weakness, and the NCSC CAF uses achieved, partially achieved or not achieved. The model stores the conclusion with its vocabulary identifier and version rather than forcing one scale.", "Implementation-status vocabularies differ: the OSCAL system security plan by-component uses implemented, partial, planned and not applicable, while PCI DSS distinguishes a compensating control from a customized approach and forbids combining them for the same requirement. Both are carried as source-qualified codes with no silent merge.", "The term compensating control carries two incompatible senses. NIST defines it as an alternative to a baseline control giving equivalent or comparable protection, whereas PCAOB treats it as a control that mitigates an identified deficiency at a level of precision sufficient to prevent or detect a material misstatement. The model requires an explicit sense code on every compensating control reference.", "GAO-14-704G (September 2014) is superseded by GAO-25-107721 (15 May 2025, effective fiscal year 2026). Both were consulted; the newer edition governs where they differ, and the older is cited only for the preventive-versus-detective distinction and the integrated-operation criterion whose full text was retrievable.", "CSF 2.0 informative references and OSCAL crosswalks are alignments, yet adopters commonly present mapping tables as conformance or assurance evidence. The model rejects this inference and enforces it with a mandatory non-conformance disclaimer field.", "Control frequency has two distinct meanings that are often conflated: the cadence at which a control operates and the cadence at which it is assessed. SP 800-137 governs the latter and OSCAL task timing can express either; the model separates operating frequency from assessment timing into different findings.", "Retention obligations conflict across regimes: a ten-year documentation-retention duty for high-risk AI documentation can outlast a shorter organisational schedule and can collide with data-protection erasure duties where the binding contains personal data. The model records both references and the resulting suppression but does not adjudicate precedence, which is left to the adopting Dimension's records and privacy owners.", "Independence expectations differ: internal-audit independence as described by the professional body is organisational, while auditing and attestation standards impose a formal conceptual framework of threats and safeguards. A reviewer independent enough for internal purposes may not meet the external threshold, so the independence basis is recorded as a code rather than a boolean.", "Justification practice for control inclusion diverges: some certification practice accepts a single blanket justification that all included controls were identified as necessary by the risk assessment, while exclusions must be individually justified. This asymmetry is preserved rather than normalised.", "Sensitivity labelling regimes conflict where a published community label vocabulary meets a national classification scheme; the model carries the label vocabulary and version but cannot map between them without a jurisdiction-specific profile.", "Assessment-results exchange models treat a finding as an output of a time-boxed engagement, whereas this mixin treats the binding as durable state on a host. Round-tripping is therefore lossy in both directions and must be declared as such." ], "regional_assumptions": [ "HM Treasury Orange Book material is UK central-government guidance; its category list, assurance construct and three-lines role separation are treated as one adoptable projection, not a universal taxonomy.", "NIST publications are US federal guidance; their register field sets, risk model components and framework steps are alignment targets rather than obligations outside that context.", "The EU AI Act residual-risk acceptability requirement applies only to high-risk AI systems in EU scope, with the referenced provisions applying from 2 December 2027 and 2 August 2028 for the respective categories; it is modelled as a scoped legal projection and not generalized.", "Currency, monetary impact bands, fiscal-year horizons and working-day conventions are jurisdiction- and Dimension-specific and are carried as unit and scale references rather than fixed values.", "Data-protection constraints on affected-party and narrative consequence fields vary by jurisdiction; the redaction rule delegates to the adopting Dimension's privacy policy rather than assuming one regime.", "Retention periods, assessor independence requirements and management attestation duties are jurisdiction-specific. The model records a retention class and an independence flag but adopts no jurisdiction's schedule or threshold.", "PCAOB AS 2201 and the GAO Green Book are United States sources whose deficiency-severity ladder and internal-control criteria are offered as one selectable vocabulary, not as the default for all adopters.", "The NCSC Cyber Assessment Framework is a United Kingdom framework aimed at essential services and critical national infrastructure; its three-value outcome scale is offered as a selectable vocabulary rather than a global standard.", "Financial-sector