-
Notifications
You must be signed in to change notification settings - Fork 74
Expand file tree
/
Copy pathtaxonomy.json
More file actions
184 lines (183 loc) · 6.69 KB
/
Copy pathtaxonomy.json
File metadata and controls
184 lines (183 loc) · 6.69 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
{
"schemaVersion": "1.0.0",
"domains": [
{
"id": "people",
"title": "People",
"summary": "Founders, signers, hires, and anyone who can be phished, coerced, or planted inside the team."
},
{
"id": "devices-identity",
"title": "Devices and identity",
"summary": "Endpoints, accounts, authenticators, and the credentials that unlock everything else."
},
{
"id": "development-supply-chain",
"title": "Development and supply chain",
"summary": "Source, dependencies, build systems, and the path from commit to deployed artifact."
},
{
"id": "infrastructure",
"title": "Infrastructure",
"summary": "Cloud, networks, DNS, registrars, and the admin planes that host the product."
},
{
"id": "onchain-systems",
"title": "Onchain systems",
"summary": "Contracts, upgrade paths, oracles, and other on-chain logic that moves value."
},
{
"id": "governance-treasury",
"title": "Governance and treasury",
"summary": "Multisigs, proposals, councils, and the authority to spend or change the protocol."
},
{
"id": "community-communications",
"title": "Community and communications",
"summary": "Public channels, support surfaces, and the trust people place in official messages."
},
{
"id": "detection-incident-response",
"title": "Detection and incident response",
"summary": "Monitoring, alerting, runbooks, and the people who contain a live incident."
}
],
"roles": [
{ "id": "founder-executive", "title": "Founder / executive" },
{ "id": "engineer-developer", "title": "Engineer / developer" },
{ "id": "security-engineer", "title": "Security engineer" },
{ "id": "multisig-signer", "title": "Multisig signer" },
{ "id": "infrastructure-operator", "title": "Infrastructure operator" },
{ "id": "community-manager", "title": "Community manager" },
{ "id": "incident-responder", "title": "Incident responder" },
{ "id": "governance-participant", "title": "Governance participant" }
],
"lifecycle": [
{ "id": "design", "title": "Design" },
{ "id": "development", "title": "Development" },
{ "id": "pre-launch", "title": "Pre-launch" },
{ "id": "normal-operations", "title": "Normal operations" },
{ "id": "upgrade", "title": "Upgrade" },
{ "id": "incident-response", "title": "Incident response" },
{ "id": "recovery", "title": "Recovery" }
],
"nodeTypes": [
{ "id": "asset", "title": "Asset", "prefix": "asset" },
{ "id": "component", "title": "Component", "prefix": "component" },
{ "id": "attack-surface", "title": "Attack surface", "prefix": "surface" },
{ "id": "threat", "title": "Threat", "prefix": "threat" },
{ "id": "control", "title": "Control", "prefix": "control" },
{ "id": "response", "title": "Response", "prefix": "response" },
{ "id": "guidance", "title": "Guidance", "prefix": "guidance" },
{ "id": "incident", "title": "Incident", "prefix": "incident" }
],
"edgeTypes": [
{
"id": "contains",
"title": "contains",
"direction": "source contains target",
"sources": ["asset", "component"],
"targets": ["component"]
},
{
"id": "depends-on",
"title": "depends on",
"direction": "source depends on target",
"sources": ["component"],
"targets": ["component"]
},
{
"id": "exposes",
"title": "exposes",
"direction": "source exposes target",
"sources": ["component"],
"targets": ["attack-surface"]
},
{
"id": "targets",
"title": "targets",
"direction": "source threat targets target",
"sources": ["threat"],
"targets": ["asset", "component", "attack-surface"]
},
{
"id": "mitigates",
"title": "mitigates",
"direction": "source control mitigates target threat",
"sources": ["control"],
"targets": ["threat"]
},
{
"id": "protects",
"title": "protects",
"direction": "source control protects target",
"sources": ["control"],
"targets": ["asset", "component", "attack-surface"]
},
{
"id": "detects",
"title": "detects",
"direction": "source control detects target",
"sources": ["control"],
"targets": ["threat", "attack-surface"]
},
{
"id": "responds-to",
"title": "responds to",
"direction": "source response responds to target",
"sources": ["response"],
"targets": ["threat", "incident"]
},
{
"id": "documented-by",
"title": "documented by",
"direction": "source is documented by target guidance",
"sources": ["asset", "component", "attack-surface", "threat", "control", "response", "incident"],
"targets": ["guidance"]
},
{
"id": "demonstrated-by",
"title": "demonstrated by",
"direction": "source is demonstrated by target incident",
"sources": ["threat", "attack-surface"],
"targets": ["incident"]
},
{
"id": "evaluated-by",
"title": "evaluated by",
"direction": "source is in scope for target certification guidance",
"sources": ["asset", "component", "attack-surface", "threat", "control", "response"],
"targets": ["guidance"]
},
{
"id": "related-to",
"title": "related to",
"direction": "weak symmetric link; use only when a stronger edge is wrong",
"sources": ["asset", "component", "attack-surface", "threat", "control", "response", "guidance", "incident"],
"targets": ["asset", "component", "attack-surface", "threat", "control", "response", "guidance", "incident"]
}
],
"controlClasses": [
{ "id": "preventive", "title": "Preventive" },
{ "id": "detective", "title": "Detective" },
{ "id": "corrective", "title": "Corrective" },
{ "id": "recovery", "title": "Recovery" },
{ "id": "governance", "title": "Governance" }
],
"severities": [
{ "id": "contextual", "title": "Contextual" },
{ "id": "low", "title": "Low" },
{ "id": "medium", "title": "Medium" },
{ "id": "high", "title": "High" },
{ "id": "critical", "title": "Critical" }
],
"statuses": [
{ "id": "proposed", "title": "Proposed" },
{ "id": "reviewed", "title": "Reviewed" },
{ "id": "deprecated", "title": "Deprecated" }
],
"notes": {
"rolesVsMdxTags": "Security Map roles are a graph taxonomy for filtering map nodes. They are deliberately distinct from MDX audience tags such as Engineer/Developer or Operations & Strategy. Do not treat a role id as a page tag.",
"severity": "Threat severity is a default triage hint, not a universal ranking. Every threat with a severity other than contextual must include severityBasis."
}
}