← Back to Current Taxonomy
Under Testing & Review

Target Taxonomy v1.1

Fable 5 external review validated the taxonomy architecture and recommended vocabulary extensions to cover all 318 CRI v2.2 Diagnostic Statements. The architecture is stable — the vocabulary grows under governance.
8
Dimensions
32
Characteristics
24
Control Functions
~150
DS Unlocked
New value (v1.1) Deprecated Existing (v1.0)
Existing Dimensions
1. Control Type Single Value + Confidence Frozen
The fundamental nature of the control. Frozen at 4 values — strongest performing dimension (80% High confidence). "Directive" was rejected: the Directive/Governance boundary is unstable at 9B–32B model scale.
Preventive
253
Governance
197
Corrective
61
Detective
57
2. Evidence Role Single Value + Confidence +2 / -1
How the control produces assessable evidence. Tests covers exercises, tabletops, DR tests, and penetration testing (~35 DS). Reports covers formal communication to named recipients (~25 DS). Automates is deprecated — replaced by the Execution Mode dimension.
Enforces 290 Documents 152 Monitors 67 Implements 30 Reviews 22 Tests Reports Automates 7
Discriminator: Reports = has a named recipient (board, regulator, customer). Documents = creates or maintains an artifact.
3. Scope Multi-Value + Confidence +1
What boundary the control operates within. Third_Party is the highest-ROI single value in the analysis — unlocks all 32 EX Diagnostic Statements plus ~15 GV supply chain DS. Fixes the demonstrated failure where TPM-05.5 (Third-Party Scope Review) carried zero third-party signal.
Enterprise System_Specific Device User Privileged_Access Third_Party
4. Characteristics Multi-Value + Confidence +9 (23 → 32)
The security and governance domains the control operates in. The original 23 were developed in the access control domain (PR.AA). Fable 5 identified 6 whole SCF domains with no vocabulary. Batch A values (6) are lexically anchored and Easy for L1. Batch B values (3) require pilot validation for confusion rates.
Existing values (v1.0)
Access_Management Account_Lifecycle Alerting Asset_Management Authentication Authorization Automation Backup_Recovery Change_Management Configuration_Management Credential_Management Data_Protection Encryption Endpoint_Security Incident_Response Least_Privilege Logging Monitoring Network_Security Physical_Access Policy Review_Recertification Training_Awareness
Proprietary Methodology
Vocabulary extensions and new dimensions
available under engagement.
Contact Jones & Associates
4A. Characteristics — Extensions Multi-Value + Confidence +9
Batch A — Add immediately (Easy for L1)
Third_Party_Management ~45 DS Risk_Management ~40 DS Business_Continuity ~20 DS Secure_Development ~20 DS Audit_Assurance ~12 DS Threat_Intelligence ~10 DS
Batch B — Pilot first (Moderate for L1)
Personnel_Security ~10 DS Communications_Reporting ~10 DS Privacy ~10 DS
5. Control Functions Multi-Value + Confidence +9 (15 → 24)
The specific actions the control performs. The original 15 verbs were access-control verbs. Six of seven CRI functions needed verbs that didn't exist — forcing L1 to misclassify (e.g., SAT-03 "Training" was tagged Reviews_Compliance because Trains_Personnel wasn't available).
Existing verbs (v1.0)
Detects_Anomaly Encrypts_Data Enforces_Policy Escalates_Incident Generates_Alert Manages_Credentials Monitors_Activity Prevents_Change Provisions_Access Records_Activity Restricts_Access Reviews_Compliance Revokes_Access Validates_Configuration Verifies_Identity
Batch A — Add immediately (Easy for L1)
Assesses_Risk ~30 DS Tests_Capability ~25 DS Maintains_Inventory ~15 DS Evaluates_Third_Party ~15 DS Trains_Personnel ~12 DS Restores_Operations ~11 DS Remediates_Vulnerability ~10 DS
Batch B — Pilot first (Moderate for L1)
Notifies_Stakeholders ~10 DS Contains_Incident ~10 DS
6. Confidence Scoring Per-Value Metadata Frozen
Three levels, applied per-value. Frozen — numeric scores from 9B–32B models are noise dressed as precision.
High — clear evidence in control text Medium — implied or secondary function Low — tangential or inferred
7. Cadence Single Value + Confidence New — ~60 DS
What temporal pattern does the control operate on? DE.CM literally means continuous monitoring. A DS demanding continuous detection should not be rated as covered by an annual manual review — today the taxonomy gives the matcher no way to see that difference. Near-lexical for L1 (“annually,” “continuously,” “upon termination”).
Continuous Periodic Event_Triggered Unspecified
Unspecified is mandatory. Without it, L1 will force-fit when control text is silent about timing — producing high-confidence misfits.
8. Execution Mode Single Value + Confidence New — ~50 DS
Is the control executed by systems or people? Automation is orthogonal to evidence role — an automated control can Enforce, Monitor, or Document. This dimension corrects the Evidence Role “Automates” category error (7 controls). Expect ~60% High, ~30% Unspecified, ~10% Medium.
Automated Manual Hybrid Unspecified
Implementation sequencing:
Phase 1 — Vocabulary Extension
Add Third_Party scope, 6 Batch A characteristics, 7 Batch A function verbs, Tests evidence role. No schema change. Then re-profile ~200 controls in GOV, TPM, RSK, BCD, HRS, THR, TDA, SEA, CPL domains.
Phase 2 — New Dimensions
Cadence and Execution Mode. Each requires independent dimension-isolation validation (ACF-TAX-001) before promotion to active taxonomy.
Phase 3 — Moderate Values
Batch B characteristics and function verbs. Profile HRS, TPM, and BCD domains first, measure pairwise confusion rates, then decide.
Governing principle: The taxonomy architecture is stable. The vocabulary grows under governance. Every proposed value must pass: coverage improvement (≥5 DS), confusion rate (<15%), three-run stability (≥85%), and gold-standard agreement (≥80%).