← Back to Demo Home
Knowledge Layer

Control Profile Taxonomy

Every control in the bank's library is classified across six dimensions before assessment begins. This structured metadata is what allows the engine to reason about compatibility between controls and CRI requirements — without keyword matching.
568
Controls Profiled
6
Dimensions
3
DS Assessed
318
DS in CRI v2.2
High confidence Medium confidence Low confidence
1. Control Type Single Value + Confidence
The fundamental nature of the control — does it prevent, detect, correct, or govern?
Preventive
253
Governance
197
Corrective
61
Detective
57
Confidence Distribution
High 454 Medium 66 Low 48
2. Evidence Role Single Value + Confidence
How the control produces assessable evidence — the verb that describes its operational behavior.
Enforces
290
Documents
152
Monitors
67
Implements
30
Reviews
22
Automates
7
Confidence Distribution
High 411 Medium 64 Low 93
3. Scope Multi-Value + Confidence
What boundary the control operates within. A single control can span multiple scopes — each scored independently.
Enterprise Device User Privileged_Access System_Specific
4. Characteristics Multi-Value + Confidence
The security domain the control operates in. Most controls have a primary characteristic (High) and a secondary (Medium) — reflecting that real controls rarely belong to a single domain.
Access_Management Account_Lifecycle Asset_Management Backup_Recovery Configuration_Management Credential_Management Data_Protection Encryption Endpoint_Security Logging Monitoring Network_Security Physical_Access Policy Review_Recertification Training_Awareness Vulnerability_Management
5. Control Functions Multi-Value + Confidence
The specific actions the control performs. This is the most granular dimension — it describes what the control actually does, not what category it belongs to.
Detects_Anomaly Encrypts_Data Enforces_Policy Generates_Alert Manages_Credentials Monitors_Activity Prevents_Change Provisions_Access Records_Activity Restricts_Access Reviews_Compliance Revokes_Access Validates_Configuration Verifies_Identity
6. Confidence Scoring Per-Value Metadata
Every multi-value classification carries its own confidence score. The L1 model doesn't just say "this is an access control" — it says "Access_Management: High, Network_Security: Medium." This enables the compatibility engine to weight matches appropriately during assessment.
High — clear evidence in control text Medium — implied or secondary function Low — tangential or inferred
Why this matters: The taxonomy is the intellectual property. Models are interchangeable — when ornith-9b failed on 24 controls, gemma4:12b rescued all 24 with zero changes to the taxonomy, specification, or prompt. The knowledge layer is permanent. Model selection is operational.
Scale of work remaining: 568 controls are profiled. The CRI v2.2 Profile contains 318 Diagnostic Statements. Each DS may require the taxonomy to expand — new Characteristics, new Control Functions, new Scope values that emerge from domains the current vocabulary doesn't cover. The taxonomy grows with each assessment.
Under Review
Target Taxonomy v1.1
8 dimensions, 32 characteristics, 24 control functions — expanded vocabulary validated by Fable 5 external review for full 318 DS coverage