Mithril architecture — DoDAF 2.02
Mithril's organizations, roles, services, systems, capabilities, rules and pedigree, mapped onto the DoDAF 2.02 meta-model (DM2). For each of the 8 viewpoints and 52 models, the concepts Mithril has instances of are shown apart from those it does not.
-
26 / 173
DM2 classes in use
-
2103
Instances
-
1923
Relations
-
52 / 8
Models / viewpoints
Machine-readable (JSON-LD) · DM2 ontology
Viewpoints and models
All Viewpoint
- AV-1 Overview and Summary Information 24 / 146 concepts with Mithril instances
- AV-2 Integrated Dictionary 27 / 163 concepts with Mithril instances
Capability Viewpoint
- CV-1: Vision 18 / 137 concepts with Mithril instances
- CV-2: Capability Taxonomy 22 / 151 concepts with Mithril instances
- CV-3: Capability Phasing 35 / 245 concepts with Mithril instances
- CV-4: Capability Dependencies 29 / 176 concepts with Mithril instances
- CV-5: Capability to Organizational Development Mapping 34 / 243 concepts with Mithril instances
- CV-6: Capability to Operational Activities Mapping 23 / 150 concepts with Mithril instances
- CV-7: Capability to Services Mapping 29 / 222 concepts with Mithril instances
Data and Information Viewpoint
- DIV-1:Conceptual Data Model 11 / 93 concepts with Mithril instances
- DIV-2: Logical Data Model 15 / 105 concepts with Mithril instances
- DIV-3: Physical Data Model 22 / 119 concepts with Mithril instances
Operational Viewpoint
- OV-1: High Level Operational Concept Graphic 13 / 89 concepts with Mithril instances
- OV-2: Operational Connectivity Description 16 / 106 concepts with Mithril instances
- OV-3: Operational Resource Flow Matrix 17 / 138 concepts with Mithril instances
- OV-4: Organizational Relationships Chart 14 / 94 concepts with Mithril instances
- OV-5a: Activity Decomposition Tree 12 / 90 concepts with Mithril instances
- OV-5b: Activity Model 18 / 140 concepts with Mithril instances
- OV-6a: Operational Rules Model 22 / 207 concepts with Mithril instances
- OV-6b: State Transition Description 18 / 138 concepts with Mithril instances
- OV-6c: Event-Trace Description 18 / 136 concepts with Mithril instances
Project Viewpoint
- PV-1: Project Portfolio Relationships 19 / 149 concepts with Mithril instances
- PV-2: Project Timelines 24 / 163 concepts with Mithril instances
- PV-3: Project to Capability Mapping 21 / 159 concepts with Mithril instances
Services Viewpoint
- SvcV-1 Services Interface Description 28 / 217 concepts with Mithril instances
- SvcV-2 Services Communications Description 28 / 218 concepts with Mithril instances
- SvcV-3a Systems-Services Matrix 21 / 142 concepts with Mithril instances
- SvcV-3b Services-Services Matrix 24 / 150 concepts with Mithril instances
- SvcV-4 Services Functionality Description 21 / 113 concepts with Mithril instances
- SvcV-5 Operational Activity to Services Traceability Matrix 18 / 104 concepts with Mithril instances
- SvcV-6 Services Data Exchange Matrix 25 / 155 concepts with Mithril instances
- SvcV-7 Services Performance Parameters Matrix 23 / 143 concepts with Mithril instances
- SvcV-8 Services Evolution Description 24 / 157 concepts with Mithril instances
- SvcV-9 Services Technology and Skills Forecast 22 / 155 concepts with Mithril instances
- SvcV-10a Services Rules Model 29 / 228 concepts with Mithril instances
- SvcV-10b Services State Transition Description 25 / 150 concepts with Mithril instances
- SvcV-10c Services Event-Trace Description 24 / 147 concepts with Mithril instances
Standards Viewpoint
- Standards View-1 Standards Profile 26 / 127 concepts with Mithril instances
- Standards View-2 Standards Forecast 26 / 129 concepts with Mithril instances
Systems Viewpoint
- SV-1 Systems Interface Description 24 / 211 concepts with Mithril instances
- SV-2 Systems Communications Description 22 / 205 concepts with Mithril instances
- SV-3 Systems-Systems Matrix 15 / 125 concepts with Mithril instances
- SV-4 Systems Functionality Description 18 / 139 concepts with Mithril instances
- SV-5a Operational Activity to Systems Function Traceability Matrix 14 / 96 concepts with Mithril instances
