本文へ移動

Back to the overview

SV-1 Systems Interface Description

Identification of systems and system items and their interconnections

Viewpoint: Systems Viewpoint · https://mithril.fund/ontology/dm2/2.02/views#SV-1

Mithril in this model

System couple
Mithril (mithril.fund) —
kotoba-cloud-control-plane
  • site:bindsTo → kotoba-identity-authority (IDENTITY_AUTHORITY)
  • site:bindsTo → kotoba-research-authority (RESEARCH_AUTHORITY)
  • site:bindsTo → kotoba-research-authority (ORG_AUTHORITY)
  • site:bindsTo → kotoba-research-authority (FAKE_REPORT_AUTHORITY)
  • site:bindsTo → kotoba-cloud-database (DATABASE_SERVICE)
  • site:bindsTo → kotobase-authn (AUTHN_SERVICE)
  • site:serves → kotoba.cloud
  • site:serves → www.kotoba.cloud
  • site:serves → api.kotoba.cloud
  • site:serves → console.kotoba.cloud
  • site:serves → boot.kotoba.cloud
  • site:serves → docs.kotoba.cloud
  • site:serves → kyber.kotoba.cloud
  • site:serves → knowledge.kotoba.cloud
  • site:serves → data.kotoba.cloud
  • site:serves → yabai.kotoba.cloud
  • site:serves → blog.kotoba.cloud
  • site:serves → graph.kotoba.cloud
  • site:serves → support.kotoba.cloud
  • site:serves → apps.kotoba.cloud
  • and 5 more (all in the JSON-LD)
kotoba-identity-authority
  • site:serves → auth.kotoba.cloud
kotoba-research-authority —
kotoba-cloud-database —
kotobase-authn —
R2 kotobase-graph-database-production (PUBLIC_BLOCKS) —
R2 internal-security-nvd (NVD_BLOCKS, read-only allow-listed keys) —
Durable Object PqKeyRegistry (SQLite, post-quantum key registry) —
Durable Object BillingAccount (SQLite) —
EDR / XDR
  • site:answers → DE.CM-01 — Networks and network services are monitored to find potentially adverse events
  • site:answers → DE.CM-03 — Personnel activity and technology usage are monitored to find potentially adverse events
  • site:answers → DE.CM-09 — Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • site:answers → DE.AE-02 — Potentially adverse events are analyzed to better understand associated activities
  • site:answers → DE.AE-03 — Information is correlated from multiple sources
  • site:answers → DE.AE-06 — Information on adverse events is provided to authorized staff and tools
  • site:answers → DE.AE-08 — Incidents are declared when adverse events meet the defined incident criteria
  • site:answers → PR.PS-05 — Installation and execution of unauthorized software are prevented
  • site:answers → RS.AN-03 — Analysis is performed to establish what has taken place during an incident and the root cause of the incident
  • site:answers → RS.MI-01 — Incidents are contained
  • site:answers → RS.MI-02 — Incidents are eradicated
CMDB / 資産台帳
  • site:answers → ID.AM-01 — Inventories of hardware managed by the organization are maintained
  • site:answers → ID.AM-02 — Inventories of software, services, and systems managed by the organization are maintained
  • site:answers → ID.AM-03 — Representations of the organization’s authorized network communication and internal and external network data flows are maintained
  • site:answers → ID.AM-04 — Inventories of services provided by suppliers are maintained
  • site:answers → ID.AM-05 — Assets are prioritized based on classification, criticality, resources, and impact on the mission
  • site:answers → ID.AM-07 — Inventories of data and corresponding metadata for designated data types are maintained
  • site:answers → ID.AM-08 — Systems, hardware, software, services, and data are managed throughout their life cycles
  • site:answers → GV.OC-04 — Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
  • site:answers → GV.OC-05 — Outcomes, capabilities, and services that the organization depends on are understood and communicated
Email Security(フィッシング対策・報告)
  • site:answers → PR.DS-02 — The confidentiality, integrity, and availability of data-in-transit are protected
  • site:answers → DE.CM-01 — Networks and network services are monitored to find potentially adverse events
  • site:answers → DE.AE-02 — Potentially adverse events are analyzed to better understand associated activities
  • site:answers → DE.AE-06 — Information on adverse events is provided to authorized staff and tools
  • site:answers → DE.AE-08 — Incidents are declared when adverse events meet the defined incident criteria
  • site:answers → RS.MA-02 — Incident reports are triaged and validated
  • site:answers → RS.MA-03 — Incidents are categorized and prioritized
  • site:answers → RS.CO-02 — Internal and external stakeholders are notified of incidents
  • site:answers → RS.CO-03 — Information is shared with designated internal and external stakeholders
  • site:answers → ID.RA-02 — Cyber threat intelligence is received from information sharing forums and sources
  • site:answers → ID.RA-03 — Internal and external threats to the organization are identified and recorded
  • site:answers → PR.AT-01 — Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
脆弱性管理(CTEM / DAST / SAST / VM)
  • site:answers → ID.RA-01 — Vulnerabilities in assets are identified, validated, and recorded
  • site:answers → ID.RA-02 — Cyber threat intelligence is received from information sharing forums and sources
  • site:answers → ID.RA-05 — Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
  • site:answers → ID.RA-06 — Risk responses are chosen, prioritized, planned, tracked, and communicated
  • site:answers → ID.RA-08 — Processes for receiving, analyzing, and responding to vulnerability disclosures are established
  • site:answers → ID.AM-02 — Inventories of software, services, and systems managed by the organization are maintained
  • site:answers → ID.AM-08 — Systems, hardware, software, services, and data are managed throughout their life cycles
  • site:answers → PR.PS-02 — Software is maintained, replaced, and removed commensurate with risk
  • site:answers → PR.PS-06 — Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
  • site:answers → DE.CM-09 — Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
CSPM / CNAPP
  • site:answers → GV.SC-07 — The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
  • site:answers → ID.AM-02 — Inventories of software, services, and systems managed by the organization are maintained
  • site:answers → ID.RA-01 — Vulnerabilities in assets are identified, validated, and recorded
  • site:answers → ID.RA-05 — Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