supervisory expectations and EU ICT resilience law may require explicit management-body approval of residual risk and additional independent review that the adopting Dimension must add locally; no such duty is assumed here.", "The model assumes an adopting Dimension that operates at least one system of record capable of issuing authoritative identifiers; where none exists the identity priority falls through to governed IRIs and then to UUID or ULID.", "Litigation hold and disposition-freeze semantics are drawn from a United States federal records practice in which counsel issues the hold and a written instruction is required to lift it. Other jurisdictions place the duty to preserve on different actors and at different trigger points; the hold reference and authority are therefore modelled as external references.", "The ten-year documentation-retention assumption derives from European high-risk AI provisions and applies only where those provisions bind the host; it is not a general default.", "Governance-line terminology assumes an organisation large enough to separate management, oversight and independent assurance. Small entities routinely combine these roles, so the model requires the overlap to be declared and mitigated rather than prohibited outright.", "Certification-oriented statements about determining necessary controls and justifying exclusions assume an information-security management system context and may not transfer unchanged to safety, financial or clinical risk regimes.", "Sensitivity label handling assumes a community whose members have agreed to the label vocabulary; where no such agreement exists, the labels carry no enforceable handling obligation." ], "adversarial_checks": [ "Entry-kind challenge, recorded for adjudication: relationship was tested as an alternative subject kind. A relationship entry would give each risk-to-control link its own identity, which genuinely suits relied-on-control attribution and residual change explanation, both of which are n-ary link attributes. It fails for the remaining required content - assessment scope, horizon, criteria pin, likelihood and consequence dimensions, uncertainty, appetite comparison - which are properties of an assessment context attached to a host record rather than of a single link, and one context routinely cites many controls and many consequences. mixin is retained; a Dimension may reify the control-reliance attribution as a separate association record without altering this field group.", "Ownership-leak sweep: every bundle, layer, finding, data element and function was re-read against each composition rationale and boundary note. Control effectiveness is cited and never determined; acceptance and authorization are referenced and never granted; observation capture, evidence collection and audit-log retention are delegated with the delegation stated in the audit requirements themselves; risk entity status transitions appear nowhere; no function evaluates, executes or enforces anything.", "Universal-matrix check: no five-by-five grid, fixed likelihood band, default impact scale or scoring formula appears anywhere in the structure. Qualitative, ordinal, semi-quantitative, quantitative, probabilistic, scenario-based and multi-dimensional expressions are all admitted through an expression-mode field plus a resolvable scale reference, and prohibited operations are derived from the declared scale type.", "Counterexample search: three awkward cases were tested against the field group. A quantitative frequency-and-magnitude analysis producing a distribution is representable through distribution parameters and quantitative units. A purely qualitative safety hazard judgement with no inherent estimate is representable because the inherent estimate is optional with a required omission ground. A scenario-set assessment with no single headline likelihood is representable through scenario identifiers, per-scenario estimates and an explicit reference-case designation. A fourth case, an assessment relying on a control with no current effectiveness determination, drove the reliance-without-determination flag.", "Aggregation trap: the structure deliberately refuses to define a roll-up algorithm even though enterprise staging guidance encourages a single profile. The comparability function returns a verdict, the mismatched pins and a caveat set, and leaves construction of any aggregate to the enterprise reporting model. This is the most likely point of pressure from adopters wanting a single enterprise number.", "Date-as-identifier check: no identifier field, serial naming rule or artifact identity strategy uses an assessment date, review cycle, fiscal period or version label as an identifier; the serial rule explicitly excludes date, period and cycle components and forbids reuse of retired sequence values.", "Inline-versus-artifact audit: eleven findings are inline because they are reference, pin, dimension or verdict fields that must stay inseparable from the values they qualify; the two findings that declare artifacts do so for genuinely separable documents - a pinned criteria and method record and the basis and derivation records - and no finding carries both