- SV-5b Operational Activity to Systems Traceability Matrix 17 / 103 concepts with Mithril instances
- SV-6 Systems Data Exchange Matrix 19 / 140 concepts with Mithril instances
- SV-7 Systems Performance Parameters Matrix 17 / 127 concepts with Mithril instances
- SV-8 Systems Evolution Description 18 / 143 concepts with Mithril instances
- SV-9 Systems Technology and Skills Forecast 16 / 139 concepts with Mithril instances
- SV-10a Systems Rules Model 23 / 214 concepts with Mithril instances
- SV-10b Systems State Transition Description 19 / 136 concepts with Mithril instances
- SV-10c Systems Event-Trace Description 18 / 133 concepts with Mithril instances
Integrated dictionary — the site mapping
For every kind of entity Mithril has: the DM2 class, the DM2 definition that justifies it, and where the instances come from.
| Kind | DM2 class | Count | Why | Source |
|---|---|---|---|---|
| Operator |
Organization
|
1 | DM2 Organization: "A specific real-world assemblage of people and other resources organized for an on-going purpose." The named public operator of mithril.fund is one specific company, an individual — not a type. |
src/app_kotoba_cloud/profile.cljk public-operator
|
| Legal entity (twin) |
Organization
|
3 | DM2 Organization (an individual). The enterprise twin's LegalEntity / OperatorOrg records are specific legal persons, each with its own jurisdiction. |
assets/twin-catalog-src/enterprise.json entities
|
| Organization account |
Organization
|
0 | DM2 Organization (an individual): each registered org is one did:webvh organization (com-<handle>.kotoba.cloud) with members. |
src/app_kotoba_cloud/org_registry.cljk registry :organizations (the public projection)
|
| Product vendor |
Organization
|
272 | DM2 Organization (an individual): each product record names the company that provides it. |
assets/compliance-catalog-src/products.json provider (distinct)
|
| VC fund |
Organization
|
8 | DM2 Organization (an individual): each fund record is one named firm with its own source URL. |
assets/vc-catalog-src/funds.json
|
| Portfolio company |
Organization
|
6 | DM2 Organization (an individual): each record is one named company. |
assets/vc-catalog-src/companies.json
|
| Legal body |
Organization
|
37 | DM2 Organization (an individual): courts, agencies, bar associations and prosecutors are specific bodies organized for an on-going purpose. |
assets/legal-catalog-src/orgs.json
|
| Threat actor group |
Organization
|
176 | DM2 Organization (an individual): an ATT&CK intrusion set is reported as one specific group of people acting for an on-going purpose. The record is a reported association, not an attribution made here. |
assets/security-data/index.json records of class security/class/actor-group
|
| Historical ransomware group |
Organization
|
219 | DM2 Organization (an individual): each Ransomwatch record names one group. The records are historical and unconfirmed, as the catalog labels them. |
assets/security-data/index.json records of class security/class/historical-group
|
| Organization type (account) |
OrganizationType
|
1 | DM2 OrganizationType: "A type of Organization." Every Mithril organization account has the same shape (roles, did:webvh, membership VCs); that shape is the type, the registered orgs its members. |
src/app_kotoba_cloud/org_registry.cljk registry :policies
|
| Organization type (catalog) |
OrganizationType
|
4 | DM2 OrganizationType: the catalogs group organizations by kind (VC fund, portfolio company, intrusion set, historical group); each kind is a type of Organization. |
the catalog vocabularies (vc#fund, vc#company, security actor-group / historical-group)
|
| Reference organization model |
OrganizationType
|
1 | DM2 OrganizationType: orgbrain's ontology describes a kind of company (its roles, authorities, processes) that a customer's org is compared against — a type, not a particular company. |
assets/orgbrain-catalog/index.json ontology
|
| Organization role |
PersonRoleType
|
