本文へ移動

Mithril アーキテクチャ — DoDAF 2.02

Mithril の組織・ロール・サービス・システム・ケイパビリティ・ルール・来歴を、米国防総省のアーキテクチャフレームワーク DoDAF 2.02 のメタモデル(DM2)に対応づけて示します。8 つのビューポイントと 52 のモデルそれぞれで、Mithril に実例がある概念と、ない概念を分けて表示します。

  • 26 / 173

    使っている DM2 クラス

  • 2103

    インスタンス

  • 1923

    関係

  • 52 / 8

    モデル / ビューポイント

機械可読(JSON-LD) · DM2 オントロジー

ビューポイントとモデル

All Viewpoint

Capability Viewpoint

Data and Information Viewpoint

Operational Viewpoint

Project Viewpoint

Services Viewpoint

Standards Viewpoint

Systems Viewpoint

統合辞書 — サイトのマッピング

Mithril が持つ実体の種類ごとに、対応する DM2 クラスと、その根拠になる DM2 の定義、インスタンスの出所を示します。

種類 DM2 クラス 件数 根拠 出所
運営者 Organization 1 DM2 Organization: "A specific real-world assemblage of people and other resources organized for an on-going purpose." The named public operator of mithril.fund is one specific company, an individual — not a type. src/app_kotoba_cloud/profile.cljk public-operator
法人(twin) Organization 3 DM2 Organization (an individual). The enterprise twin's LegalEntity / OperatorOrg records are specific legal persons, each with its own jurisdiction. assets/twin-catalog-src/enterprise.json entities
組織アカウント Organization 0 DM2 Organization (an individual): each registered org is one did:webvh organization (com-<handle>.kotoba.cloud) with members. src/app_kotoba_cloud/org_registry.cljk registry :organizations (the public projection)
製品ベンダー Organization 272 DM2 Organization (an individual): each product record names the company that provides it. assets/compliance-catalog-src/products.json provider (distinct)
VC ファンド Organization 8 DM2 Organization (an individual): each fund record is one named firm with its own source URL. assets/vc-catalog-src/funds.json
投資先企業 Organization 6 DM2 Organization (an individual): each record is one named company. assets/vc-catalog-src/companies.json
法務機関 Organization 37 DM2 Organization (an individual): courts, agencies, bar associations and prosecutors are specific bodies organized for an on-going purpose. assets/legal-catalog-src/orgs.json
脅威アクター Organization 176 DM2 Organization (an individual): an ATT&CK intrusion set is reported as one specific group of people acting for an on-going purpose. The record is a reported association, not an attribution made here. assets/security-data/index.json records of class security/class/actor-group
過去のランサムウェア集団 Organization 219 DM2 Organization (an individual): each Ransomwatch record names one group. The records are historical and unconfirmed, as the catalog labels them. assets/security-data/index.json records of class security/class/historical-group
組織の種類(アカウント) OrganizationType 1 DM2 OrganizationType: "A type of Organization." Every Mithril organization account has the same shape (roles, did:webvh, membership VCs); that shape is the type, the registered orgs its members. src/app_kotoba_cloud/org_registry.cljk registry :policies
組織の種類(カタログ) OrganizationType 4 DM2 OrganizationType: the catalogs group organizations by kind (VC fund, portfolio company, intrusion set, historical group); each kind is a type of Organization. the catalog vocabularies (vc#fund, vc#company, security actor-group / historical-group)
参照組織モデル OrganizationType 1 DM2 OrganizationType: orgbrain's ontology describes a kind of company (its roles, authorities, processes) that a customer's org is compared against — a type, not a particular company. assets/orgbrain-catalog/index.json ontology
組織ロール PersonRoleType 4 DM2 PersonRoleType: "A category of person roles defined by the role or roles they share that are relevant to an architecture." owner / admin / member / billing are categories of person roles; DM2 has no plain PersonRole class, and no individual person is published. src/app_kotoba_cloud/org_registry.cljk registry :policies :roles
職務ロール(orgbrain) PersonRoleType 8 DM2 PersonRoleType: CEO, CFO, IT Admin … are categories of person roles in the reference model (with a minimum headcount), not individuals. assets/orgbrain-catalog/index.json ontology orgbrain/roles + the roles its tasks and delegations name
業務プロセス Activity 6 DM2 Activity: "Work, not specific to a single organization, weapon system or individual that transforms inputs (Resources) into outputs (Resources) or changes their state." Each BPMN process is such work, defined for the reference organization. assets/orgbrain-catalog/index.json processes
プロセスのタスク Activity 39 DM2 Activity: each BPMN task is a unit of work, part of its process. assets/orgbrain-catalog/index.json processes[].elements (type task)
RACI タスク Activity 15 DM2 Activity: each RACI task (annual budget, payroll run …) is recurring work with a responsible role. assets/orgbrain-catalog/index.json ontology orgbrain/tasks
攻撃手法 Activity 498 DM2 Activity: an ATT&CK technique is reported adversary work that changes the state of the systems it acts on; it is not specific to one group. assets/security-data/index.json records of class security/class/technique