artifacts and a rationale.", "Documentation is not effectiveness. A complete policy, procedure, design description or control catalogue entry sets no effectiveness field; a conclusion requires at least one verified assessment or evidence binding. The Basel Committee's own review finding that several operational-risk principles had not been adequately implemented, despite being published, is the counterexample this rule encodes.", "A framework crosswalk is not conformance. Mapping this control to an entry in another catalogue sets only crosswalk fields with a mandatory non-conformance disclaimer, and can never set applicability, implementation status or effectiveness.", "Absence of incidents is not evidence. No field permits an effectiveness conclusion derived from a zero incident count, a clean loss record or an uneventful period; incident and loss records are explicitly out of scope and are not a permitted conclusion basis.", "Design adequacy does not imply operation. A control can be adequately designed and not implemented, implemented and not operating, or operating and never tested. Four independent status fields plus a separate conclusion prevent any collapse, and no function derives one from another.", "Ownership creep audit. Every bundle, layer, finding and function was compared against each boundary note and composition link. No node stores catalogue text, policy text, configuration state, test cases, test results, evidence payloads, remediation workflow states or audit-trail records. References to a runtime evaluator, an enforcement engine or an audit record confer no evaluation, execution, enforcement or trail semantics here; the operating-cadence finding declares expected cadence and consumes observed counts by reference only, and audit requirements emit to the audit model while retaining only the emission reference.", "Stale-conclusion audit. An expired conclusion cannot masquerade as current: read returns an explicit expired marker, the residual contribution is suspended, and patching an expired conclusion is forbidden so that a fresh basis must be produced.", "Identifier audit. No local identifier, in any bundle, layer, finding, question, data element, artifact or function, encodes a date, a status, a period or a framework code, so records cannot be silently re-keyed or invalidated when a framework version or reporting period changes.", "Vocabulary-merge audit. Conflicting external status and outcome scales are never coerced into one internal scale; every coded value carries its vocabulary identifier and version, and consumers must fail closed rather than default an unknown value to applicable, implemented or effective.", "Tested whether this mixin quietly acquires ownership of runtime authorization: the authorization function was restricted to deciding admissibility of writes to this model's own records, with evaluation and enforcement moved to a composition reference and recorded in the boundary notes, and the duty-separation finding was made inline specifically to avoid creating a competing rule store.", "Tested whether audit-trail semantics were being absorbed: all audit language was rewritten as emission of events to a referenced model, with an explicit statement that record structure, immutability, query and audit retention are not owned here and that the model retains only references.", "Tested whether deletion ownership was overclaimed: the disposition function now produces an advisory eligibility verdict and a request, and the delete rules name the referenced records model and the adopting Dimension's records policy as the owners of execution.", "Tested whether a standalone risk or control lifecycle was smuggled in: state and currency findings were rewritten as host-scoped obligations, and the inline-only rationale for the state finding records why no separate lifecycle artifact exists.", "Searched for a counterexample to the claim that residual risk always has a single accepting authority: risks accepted jointly across entities, and inherited third-party controls where the accepting party cannot compel the operator, both break it. The criteria-conflict and inherited-reliance questions were added so the model records the divergence instead of forcing a single verdict.", "Tested whether attractive but unsupported structure had been added: a quantitative residual-reduction scale and a control maturity ladder were rejected because no consulted primary source defines a portable scale, and the absence is recorded as a checklist gap rather than filled with plausible invention.", "Tested the artifact-versus-inline split for convenience bias: findings were forced to justify inline status on ownership grounds rather than on brevity, which moved provenance, profiles and duty separation to inline with explicit rationales while leaving artifacts only where this model genuinely authors a durable, citable output." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "claude" ], "waivedProviders": [ "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-08-29T09:06:27Z", "scope": "Queued subject-model research from WM-XCT-013 onward", "active_providers": [ "claude" ], "waived_providers": [ { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-08-29T09:06:27Z", "reason": "The repository owner explicitly instructed the research queue to continue without Grok after repeated structured-output failures." } ], "review_rule": "Claude-only results require a separate no-tools adversarial audit and remain reviewable drafts with a visible single-provider hold." }, "boundaryDecision": { "entry_kind": "mixin", "status": "split", "rationale": "Two axes must be kept apart. On the record plane the frozen registry classifies vr.wm-xct-027 as a child record embedded under parent WM-KNW-015 rather than a standalone model plane; that classification governs registration and inheritance only and is not itself a subject-model kind. On the subject-model plane the defensible schema kind for the retained core is mixin: bundles 1-3 and 7-9 are a reusable, host-scoped field group with no independent identity, whose lifecycle is expressly host-scoped (rctl-gov-binding-state inline rationale) and whose content is reference pins, estimate slots, verdicts and governance stamps. The pack's own rejection of relationship is sound - assessment scope, horizon, criteria pin, likelihood and consequence dimensions, uncertainty and appetite comparison are properties of a context that cites many controls and many consequences, not of one edge. The status is split rather than accepted because bundles 4-6 (rctl-control-definition-binding, rctl-control-linkage-topology, rctl-control-assurance) author durable local artifacts - implementation assertion records, assessment/evidence manifests, effectiveness conclusion statements and a coverage matrix - that the same record's scope_statement, out_of_scope list, boundary note 2 and the rctl-risk-residual-estimate inline rationale all disclaim as owned elsewhere. The retained mixin keeps risk binding, framing, estimation, residual position, comparability and governance; the control design/implementation/operating/effectiveness authoring plane and the cross-record coverage matrix move to the control assessment model already named as their owner, leaving citation-by-reference behind. This split is the adjudicated boundary action to be recorded in the draft; it does not stop publication of a single reviewable draft carrying the hold." }, "decisions": [ { "concept": "Subject-model entry kind for the retained core (mixin vs relationship vs entity)", "disposition": "accepted as mixin", "rationale": "The retained content has no identity independent of a host record, declares its lifecycle host-scoped, and stores pins, slots and verdicts rather than an authored subject. The pack's counter-test against relationship holds: one assessment context routinely cites many controls and many consequences, so an edge-identity kind cannot carry scope, horizon, criteria pin, dimensions, uncertainty or appetite comparison." }, { "concept": "Aggregate root ambiguity across the three merged passes", "disposition": "reclassified to one host-scoped assessment-context root", "rationale": "Three roots are implied at once: an assessment context (risk pass), a control assertion set bound to exactly one catalogue entry (rctl-control-catalogue-binding), and a risk-control edge (rctl-gov-binding-state). crud.create admits a binding with at least one control reference while the duplicate rule and rctl-gov-q-state-concurrent key on a single risk-control pair. The synthesizer must fix the root at the host-scoped context and restate edge cardinality as a contained collection, not a second root." }, { "concept": "Control assurance authoring plane in bundle rctl-control-assurance", "disposition": "split out to the control assessment model", "rationale": "out_of_scope excludes evaluation or testing of control design and operating effectiveness and the production of effectiveness determinations, and boundary note 2 assigns them to the control assessment model, yet rctl-control-artifact-effectiveness-conclusion-statement, rctl-control-artifact-implementation-assertion-record and rctl-control-fn-record-effectiveness-conclusion author exactly those objects locally. The record contradicts its own contract and must cite rather than author." }, { "concept": "Local coverage matrix artifact rctl-control-artifact-coverage-matrix", "disposition": "rejected as an authored local artifact", "rationale": "rctl-risk-comparability-limits declares no local aggregate artifact because aggregates belong to the enterprise reporting model, and known_omissions states aggregation semantics are not modelled. A many-to-many matrix spanning many risks, controls and hosts is cross-record state a host-scoped field group cannot own. Retain the traversal question, drop the authored matrix." }, { "concept": "Non-retrievable standards carried as tier-1 primary support", "disposition": "reclassified to scope-level alignment with explicit non-retrieval markers", "rationale": "known_omissions records that ISO/IEC 27001 and 27002 returned HTTP 403 and that ISO 31000 and the COSO texts were paywalled or unretrievable, yet SRC-030, SRC-031, SRC-013 and SRC-026 are listed primary_source true and SRC-030 and SRC-031 carry seven or more governance nodes and functions as source_refs. Support may not be asserted at a tier the pack