4 | DM2 PersonRoleType: "A category of person roles defined by the role or roles they share that are relevant to an architecture." owner / admin / member / billing are categories of person roles; DM2 has no plain PersonRole class, and no individual person is published. |
src/app_kotoba_cloud/org_registry.cljk registry :policies :roles
|
| Job role (orgbrain) |
PersonRoleType
|
8 | DM2 PersonRoleType: CEO, CFO, IT Admin … are categories of person roles in the reference model (with a minimum headcount), not individuals. |
assets/orgbrain-catalog/index.json ontology orgbrain/roles + the roles its tasks and delegations name
|
| Business process |
Activity
|
6 | DM2 Activity: "Work, not specific to a single organization, weapon system or individual that transforms inputs (Resources) into outputs (Resources) or changes their state." Each BPMN process is such work, defined for the reference organization. |
assets/orgbrain-catalog/index.json processes
|
| Process task |
Activity
|
39 | DM2 Activity: each BPMN task is a unit of work, part of its process. |
assets/orgbrain-catalog/index.json processes[].elements (type task)
|
| RACI task |
Activity
|
15 | DM2 Activity: each RACI task (annual budget, payroll run …) is recurring work with a responsible role. |
assets/orgbrain-catalog/index.json ontology orgbrain/tasks
|
| Attack technique |
Activity
|
498 | DM2 Activity: an ATT&CK technique is reported adversary work that changes the state of the systems it acts on; it is not specific to one group. |
assets/security-data/index.json records of class security/class/technique
|
| Authority |
Rule
|
6 | DM2 Rule: "A principle or condition that governs behavior; a prescribed guide for conduct or action." An authority (approve-spend, sign-contract …) is the condition under which a task may be done. |
assets/orgbrain-catalog/index.json ontology orgbrain/authorities
|
| Security service |
Service
|
8 | DM2 Service: "A mechanism to enable access to a set of one or more capabilities, where the access is provided using a prescribed interface and is exercised consistent with constraints and policies as specified by the service description." Each of the eight services is offered through a documented interface with stated capabilities. |
src/app_kotoba_cloud/security_services.cljk security-services
|
| Service description |
ServiceDescription
|
8 | DM2 ServiceDescription: "Information necessary to interact with the service in such terms as the service inputs, outputs, and associated semantics." Each catalog entry states the service's inputs, outputs, integration and status. |
src/app_kotoba_cloud/security_services.cljk (:summary :inputs :outputs :integration), published at /security/services/
|
| Service endpoint |
ServicePort
|
3 | DM2 ServicePort: "A part of a Performer that specifics a interaction component through which the Performer interacts with other Performers." POST /v1/security/govern | respond | recover are those interaction points. |
src/app_kotoba_cloud/security_services.cljk :integration :endpoint
|
| External service |
Service
|
2 | DM2 Service: Stripe (billing) and Cloudflare (Workers, R2, Durable Objects, custom domains) are mechanisms giving Mithril access to capabilities through prescribed interfaces. |
assets/twin-catalog-src/enterprise.json external_dependencies
|
| Capability |
Capability
|
31 | DM2 Capability: "The ability to achieve a Desired Effect under specified [performance] standards and conditions through combinations of ways and means [activities and resources] to perform a set of activities." Each service lists the abilities it provides. |
src/app_kotoba_cloud/security_services.cljk :capabilities
|
| Capability type |
CapabilityType
|
8 | DM2 CapabilityType: "Category or type of capability." Each service's :domain (exposure management, dynamic testing …) is the category its capabilities belong to. |
src/app_kotoba_cloud/security_services.cljk :domain
|
| Mithril platform |
System
|
1 | DM2 System: "A functionally, physically, and/or behaviorally related group of regularly interacting or interdependent elements." Mithril as a whole: the Workers, data stores and security products that serve mithril.fund. |