権限 Rule 6 DM2 Rule: "A principle or condition that governs behavior; a prescribed guide for conduct or action." An authority (approve-spend, sign-contract …) is the condition under which a task may be done. assets/orgbrain-catalog/index.json ontology orgbrain/authorities
セキュリティサービス Service 8 DM2 Service: "A mechanism to enable access to a set of one or more capabilities, where the access is provided using a prescribed interface and is exercised consistent with constraints and policies as specified by the service description." Each of the eight services is offered through a documented interface with stated capabilities. src/app_kotoba_cloud/security_services.cljk security-services
サービス記述 ServiceDescription 8 DM2 ServiceDescription: "Information necessary to interact with the service in such terms as the service inputs, outputs, and associated semantics." Each catalog entry states the service's inputs, outputs, integration and status. src/app_kotoba_cloud/security_services.cljk (:summary :inputs :outputs :integration), published at /security/services/
サービスの API 窓口 ServicePort 3 DM2 ServicePort: "A part of a Performer that specifics a interaction component through which the Performer interacts with other Performers." POST /v1/security/govern | respond | recover are those interaction points. src/app_kotoba_cloud/security_services.cljk :integration :endpoint
外部サービス Service 2 DM2 Service: Stripe (billing) and Cloudflare (Workers, R2, Durable Objects, custom domains) are mechanisms giving Mithril access to capabilities through prescribed interfaces. assets/twin-catalog-src/enterprise.json external_dependencies
ケイパビリティ Capability 31 DM2 Capability: "The ability to achieve a Desired Effect under specified [performance] standards and conditions through combinations of ways and means [activities and resources] to perform a set of activities." Each service lists the abilities it provides. src/app_kotoba_cloud/security_services.cljk :capabilities
ケイパビリティの分類 CapabilityType 8 DM2 CapabilityType: "Category or type of capability." Each service's :domain (exposure management, dynamic testing …) is the category its capabilities belong to. src/app_kotoba_cloud/security_services.cljk :domain
Mithril プラットフォーム System 1 DM2 System: "A functionally, physically, and/or behaviorally related group of regularly interacting or interdependent elements." Mithril as a whole: the Workers, data stores and security products that serve mithril.fund. this mapping (the whole of which the twin's workers and the products are parts)
Worker System 5 DM2 System: each Cloudflare Worker is a deployed group of interacting code, bindings and routes. assets/twin-catalog-src/enterprise.json workers
データストア System 4 DM2 System: an R2 bucket or a Durable Object class is a group of storage elements that a Worker regularly interacts with. assets/twin-catalog-src/enterprise.json data_stores
セキュリティ製品 System 10 DM2 System: each Mithril security product (EDR, SIEM, CMDB …) is a group of engines, rules and an API that work together. cloud-kotoba/<product> src/kotoba_cloud/<product>/product.cljk (via security-fit/products)
市場の製品 System 374 DM2 System: each catalogued commercial product (a scanner, an EDR suite …) is a system; the catalog records what it is, not how it performs. assets/compliance-catalog-src/products.json
製品カテゴリ SystemType 45 DM2 SystemType: "The Powertype of System." A category such as edr-xdr is a set of systems; its members are the products filed under it. assets/compliance-catalog-src/categories.json
常駐ボット System 2 DM2 System: a Hermes profile is a model, tools, schedule and memory working together to act for the repository (support inbox, security watch). hermes/profiles/<profile>/ (ADR-2609241200)
クラウドエージェント System 0 DM2 System: a desktop agent backed up to /v1/agents is persona, memory and model working together. The records belong to their owners and are never published, so there are no public instances. src/app_kotoba_cloud/agents.cljk (per-principal, private)
ホスト名 Address 16 DM2 Address: "The name of a location along with the location-finding scheme that allows a location to be found from the name. Examples include postal address, email address, URL, datalink address." A hostname is found through DNS. assets/twin-catalog-src/enterprise.json hosts (as recorded 2026-09-18, before the mithril.fund rebrand)
実行時コントロール Rule 2 DM2 Rule: "A principle or condition that governs behavior." A rate limit or the Biscuit root-key check governs what the edge admits. assets/twin-catalog-src/enterprise.json controls
標準・フレームワーク Standard 7 DM2 Standard: "A formal agreement documenting generally accepted specifications or criteria for products, processes, procedures, policies, systems, and/or personnel." ISO/IEC 27001, SOC 2, PCI DSS, NIST CSF 2.0, CIS Controls, CSA CCM, ISO/IEC 27701. assets/compliance-catalog-src/frameworks.json (every kind except regulation / government-authorization)