  • site:answers → PR.AA-05 — Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • site:answers → PR.PS-01 — Configuration management practices are established and applied
  • site:answers → PR.IR-01 — Networks and environments are protected from unauthorized logical access and usage
  • site:answers → PR.DS-01 — The confidentiality, integrity, and availability of data-at-rest are protected
  • site:answers → PR.DS-11 — Backups of data are created, protected, maintained, and tested
ZTNA / Private Access
  • site:answers → PR.AA-01 — Identities and credentials for authorized users, services, and hardware are managed by the organization
  • site:answers → PR.AA-03 — Users, services, and hardware are authenticated
  • site:answers → PR.AA-05 — Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • site:answers → PR.IR-01 — Networks and environments are protected from unauthorized logical access and usage
UEM / MDM
  • site:answers → ID.AM-01 — Inventories of hardware managed by the organization are maintained
  • site:answers → ID.AM-02 — Inventories of software, services, and systems managed by the organization are maintained
  • site:answers → PR.PS-01 — Configuration management practices are established and applied
  • site:answers → PR.PS-02 — Software is maintained, replaced, and removed commensurate with risk
  • site:answers → PR.PS-05 — Installation and execution of unauthorized software are prevented
  • site:answers → PR.DS-01 — The confidentiality, integrity, and availability of data-at-rest are protected
  • site:answers → PR.AA-03 — Users, services, and hardware are authenticated
SIEM / SOAR
  • site:answers → PR.PS-04 — Log records are generated and made available for continuous monitoring
  • site:answers → DE.CM-01 — Networks and network services are monitored to find potentially adverse events
  • site:answers → DE.CM-03 — Personnel activity and technology usage are monitored to find potentially adverse events
  • site:answers → DE.CM-06 — External service provider activities and services are monitored to find potentially adverse events
  • site:answers → DE.CM-09 — Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • site:answers → DE.AE-02 — Potentially adverse events are analyzed to better understand associated activities
  • site:answers → DE.AE-03 — Information is correlated from multiple sources
  • site:answers → DE.AE-04 — The estimated impact and scope of adverse events are understood
  • site:answers → DE.AE-06 — Information on adverse events is provided to authorized staff and tools
  • site:answers → DE.AE-07 — Cyber threat intelligence and other contextual information are integrated into the analysis
  • site:answers → DE.AE-08 — Incidents are declared when adverse events meet the defined incident criteria
  • site:answers → RS.MA-01 — The incident response plan is executed in coordination with relevant third parties once an incident is declared
  • site:answers → RS.MA-02 — Incident reports are triaged and validated
  • site:answers → RS.MA-03 — Incidents are categorized and prioritized
  • site:answers → RS.MA-04 — Incidents are escalated or elevated as needed
  • site:answers → RS.MA-05 — The criteria for initiating incident recovery are applied
  • site:answers → RS.AN-03 — Analysis is performed to establish what has taken place during an incident and the root cause of the incident
  • site:answers → RS.AN-06 — Actions performed during an investigation are recorded, and the records’ integrity and provenance are preserved
  • site:answers → RS.AN-07 — Incident data and metadata are collected, and their integrity and provenance are preserved
  • site:answers → RS.AN-08 — An incident’s magnitude is estimated and validated
  • and 4 more (all in the JSON-LD)
GRC / 監査
  • site:answers → GV.OC-03 — Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed
  • site:answers → GV.RM-02 — Risk appetite and risk tolerance statements are established, communicated, and maintained
  • site:answers → GV.RM-06 — A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
  • site:answers → GV.RR-02 — Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
  • site:answers → GV.PO-01 — Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
  • site:answers → GV.PO-02 — Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
  • site:answers → GV.OV-01 — Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • site:answers → GV.OV-02 — The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
  • site:answers → GV.OV-03 — Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • site:answers → GV.SC-04 — Suppliers are known and prioritized by criticality
  • site:answers → GV.SC-05 — Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
  • site:answers → GV.SC-06 — Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
  • site:answers → GV.SC-07 — The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
  • site:answers → GV.SC-08 — Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
  • site:answers → GV.SC-10 — Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
  • site:answers → ID.RA-05 — Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
  • site:answers → ID.RA-06 — Risk responses are chosen, prioritized, planned, tracked, and communicated
  • site:answers → ID.RA-07 — Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
Backup / DR
  • site:answers → PR.DS-11 — Backups of data are created, protected, maintained, and tested
  • site:answers → PR.IR-03 — Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • site:answers → ID.IM-04 — Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • site:answers → RC.RP-01 — The recovery portion of the incident response plan is executed once initiated from the incident response process
  • site:answers → RC.RP-02 — Recovery actions are selected, scoped, prioritized, and performed
  • site:answers → RC.RP-03 — The integrity of backups and other restoration assets is verified before using them for restoration
  • site:answers → RC.RP-04 — Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
  • site:answers → RC.RP-05 — The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed
  • site:answers → RC.RP-06 — The end of incident recovery is declared based on criteria, and incident- related documentation is completed
  • site:answers → RC.CO-03 — Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
  • site:answers → RC.CO-04 — Public updates on incident recovery are shared using approved methods and messaging
kotoba-cloud-support —
kotoba-security-watch —