this mapping (the whole of which the twin's workers and the products are parts)
|
| Worker |
System
|
5 | DM2 System: each Cloudflare Worker is a deployed group of interacting code, bindings and routes. |
assets/twin-catalog-src/enterprise.json workers
|
| Data store |
System
|
4 | DM2 System: an R2 bucket or a Durable Object class is a group of storage elements that a Worker regularly interacts with. |
assets/twin-catalog-src/enterprise.json data_stores
|
| Security product |
System
|
10 | DM2 System: each Mithril security product (EDR, SIEM, CMDB …) is a group of engines, rules and an API that work together. |
cloud-kotoba/<product> src/kotoba_cloud/<product>/product.cljk (via security-fit/products)
|
| Market product |
System
|
374 | DM2 System: each catalogued commercial product (a scanner, an EDR suite …) is a system; the catalog records what it is, not how it performs. |
assets/compliance-catalog-src/products.json
|
| Product category |
SystemType
|
45 | DM2 SystemType: "The Powertype of System." A category such as edr-xdr is a set of systems; its members are the products filed under it. |
assets/compliance-catalog-src/categories.json
|
| Resident bot |
System
|
2 | DM2 System: a Hermes profile is a model, tools, schedule and memory working together to act for the repository (support inbox, security watch). |
hermes/profiles/<profile>/ (ADR-2609241200)
|
| Cloud agent |
System
|
0 | DM2 System: a desktop agent backed up to /v1/agents is persona, memory and model working together. The records belong to their owners and are never published, so there are no public instances. |
src/app_kotoba_cloud/agents.cljk (per-principal, private)
|
| Hostname |
Address
|
16 | DM2 Address: "The name of a location along with the location-finding scheme that allows a location to be found from the name. Examples include postal address, email address, URL, datalink address." A hostname is found through DNS. |
assets/twin-catalog-src/enterprise.json hosts (as recorded 2026-09-18, before the mithril.fund rebrand)
|
| Runtime control |
Rule
|
2 | DM2 Rule: "A principle or condition that governs behavior." A rate limit or the Biscuit root-key check governs what the edge admits. |
assets/twin-catalog-src/enterprise.json controls
|
| Standard or framework |
Standard
|
7 | DM2 Standard: "A formal agreement documenting generally accepted specifications or criteria for products, processes, procedures, policies, systems, and/or personnel." ISO/IEC 27001, SOC 2, PCI DSS, NIST CSF 2.0, CIS Controls, CSA CCM, ISO/IEC 27701. |
assets/compliance-catalog-src/frameworks.json (every kind except regulation / government-authorization)
|
| Regulation |
Rule
|
9 | DM2 Rule: a regulation (GDPR, HIPAA, DORA, APPI …) or a government authorization program (FedRAMP) is a prescribed guide for conduct issued by an authority, not a consensus standard. |
assets/compliance-catalog-src/frameworks.json (kind regulation / government-authorization)
|
| CSF 2.0 subcategory |
Guidance
|
106 | DM2 Guidance: "An authoritative statement intended to lead or steer the execution of actions." A CSF 2.0 subcategory is an outcome statement NIST publishes to steer practice; it is part of the CSF standard. |
assets/csf2-catalog/subcategories.json
|
| Legislation |
Rule
|
4 | DM2 Rule: a statute or regulation (GDPR, NIS2, APPI, PDPA) is a prescribed guide for conduct. |
assets/legal-catalog-src/corpora.json (kind legislation)
|
| Treaty |
Agreement
|
1 | DM2 Agreement: "A consent among parties regarding the terms and conditions of activities that said parties participate in." The Budapest Convention is agreed among its parties. |
assets/legal-catalog-src/corpora.json (kind treaty)
|
| Standard (legal corpus) |
Standard
|
1 | DM2 Standard: the legal corpus files NIST CSF 2.0 as a framework — a formal, generally accepted specification. |
assets/legal-catalog-src/corpora.json (kind framework)
|
| Security specification |
Standard
|
1 | DM2 Standard: SCAP is a published family of specifications for exchanging configuration and vulnerability information. |
assets/security-data/index.json records of class security/class/standard
|