simultaneously declares it does not hold." }, { "concept": "AI Act citation provenance, SRC-012 republication against SRC-034 official text", "disposition": "rejected as primary support; re-point or dual-cite to SRC-034", "rationale": "SRC-012 is a tier-3 third-party republication yet is load-bearing in rctl-risk-consequence-dimension, rctl-risk-residual-estimate, rctl-risk-appetite-comparison, boundary note 6 and rctl-risk-fn-compare-inherent-residual, while SRC-034 supplies the tier-1 EUR-Lex text in the same pack. The coverage gap note also says the AI Act was read via republication rather than EUR-Lex, contradicting SRC-034's own entry." }, { "concept": "Artifact identity strategies that embed version tokens", "disposition": "rejected as written; narrow the global rule or rewrite three strategies", "rationale": "identity_priority forbids a version tag as an identifier alone or in combination, but rctl-risk-criteria-pin-record combines a governed IRI with an immutable version token, rctl-gov-art-criteria-binding combines a criteria-version IRI with a binding revision IRI, and rctl-gov-art-disclosure-profile appends a semantic version. Either the global prohibition is narrowed to bare or leading version tags, or the three strategies are restated." }, { "concept": "Access scope enumeration omits the field plane", "disposition": "rejected as written; field scope must be declared", "rationale": "access.scopes lists bundle, layer, finding and artifact, which are research-structure planes, while crud.read promises a field projection and rctl-gov-q-sens-field requires field-level withholding, generalisation or hashing. The enforcement surface the model declares does not include the plane its own disclosure rules operate on." }, { "concept": "Precedence among the five declared access exceptions", "disposition": "deferred pending a declared precedence rule", "rationale": "Unfettered reviewer access, statutory unredacted release and restriction of a binding disclosing an exploitable unremediated weakness can collide on the same record with no ordering stated, even though the model does declare precedence for conflicting regional and sector profiles. The asymmetry must be closed before enforcement can be delegated coherently." }, { "concept": "Hard-delete precondition for unreviewed draft assertions", "disposition": "rejected as unverifiable within the declared boundary", "rationale": "crud.delete permits an author to hard-delete a draft provided no external consumer has read it, while access.audit_requirements state the model retains only references and does not reproduce, reconcile or assert completeness of the audit trail. The model cannot establish the precondition it conditions destruction on; the rule must be restated as a delegated check." }, { "concept": "Claimed count of fifteen composition links", "disposition": "rejected as unsupported by the delivered structure", "rationale": "The relationships checklist entry asserts fifteen composition links recording neighbour ownership, and the adversarial checks reference composition rationales, but the pack delivers only nine boundary_notes and no composition-link array. Either the links are emitted or the count is corrected; an uncorroborated count inflates the ownership evidence the split decision depends on." }, { "concept": "rctl-risk-fn-compare-inherent-residual recording a difference", "disposition": "reclassified to a change-set record with mode-gated arithmetic", "rationale": "The declared conflict on ordinal scales states the model stores scale-referenced codes and refuses implicit arithmetic, yet the function description records the difference between two estimates. A difference is undefined under qualitative, ordinal and scenario-based expression modes; the function must record changed dimensions and direction, computing a magnitude only where the pinned expression mode admits it." }, { "concept": "Coverage verdicts for retention, privacy and security dimensions", "disposition": "reclassified to covered-by-service-layer", "rationale": "Each of these dimensions is marked covered while the structured question set carries exactly one question of the corresponding kind across 176 questions, with the weight resting on crud, policies and access prose. The verdict is defensible only if it names the service layer as the carrier, otherwise it overstates finding-level coverage." }, { "concept": "Missing reconciliation report artifact", "disposition": "rejected as an undeclared but published output", "rationale": "serial_naming_rule enumerates reconciliation reports among serial artifacts and the Model steward role publishes them, and rctl-gov-fn-reconcile-bindings produces them, yet no artifact and no identity strategy is declared anywhere in the structure. A durable, published, serial output must carry an identity rule or be withdrawn from the naming rule and the role." }, { "concept": "Handling of superseded GAO-14-704G alongside GAO-25-107721", "disposition": "accepted", "rationale": "The pack cites both editions, marks the superseded one at a lower authority tier, records the supersession as a named conflict, states which edition governs on divergence, and limits use of the older text