Cyber Integrity & System Security
Vulnerabilities, threats, incidents of N4/M8 systems
Bundle → Layer → Finding → Questions Incomplete
4 bundles · 8 layers · 0 findings · 0 questions
weakness What could be exploited
vulnerabilities
known weaknesses in software and components
exposures
which concrete systems carry them and their patch state
threat Who and what attacks
actorsAndCampaigns
actors, campaigns and techniques posing risk
indicators
observable signs of compromise and their attribution
incident What actually happened
detection
declared incidents, triage and impact scoping
response
containment, recovery and closure
assurance How well defended
controls
each owner's declared control baseline
posture
periodic assessments against that baseline
Note: Legacy card: layers named, findings and questions never written.
Classifiers Filled
- Family
- World Models
- Category
- Cross-cutting context
- Entry kind
- mixin
- Navigation path
- NAV.XCT.SEC
- Domain
- XCT.SEC
- Industry
- Cross-industry
- Tags
- cyberintegrityxct.sec
- Also called
- S8
What it is Derived, awaiting review
This meta-model describes the technical health of the systems the catalogue depends on: known vulnerabilities, which live systems are exposed and how far patched, the threats and indicators observed against them, the incidents that actually occurred, and the control baselines and posture assessments that say how well defended each system is.
Note: First sentence of the legacy card introduction.
Why it exists Filled
Vulnerabilities, threats, incidents of N4/M8 systems
Distinguishing features Derived, awaiting review
- It is its own model because system security has its own registries, actors and cadence (disclosure, patching, incident response) that are orthogonal to who owns data and who may read it, yet every access guarantee in this cluster silently assumes it.
What robots and AI may and may not do Missing, in the backlog
Not described yet. This gap is in the card backlog.
Moral aspects Missing, in the backlog
Not described yet. This gap is in the card backlog.
Owners Filled
Steward
Each system owner stewards the records of their own systems: exposures, patch states, baselines and assessments.
Links to other meta-models Filled
references
- world.informationSystem - the software systems whose weaknesses, incidents and baselines this model tracks.
- world.network - network infrastructure appears as the other class of protected, registered asset.
- world.ownership - system ownership determines who patches, who declares baselines and who is notified.
- world.accessAudit - access-log anomalies feed detection, and incident timelines cite log entries as evidence.
- world.accessEnforcement - an incident that is also a violation of access contracts escalates into that model's cases.
imports
- cve - REFERENCE: the public identifier scheme for vulnerabilities.
- cwe - REFERENCE: the weakness classification scheme behind vulnerability classes.
- cvss - REFERENCE: the severity scoring vocabulary carried on vulnerabilities.
- iso-27001 - ALIGN: the control catalogue that declared baselines map to.
- oasis-stix - ALIGN: the exchange shape for threats and indicators under threat-sharing contracts.
requires
- vr.wm-obj-008
- vr.wm-pol-014
- vr.wm-sft-002
- vr.wm-xct-004
- vr.wm-xct-007
What else AI and robots need to interact with it Incomplete
Identity and identifiers required Missing, in the backlog
Not described yet. This gap is in the card backlog.
Direct properties not applicable Not applicable
Not applicable
Institutional or informational subject: no invented physical properties.
Recognition optional Missing, in the backlog
Not described yet. This gap is in the card backlog.
Capabilities and actions required Derived, awaiting review
- vulnerabilityDisclosed: a weakness became known, with or without a coordinated embargo.
- exposureIdentified: a concrete system was found to carry a known vulnerability.
- patchApplied: a remediation was applied and its verification recorded.
- threatObserved: a threat actor, campaign or technique was observed in scope.
- incidentDeclared: a security event was declared an incident and triage began.
- incidentContained: the spread of an incident was stopped; recovery began.
- incidentClosed: recovery finished and lessons were recorded.
- assessmentCompleted: a posture assessment concluded with findings.
Legacy events listed as state transitions.
Hazards and failure modes optional Missing, in the backlog
Not described yet. This gap is in the card backlog.
Standards and interfaces required Derived, awaiting review
- coordinatedDisclosure: a finder, the system owner and the CERT steward agree on an embargo and publication timeline for a new vulnerability.
- threatSharing: system owners exchange indicators and threat context under attribution and confidentiality terms.
- incidentNotification: the CERT steward, and the owners of data held on a struck system, are notified within agreed timeframes when an incident has a data-exposure flag.
- publicAdvisory: vulnerability, affected versions and fixed versions; omits which live systems remain unpatched.
- ownerRiskDashboard: exposures, patch states and posture for one owner's systems only; omits everyone else's estate.
- certSituationBoard: cross-system aggregate of exposures, threats and incidents at cohort grain; omits identifiable unpatched systems.
Context of use required Filled
- A CERT steward archetype coordinates across owners, runs disclosure embargoes and keeps the situation board; access to any owner's detail remains a grant from that owner under S1/S2, logged in S4.
Sources Missing, in the backlog
Not described yet. This gap is in the card backlog.
Open questions
- Superseded by a researched world model? Map this legacy card to its successor or retire it.
Machine files
Provenance
legacy MMAS card (world-models v0.2) · legacy
Built from: models/world-s8-cyber-integrity-and-system-security/spec.yaml, models/docs/security-ownership-access/S8-cyber-integrity-and-system-security.md