| Legal corpus |
Information
|
9 | DM2 Information: "the state of a something of interest that is materialized -- in any medium or form -- and communicated or received." A legislation portal or case-law database is a body of published information, not itself a rule. |
assets/legal-catalog-src/corpora.json (kind legislation-corpus / case-law-corpus)
|
| Sanctions list |
Information
|
9 | DM2 Information: each list is a published body of designations (a CSV, XML or web page). The prohibition it carries is the issuing authority's regulation, which the catalog does not record — so the list is Information, not Rule. Aggregators (OpenSanctions) publish lists too. |
assets/sanctions-catalog-src/sanctions.json sources
|
| Audit log |
Data
|
1 | DM2 Data: "Representation of information in a formalized manner suitable for communication, interpretation, or processing by humans or by automatic means." A lab audit log is machine-readable records. |
assets/security-data/index.json records of class security/class/attack-log
|
| Threat model |
Information
|
1 | DM2 Information: an authored threat-model scenario template is information about a situation; the catalog marks it as not evidence of an attack. |
assets/security-data/index.json records of class security/class/threat-model
|
| Published dataset |
Data
|
8 | DM2 Data: each catalog Mithril publishes (JSON blocks, JSON-LD, datoms) is information formalized for processing by automatic means. |
assets/*-catalog/, assets/security-data/, assets/twin-catalog-src/, assets/orgbrain-catalog/, assets/csf2-catalog/
|
| Pedigree |
PedigreeInformation
|
8 | DM2 PedigreeInformation: "Information describing pedigree." Each dataset's provenance — the source URLs, evidence layers, fetch dates, upstream commits and file hashes it records, and prov:wasDerivedFrom on every security-data claim — is its pedigree. |
each dataset's source-url / layer / generatedAt / sources / prov:wasDerivedFrom (the PROV → DM2 bridge below)
|
| Architectural description |
ArchitecturalDescription
|
53 | DM2 ArchitecturalDescription: "Information describing an architecture such as an OV-5 Activity Model document." Each page of this architecture surface, and the JSON-LD, describes Mithril's architecture. |
/docs/architecture/ (this surface)
|
| DoDAF model |
ArchitecturalDescriptionType
|
52 | DM2 ArchitecturalDescriptionType: "The Powertype of ArchitecturalDescription." Each of the 52 official models (AV-1 … DIV-3) is a kind of architectural description; the page for it is an instance. |
assets/dm2/dm2-2.02.edn :models (official catalog)
|
| Country |
Country
|
5 | DM2 Country: "A political state or nation or its territory." |
jurisdictions named by the twin, the compliance frameworks and the sanctions lists (location-codes below)
|
| Region of a country |
RegionOfCountry
|
2 | DM2 RegionOfCountry: "A large, usually continuous segment of a political state or nation or its territory." Delaware and California. |
jurisdiction codes us-de (twin) and us-ca (frameworks)
|
| Geopolitical extent |
GeoPoliticalExtent
|
2 | DM2 GeoPoliticalExtent: "A geospatial extent whose boundaries are by declaration or agreement by political parties." The EU and the EEA are extents by agreement, not countries. |
jurisdiction codes eu / eea
|
| Logical location |
Location
|
1 | DM2 Location: "A point or extent in space that may be referred to physically or logically." The Cloudflare global edge, the twin's worker jurisdiction, is logical, not geopolitical. |
assets/twin-catalog-src/enterprise.json jurisdictions (cloudflare)
|
| Project |
Project
|
0 | DM2 Project: "A temporary endeavor undertaken to create Resources or Desired Effects." No site data records one: research requests are API calls (the request ledger), product and desktop releases are artifacts, not endeavors. No instances are claimed. |
examined: src/app_kotoba_cloud/research.cljk + requests_site.cljk, product_release.cljk, desktop_releases.cljk
|
Relations
Relations are emitted in IDEAS place order (place1 → place2); each is checked against the DM2 domain and range under the subclass closure.