規制 Rule 9 DM2 Rule: a regulation (GDPR, HIPAA, DORA, APPI …) or a government authorization program (FedRAMP) is a prescribed guide for conduct issued by an authority, not a consensus standard. assets/compliance-catalog-src/frameworks.json (kind regulation / government-authorization)
CSF 2.0 サブカテゴリ Guidance 106 DM2 Guidance: "An authoritative statement intended to lead or steer the execution of actions." A CSF 2.0 subcategory is an outcome statement NIST publishes to steer practice; it is part of the CSF standard. assets/csf2-catalog/subcategories.json
法令 Rule 4 DM2 Rule: a statute or regulation (GDPR, NIS2, APPI, PDPA) is a prescribed guide for conduct. assets/legal-catalog-src/corpora.json (kind legislation)
条約 Agreement 1 DM2 Agreement: "A consent among parties regarding the terms and conditions of activities that said parties participate in." The Budapest Convention is agreed among its parties. assets/legal-catalog-src/corpora.json (kind treaty)
法務コーパス内の標準 Standard 1 DM2 Standard: the legal corpus files NIST CSF 2.0 as a framework — a formal, generally accepted specification. assets/legal-catalog-src/corpora.json (kind framework)
セキュリティ仕様 Standard 1 DM2 Standard: SCAP is a published family of specifications for exchanging configuration and vulnerability information. assets/security-data/index.json records of class security/class/standard
法令・判例コーパス Information 9 DM2 Information: "the state of a something of interest that is materialized -- in any medium or form -- and communicated or received." A legislation portal or case-law database is a body of published information, not itself a rule. assets/legal-catalog-src/corpora.json (kind legislation-corpus / case-law-corpus)
制裁リスト Information 9 DM2 Information: each list is a published body of designations (a CSV, XML or web page). The prohibition it carries is the issuing authority's regulation, which the catalog does not record — so the list is Information, not Rule. Aggregators (OpenSanctions) publish lists too. assets/sanctions-catalog-src/sanctions.json sources
監査ログ Data 1 DM2 Data: "Representation of information in a formalized manner suitable for communication, interpretation, or processing by humans or by automatic means." A lab audit log is machine-readable records. assets/security-data/index.json records of class security/class/attack-log
脅威モデル Information 1 DM2 Information: an authored threat-model scenario template is information about a situation; the catalog marks it as not evidence of an attack. assets/security-data/index.json records of class security/class/threat-model
公開データセット Data 8 DM2 Data: each catalog Mithril publishes (JSON blocks, JSON-LD, datoms) is information formalized for processing by automatic means. assets/*-catalog/, assets/security-data/, assets/twin-catalog-src/, assets/orgbrain-catalog/, assets/csf2-catalog/
来歴情報 PedigreeInformation 8 DM2 PedigreeInformation: "Information describing pedigree." Each dataset's provenance — the source URLs, evidence layers, fetch dates, upstream commits and file hashes it records, and prov:wasDerivedFrom on every security-data claim — is its pedigree. each dataset's source-url / layer / generatedAt / sources / prov:wasDerivedFrom (the PROV → DM2 bridge below)
アーキテクチャ記述 ArchitecturalDescription 53 DM2 ArchitecturalDescription: "Information describing an architecture such as an OV-5 Activity Model document." Each page of this architecture surface, and the JSON-LD, describes Mithril's architecture. /docs/architecture/ (this surface)
DoDAF モデル ArchitecturalDescriptionType 52 DM2 ArchitecturalDescriptionType: "The Powertype of ArchitecturalDescription." Each of the 52 official models (AV-1 … DIV-3) is a kind of architectural description; the page for it is an instance. assets/dm2/dm2-2.02.edn :models (official catalog)
国 Country 5 DM2 Country: "A political state or nation or its territory." jurisdictions named by the twin, the compliance frameworks and the sanctions lists (location-codes below)
国内の地域 RegionOfCountry 2 DM2 RegionOfCountry: "A large, usually continuous segment of a political state or nation or its territory." Delaware and California. jurisdiction codes us-de (twin) and us-ca (frameworks)
政治的領域 GeoPoliticalExtent 2 DM2 GeoPoliticalExtent: "A geospatial extent whose boundaries are by declaration or agreement by political parties." The EU and the EEA are extents by agreement, not countries. jurisdiction codes eu / eea
論理的な場所 Location 1 DM2 Location: "A point or extent in space that may be referred to physically or logically." The Cloudflare global edge, the twin's worker jurisdiction, is logical, not geopolitical. assets/twin-catalog-src/enterprise.json jurisdictions (cloudflare)
プロジェクト Project 0 DM2 Project: "A temporary endeavor undertaken to create Resources or Desired Effects." No site data records one: research requests are API calls (the request ledger), product and desktop releases are artifacts, not endeavors. No instances are claimed. examined: src/app_kotoba_cloud/research.cljk + requests_site.cljk, product_release.cljk, desktop_releases.cljk