to the two passages whose full text was retrievable. This is the correct pattern and should be preserved verbatim through synthesis." }, { "concept": "Refusal to define a risk matrix, default bands or a normalization algorithm", "disposition": "accepted", "rationale": "No grid, default likelihood band, impact scale or scoring formula appears anywhere; expression mode plus a resolvable scale reference carries the semantics, prohibited operations derive from the declared scale type, and aggregation is gated by a comparability verdict with non-strippable caveats. This restraint is the strongest part of the record and must survive the split intact." } ], "publicationHolds": [ "Live source and version verification hold: all 37 sources must be re-resolved before publication, with specific attention to the December 2025 revision pins on SRC-002, SRC-003 and SRC-004, the OSCAL v1.1.2 pin on SRC-005, the 29 July 2026 update on SRC-007, and the SP 800-53 release 5.2.0 pins on SRC-006 and SRC-014. No URL or version pin in this pack was resolved during this audit.", "Single-provider hold: the repository owner waived independent second-provider (Grok) review on 2026-08-29T09:06:27Z after repeated structured-output failures. Every publication artifact must display that this result had no independent second-provider corroboration and remains a reviewable draft, not a validated model record.", "Non-retrieved source labelling hold: SRC-030, SRC-031, SRC-013, SRC-026 and the catalogue-level-only SRC-008 must be marked non-retrieved and demoted to scope-level alignment before the draft is published, because they are currently carried as primary tier-1 support in findings and functions the pack itself says have no clause-level basis.", "Unresolved ownership split hold: the draft must visibly record that bundles 4-6 author control implementation, assessment-evidence and effectiveness artifacts that the same record's scope_statement, out_of_scope list and boundary note 2 assign to the control assessment model, and that the split adjudication is pending.", "Time-sensitive standard hold: SRC-019 (PCAOB AS 2201) carries amendments noted effective 15 December 2026, after the intended publication date, so the deficiency-severity vocabulary pinned by rctl-control-effectiveness-conclusion may change within months of release and must be re-checked at publication.", "Legal-date hold: the AI Act applicability dates asserted for the referenced categories (2 December 2027 and 2 August 2028) appear in SRC-012, the tier-3 republication, and in regional_assumptions; they were not verified in this audit and must be confirmed against the Official Journal text at SRC-034 before any regional projection is published.", "Independent second-provider review was explicitly waived by the repository owner; this Claude-only result remains a reviewable draft." ], "deferredResearch": [ "Emit the composition-link set the coverage checklist claims (fifteen links) or correct the count to the nine delivered boundary notes, and bind each link to the neighbour model that owns the adjacent concept, since the split decision rests on that ownership evidence.", "Define a precedence rule for the five access exceptions, specifically where unfettered reviewer access, statutory unredacted release to a competent authority, and restriction of a binding disclosing an exploitable unremediated weakness apply to the same record simultaneously.", "Assess whether the tombstone rule is safe under erasure obligations: rctl-gov-art-tombstone-record retains the master-system identifier verbatim and the digest of the disposed record, and a digest over a low-entropy record is a confirmation and re-identification vector that the export-side re-identification check does not cover.", "Specify the detection mechanism for upstream risk-revision supersession. Boundary note 1 promises the binding marks itself stale when the pinned revision is superseded, but no finding or function names how that change is detected; rctl-gov-fn-reconcile-bindings reports retired references only and rctl-gov-fn-evaluate-currency derives currency from time and fired triggers.", "Obtain licensed or institutional access to ISO 31000:2018, ISO/IEC 27001:2022, ISO/IEC 27002:2022, the full COSO ICIF-2013 text, COBIT, and Regulation (EU) 2022/2554 with its ICT risk-management regulatory technical standards, all of which are currently declared unretrievable while several are cited as support.", "Scope a projection-level accommodation for ordinal expression modes, since the model refuses implicit arithmetic while common matrix tooling multiplies and averages ordinal scores; without it, adopters will reintroduce the arithmetic the model forbids at the storage or interface layer.", "Revisit quantified residual attribution as a targeted search rather than a standing gap: determine whether any sector-specific primary source (prudential, safety-integrity or actuarial) prescribes an attributable inherent-to-residual apportionment method that could be pinned by reference without the model endorsing a computation." ] }, "statistics": { "sources": 37, "bundles": 9, "layers": 19, "findings": 39, "questions": 176, "artifacts": 16, "functions": 20 } }