| DM2 property | place1 → place2 | Count | Why |
|---|---|---|---|
capabilityOfPerformer
|
Capability → Security service | 31 | The capability a performer (the service) manifests. |
typeInstance
|
Capability type → Capability | 31 | A capability is a member of its category (IDEAS set membership). |
describedBy
|
Security service → Service description | 8 | "A tuple that asserts that Information describes a Thing." |
servicePortDescribedBy
|
Service endpoint → Service description | 3 | The endpoint is described by its service's description. |
typeInstance
|
Product category → Security product | 25 | A Mithril product is filed under the categories its product definition names. |
typeInstance
|
Product category → Market product | 374 | Each catalogued product resolves to exactly one category. |
typeInstance
|
Organization type (catalog) → VC fund | 8 | Catalog kind membership. |
typeInstance
|
Organization type (catalog) → Portfolio company | 6 | Catalog kind membership. |
typeInstance
|
Organization type (catalog) → Threat actor group | 176 | Catalog kind membership. |
typeInstance
|
Organization type (catalog) → Historical ransomware group | 219 | Catalog kind membership. |
typeInstance
|
Organization type (account) → Organization account | 0 | Each registered org is an organization account. |
typeInstance
|
DoDAF model → Architectural description | 52 | The page for a model is an instance of that model. |
personRoleTypePartOfPerformer
|
Organization type (account) → Organization role | 4 | "A wholePart between a PersonRoleType and a Performer in which it performs": every organization account has these roles. |
personRoleTypePartOfPerformer
|
Reference organization model → Job role (orgbrain) | 8 | The reference organization model is made of these roles. |
activityPerformedByPerformer
|
Job role (orgbrain) → Process task | 39 | The BPMN task's actor-role performs it. |
activityPerformedByPerformer
|
Job role (orgbrain) → RACI task | 15 | RACI Responsible roles perform the task. Accountable / Consulted / Informed have no DM2 association and are not emitted. |
WholePartType
|
Business process → Process task | 39 | place1 is the whole (the process), place2 the part (its task) — the order of every DM2 part-of association (activityPartOfCapability, facilityPartOfSite). |
ruleConstrainsActivity
|
Process task → Authority | 37 | "An overlap between a Rule and the Activities it allows": the authority a task requires. |
WholePartType
|
Mithril platform → Worker | 5 | The Workers are parts of the Mithril platform. |
WholePartType
|
Mithril platform → Data store | 4 | The data stores are parts of the Mithril platform. |
WholePartType
|
Mithril platform → Security product | 10 | The security products are parts of the Mithril platform. |
WholePartType
|
Standard or framework → CSF 2.0 subcategory | 106 | A CSF 2.0 subcategory is part of the CSF 2.0 standard. |
describedBy
|
Published dataset → Pedigree | 8 | A dataset is described by its pedigree. |
describedBy
|
Mithril platform → Architectural description | 53 | The architecture pages describe the platform. |
individualResourceInLocation
|
Country → Legal entity (twin) | 2 | "A wholePart that asserts an IndividualResourceState is in a Location": the legal entity's jurisdiction. |
individualResourceInLocation
|
Region of a country → Legal entity (twin) | 1 | The legal entity's jurisdiction (a state). |
regionOfCountryPartOfCountry
|
Country → Region of a country | 2 | Delaware and California are regions of the United States. |
site:bindsTo
|
Worker → Worker | 6 | Service binding. |
site:serves
|
Worker → Hostname | 16 | Route. |