関係

関係は IDEAS の順序(place1 → place2)で出力します。定義域・値域は DM2 のものを部分クラスの閉包で検査しています。

DM2 プロパティ place1 → place2 件数 根拠
capabilityOfPerformer ケイパビリティ → セキュリティサービス 31 The capability a performer (the service) manifests.
typeInstance ケイパビリティの分類 → ケイパビリティ 31 A capability is a member of its category (IDEAS set membership).
describedBy セキュリティサービス → サービス記述 8 "A tuple that asserts that Information describes a Thing."
servicePortDescribedBy サービスの API 窓口 → サービス記述 3 The endpoint is described by its service's description.
typeInstance 製品カテゴリ → セキュリティ製品 25 A Mithril product is filed under the categories its product definition names.
typeInstance 製品カテゴリ → 市場の製品 374 Each catalogued product resolves to exactly one category.
typeInstance 組織の種類(カタログ) → VC ファンド 8 Catalog kind membership.
typeInstance 組織の種類(カタログ) → 投資先企業 6 Catalog kind membership.
typeInstance 組織の種類(カタログ) → 脅威アクター 176 Catalog kind membership.
typeInstance 組織の種類(カタログ) → 過去のランサムウェア集団 219 Catalog kind membership.
typeInstance 組織の種類(アカウント) → 組織アカウント 0 Each registered org is an organization account.
typeInstance DoDAF モデル → アーキテクチャ記述 52 The page for a model is an instance of that model.
personRoleTypePartOfPerformer 組織の種類(アカウント) → 組織ロール 4 "A wholePart between a PersonRoleType and a Performer in which it performs": every organization account has these roles.
personRoleTypePartOfPerformer 参照組織モデル → 職務ロール(orgbrain) 8 The reference organization model is made of these roles.
activityPerformedByPerformer 職務ロール(orgbrain) → プロセスのタスク 39 The BPMN task's actor-role performs it.
activityPerformedByPerformer 職務ロール(orgbrain) → RACI タスク 15 RACI Responsible roles perform the task. Accountable / Consulted / Informed have no DM2 association and are not emitted.
WholePartType 業務プロセス → プロセスのタスク 39 place1 is the whole (the process), place2 the part (its task) — the order of every DM2 part-of association (activityPartOfCapability, facilityPartOfSite).
ruleConstrainsActivity プロセスのタスク → 権限 37 "An overlap between a Rule and the Activities it allows": the authority a task requires.
WholePartType Mithril プラットフォーム → Worker 5 The Workers are parts of the Mithril platform.
WholePartType Mithril プラットフォーム → データストア 4 The data stores are parts of the Mithril platform.
WholePartType Mithril プラットフォーム → セキュリティ製品 10 The security products are parts of the Mithril platform.
WholePartType 標準・フレームワーク → CSF 2.0 サブカテゴリ 106 A CSF 2.0 subcategory is part of the CSF 2.0 standard.
describedBy 公開データセット → 来歴情報 8 A dataset is described by its pedigree.
describedBy Mithril プラットフォーム → アーキテクチャ記述 53 The architecture pages describe the platform.
individualResourceInLocation 国 → 法人(twin) 2 "A wholePart that asserts an IndividualResourceState is in a Location": the legal entity's jurisdiction.
individualResourceInLocation 国内の地域 → 法人(twin) 1 The legal entity's jurisdiction (a state).
regionOfCountryPartOfCountry 国 → 国内の地域 2 Delaware and California are regions of the United States.
site:bindsTo Worker → Worker 6 Service binding.
site:serves Worker → ホスト名 16 Route.
site:storesIn Worker → データストア 4 Storage binding.
site:inJurisdiction 外部サービス → 国 1 Stripe is recorded under the US.
site:inJurisdiction 外部サービス → 論理的な場所 1 Cloudflare is recorded under its global edge.
site:appliesIn 標準・フレームワーク → 国 0 Stated jurisdiction.
site:appliesIn 規制 → 国 5 Stated jurisdiction.
site:appliesIn 規制 → 国内の地域 1 Stated jurisdiction.
site:appliesIn 規制 → 政治的領域 4 Stated jurisdiction.
site:appliesIn 制裁リスト → 国 5 Issuing jurisdiction.
site:appliesIn 制裁リスト → 政治的領域 1 Issuing jurisdiction.
site:answers セキュリティ製品 → CSF 2.0 サブカテゴリ 115 The product definition's :product/csf.
site:answers セキュリティサービス → CSF 2.0 サブカテゴリ 14 security-fit direct-controls.
site:answers 製品カテゴリ → CSF 2.0 サブカテゴリ 74 security-fit category-controls.
site:coversCategory セキュリティサービス → 製品カテゴリ 17 security-fit services-categories.
site:feedsFindingsTo セキュリティサービス → セキュリティサービス 4 Findings flow into VM.
site:handsOffTo セキュリティサービス → セキュリティサービス 1 IR → DR.
site:provides 製品ベンダー → 市場の製品 374 Product provider.
site:vcRelation VC ファンド → 投資先企業 11 Sourced VC relation.
site:vcRelation VC ファンド → VC ファンド 3 Sourced VC relation.
site:vcRelation 投資先企業 → 投資先企業 0 Sourced VC relation.
site:vcRelation 投資先企業 → VC ファンド 0 Sourced VC relation.

サイト固有の関係(DM2 のサブプロパティ)

DM2 2.02 に対応する関連がない関係は、主語と目的語の place を満たす DM2 の関連のサブプロパティとして宣言しています。

DM2 プロパティ DM2 の上位プロパティ 根拠
site:answers couple A product, service or product category answers a NIST CSF 2.0 subcategory (the committed fit mapping, security-fit).
site:appliesIn couple A framework, regulation or sanctions list states where it applies.
site:bindsTo couple A Worker's service binding to another Worker (twin bindsTo). DM2 2.02 carries system interfaces through resource flows, which the twin does not record; the binding is a couple.
site:coversCategory couple A security service covers a product category (security-fit services-categories).
site:feedsFindingsTo couple An upstream service emits shared-schema findings into the VM ledger (security-services :integration :feeds).
site:handsOffTo couple Incident response hands off to recovery once its criteria hold (security-services :integration :hands-off).
site:inJurisdiction couple A service or rule is subject to a jurisdiction. individualResourceInLocation needs an individual (IndividualResource) in place2; a Service or Rule is a type, so the site keeps the relation as a couple.
site:provides couple A vendor provides a catalogued product. DM2's resource production (activityProducesResource) needs an Activity, which the catalog does not record.
site:serves couple A Worker serves a hostname (twin serves).
site:storesIn couple A Worker keeps state in a data store (twin storedBy).
site:vcRelation couple invested / co-invested-with / acquired-by / member-of / lineage-of between funds and companies (vc-catalog relations, each sourced). The relation name is kept on the edge.