site:storesIn
|
Worker → Data store | 4 | Storage binding. |
site:inJurisdiction
|
External service → Country | 1 | Stripe is recorded under the US. |
site:inJurisdiction
|
External service → Logical location | 1 | Cloudflare is recorded under its global edge. |
site:appliesIn
|
Standard or framework → Country | 0 | Stated jurisdiction. |
site:appliesIn
|
Regulation → Country | 5 | Stated jurisdiction. |
site:appliesIn
|
Regulation → Region of a country | 1 | Stated jurisdiction. |
site:appliesIn
|
Regulation → Geopolitical extent | 4 | Stated jurisdiction. |
site:appliesIn
|
Sanctions list → Country | 5 | Issuing jurisdiction. |
site:appliesIn
|
Sanctions list → Geopolitical extent | 1 | Issuing jurisdiction. |
site:answers
|
Security product → CSF 2.0 subcategory | 115 | The product definition's :product/csf. |
site:answers
|
Security service → CSF 2.0 subcategory | 14 | security-fit direct-controls. |
site:answers
|
Product category → CSF 2.0 subcategory | 74 | security-fit category-controls. |
site:coversCategory
|
Security service → Product category | 17 | security-fit services-categories. |
site:feedsFindingsTo
|
Security service → Security service | 4 | Findings flow into VM. |
site:handsOffTo
|
Security service → Security service | 1 | IR → DR. |
site:provides
|
Product vendor → Market product | 374 | Product provider. |
site:vcRelation
|
VC fund → Portfolio company | 11 | Sourced VC relation. |
site:vcRelation
|
VC fund → VC fund | 3 | Sourced VC relation. |
site:vcRelation
|
Portfolio company → Portfolio company | 0 | Sourced VC relation. |
site:vcRelation
|
Portfolio company → VC fund | 0 | Sourced VC relation. |
Site relations (DM2 sub-properties)
Relations DM2 2.02 has no association for are declared sub-properties of the DM2 association whose places their subject and object satisfy.
| DM2 property | DM2 super-property | Why |
|---|---|---|
site:answers
|
couple
|
A product, service or product category answers a NIST CSF 2.0 subcategory (the committed fit mapping, security-fit). |
site:appliesIn
|
couple
|
A framework, regulation or sanctions list states where it applies. |
site:bindsTo
|
couple
|
A Worker's service binding to another Worker (twin bindsTo). DM2 2.02 carries system interfaces through resource flows, which the twin does not record; the binding is a couple. |
site:coversCategory
|
couple
|
A security service covers a product category (security-fit services-categories). |
site:feedsFindingsTo
|
couple
|
An upstream service emits shared-schema findings into the VM ledger (security-services :integration :feeds). |
site:handsOffTo
|
couple
|
Incident response hands off to recovery once its criteria hold (security-services :integration :hands-off). |
site:inJurisdiction
|
couple
|
A service or rule is subject to a jurisdiction. individualResourceInLocation needs an individual (IndividualResource) in place2; a Service or Rule is a type, so the site keeps the relation as a couple. |
site:provides
|
couple
|
A vendor provides a catalogued product. DM2's resource production (activityProducesResource) needs an Activity, which the catalog does not record. |
site:serves
|
couple
|
A Worker serves a hostname (twin serves). |
site:storesIn
|
couple
|
A Worker keeps state in a data store (twin storedBy). |
site:vcRelation
|
couple
|
invested / co-invested-with / acquired-by / member-of / lineage-of between funds and companies (vc-catalog relations, each sourced). The relation name is kept on the edge. |
Vocabulary alignment
Classes of the site's JSON-LD vocabularies are declared subclasses of DM2 classes (emitted into each catalog's ontology.jsonld).