語彙のアラインメント

サイトの JSON-LD 語彙のクラスを DM2 のクラスの部分クラスとして宣言しています(各カタログの ontology.jsonld に出力)。

語彙のクラス DM2 クラス
https://twin.kotoba.cloud/twin-data/enterprise/ontology#LegalEntity Organization
https://twin.kotoba.cloud/twin-data/enterprise/ontology#OperatorOrg Organization
https://twin.kotoba.cloud/twin-data/enterprise/ontology#Jurisdiction Location
https://twin.kotoba.cloud/twin-data/enterprise/ontology#Host Address
https://twin.kotoba.cloud/twin-data/enterprise/ontology#Worker System
https://twin.kotoba.cloud/twin-data/enterprise/ontology#DataStore System
https://twin.kotoba.cloud/twin-data/enterprise/ontology#ObjectStore System
https://twin.kotoba.cloud/twin-data/enterprise/ontology#DurableObject System
https://twin.kotoba.cloud/twin-data/enterprise/ontology#ExternalDependency Service
https://twin.kotoba.cloud/twin-data/enterprise/ontology#Control Rule
https://kotoba.cloud/vocab/vc#fund Organization
https://kotoba.cloud/vocab/vc#company Organization
https://kotoba.cloud/vocab/compliance#service-category SystemType
https://kotoba.cloud/vocab/sanctions#list Information
https://kotoba.cloud/vocab/law#org Organization
https://kotoba.cloud/security-data/ontology.jsonld#actor-group Organization
https://kotoba.cloud/security-data/ontology.jsonld#historical-group Organization
https://kotoba.cloud/security-data/ontology.jsonld#technique Activity
https://kotoba.cloud/security-data/ontology.jsonld#standard Standard
https://kotoba.cloud/security-data/ontology.jsonld#attack-log Data
https://kotoba.cloud/security-data/ontology.jsonld#threat-model Information

対応づけていないもの

DM2 2.02 にない、または正直に対応づけられないものは、近似せずに理由とともに残しています。

  • security-data vulnerability (1,700+ KEV CVEs) — DM2 2.02 has no weakness or vulnerability concept. The nearest, Property, would assert a trait of specific product individuals that the KEV record does not state.
  • sanctions designation signals (454) — A signal names a person OR an organization (211 / 243); a class-level alignment would type half of them wrongly, and DM2 has no individual-person class.
  • legal corpus as a class — The class mixes legislation (Rule), a treaty (Agreement), a framework (Standard) and case-law collections (Information); records are mapped one by one by kind, the class is not aligned.
  • twin ServiceBinding — It is a reified edge; the binding is emitted as the relation site:bindsTo ⊑ dm2:couple instead.
  • ATT&CK uses edges (group uses technique) — The group is an individual Organization and the technique an Activity type; DM2's activityPerformedByPerformer needs a Performer (a type) in place1, and no in-model association relates an individual performer to an activity.
  • RACI Accountable / Consulted / Informed — DM2 has an association for performing an activity, none for accountability, consultation or information.
  • orgbrain delegations and levels — A delegation of an authority between roles, and a role's level (board / exec / manager / staff), have no DM2 association.
  • individual people — Mithril publishes no individual person; organization members are private to their org.
  • Project / ProjectType — No site data records a temporary endeavor (see the Project kind).

PROV → DM2 の橋渡し

カタログの主張に付いた prov:wasDerivedFrom(出典ブロック)と、各レコードの source-url・証拠レイヤー・取得日は、そのデータセットの PedigreeInformation です。JSON-LD では「データセット dm2:describedBy 来歴」として出力し、主張ごとの出典は各カタログ自身に残ります。

モデルの概念コード(o・n・np・s・df・dfo・if・ifo)は DoD のワークブックに凡例が公開されていないため、そのまま表示し、意味づけはしていません。