| Vocabulary class | DM2 class |
|---|---|
https://twin.kotoba.cloud/twin-data/enterprise/ontology#LegalEntity
|
Organization
|
https://twin.kotoba.cloud/twin-data/enterprise/ontology#OperatorOrg
|
Organization
|
https://twin.kotoba.cloud/twin-data/enterprise/ontology#Jurisdiction
|
Location
|
https://twin.kotoba.cloud/twin-data/enterprise/ontology#Host
|
Address
|
https://twin.kotoba.cloud/twin-data/enterprise/ontology#Worker
|
System
|
https://twin.kotoba.cloud/twin-data/enterprise/ontology#DataStore
|
System
|
https://twin.kotoba.cloud/twin-data/enterprise/ontology#ObjectStore
|
System
|
https://twin.kotoba.cloud/twin-data/enterprise/ontology#DurableObject
|
System
|
https://twin.kotoba.cloud/twin-data/enterprise/ontology#ExternalDependency
|
Service
|
https://twin.kotoba.cloud/twin-data/enterprise/ontology#Control
|
Rule
|
https://kotoba.cloud/vocab/vc#fund
|
Organization
|
https://kotoba.cloud/vocab/vc#company
|
Organization
|
https://kotoba.cloud/vocab/compliance#service-category
|
SystemType
|
https://kotoba.cloud/vocab/sanctions#list
|
Information
|
https://kotoba.cloud/vocab/law#org
|
Organization
|
https://kotoba.cloud/security-data/ontology.jsonld#actor-group
|
Organization
|
https://kotoba.cloud/security-data/ontology.jsonld#historical-group
|
Organization
|
https://kotoba.cloud/security-data/ontology.jsonld#technique
|
Activity
|
https://kotoba.cloud/security-data/ontology.jsonld#standard
|
Standard
|
https://kotoba.cloud/security-data/ontology.jsonld#attack-log
|
Data
|
https://kotoba.cloud/security-data/ontology.jsonld#threat-model
|
Information
|
Not mapped
What DM2 2.02 does not model, or cannot be mapped honestly, is left out with the reason — not approximated.
- security-data vulnerability (1,700+ KEV CVEs) — DM2 2.02 has no weakness or vulnerability concept. The nearest, Property, would assert a trait of specific product individuals that the KEV record does not state.
- sanctions designation signals (454) — A signal names a person OR an organization (211 / 243); a class-level alignment would type half of them wrongly, and DM2 has no individual-person class.
- legal corpus as a class — The class mixes legislation (Rule), a treaty (Agreement), a framework (Standard) and case-law collections (Information); records are mapped one by one by kind, the class is not aligned.
- twin ServiceBinding — It is a reified edge; the binding is emitted as the relation site:bindsTo ⊑ dm2:couple instead.
- ATT&CK uses edges (group uses technique) — The group is an individual Organization and the technique an Activity type; DM2's activityPerformedByPerformer needs a Performer (a type) in place1, and no in-model association relates an individual performer to an activity.
- RACI Accountable / Consulted / Informed — DM2 has an association for performing an activity, none for accountability, consultation or information.
- orgbrain delegations and levels — A delegation of an authority between roles, and a role's level (board / exec / manager / staff), have no DM2 association.
- individual people — Mithril publishes no individual person; organization members are private to their org.
- Project / ProjectType — No site data records a temporary endeavor (see the Project kind).
PROV → DM2 bridge
prov:wasDerivedFrom on a catalog claim (its source block), and each record's source-url, evidence layer and fetch date, are the dataset's PedigreeInformation. The JSON-LD emits it as dataset dm2:describedBy pedigree; per-claim sources stay in each catalog.
The model concept codes (o, n, np, s, df, dfo, if, ifo) are shown verbatim: the DoD workbook publishes no legend for them, and none is assigned here.