Hostnames are as the twin recorded them on 2026-09-18, before the rebrand to mithril.fund.

Concepts with Mithril instances

Concept Code Count Examples
Activity n 558
  • 契約審査ライフサイクル
  • インシデントエスカレーションライフサイクル
  • 法人設立・組織変更
  • 請求・支払ライフサイクル
  • アクセス権プロビジョニングライフサイクル
  • 入退社ライフサイクル
  • 契約書ドラフト作成
  • 法務・条項審査
  • 財務条件審査
  • CEO 契約承認
  • 契約締結
  • 契約書保管
  • and 546 more (all in the JSON-LD)
Address o 16
  • kotoba.cloud
  • www.kotoba.cloud
  • api.kotoba.cloud
  • console.kotoba.cloud
  • boot.kotoba.cloud
  • docs.kotoba.cloud
  • kyber.kotoba.cloud
  • knowledge.kotoba.cloud
  • data.kotoba.cloud
  • yabai.kotoba.cloud
  • blog.kotoba.cloud
  • graph.kotoba.cloud
  • and 4 more (all in the JSON-LD)
Country o 5
  • Australia
  • Japan
  • Ukraine
  • United Kingdom
  • United States
GeoPoliticalExtent df 2
  • European Economic Area
  • European Union
Guidance df 106
  • DE.AE-02 — Potentially adverse events are analyzed to better understand associated activities
  • DE.AE-03 — Information is correlated from multiple sources
  • DE.AE-04 — The estimated impact and scope of adverse events are understood
  • DE.AE-06 — Information on adverse events is provided to authorized staff and tools
  • DE.AE-07 — Cyber threat intelligence and other contextual information are integrated into the analysis
  • DE.AE-08 — Incidents are declared when adverse events meet the defined incident criteria
  • DE.CM-01 — Networks and network services are monitored to find potentially adverse events
  • DE.CM-02 — The physical environment is monitored to find potentially adverse events
  • DE.CM-03 — Personnel activity and technology usage are monitored to find potentially adverse events
  • DE.CM-06 — External service provider activities and services are monitored to find potentially adverse events
  • DE.CM-09 — Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • GV.OC-01 — The organizational mission is understood and informs cybersecurity risk management
  • and 94 more (all in the JSON-LD)
Information dfo 19
  • EUR-Lex — EU 官報・連合法源ポータル
  • CourtListener / RECAP — US 連邦裁判例・ドocket コーパス
  • CanLII — カナダ判例・法源コーパス
  • AustLII — オーストラリア法情報研究所 (判例・法源コーパス)
  • Canada Justice Laws Website (カナダ連邦法令ポータル)
  • NZLII — ニュージーランド法情報研究所 (判例・法源コーパス)
  • Singapore Statutes Online — シンガポール法令公式ポータル (AGC Legislation Division 運営)
  • HUDOC — 欧州人権裁判所 (ECtHR) 判例データベース
  • Singapore Law Watch — 判例・法務ポータル (Singapore Academy of Law 運営)
  • US Treasury OFAC SDN List
  • UN Security Council Consolidated List
  • EU Financial Sanctions Database
  • and 7 more (all in the JSON-LD)
Location dfo 1
  • Cloudflare global edge
Organization o 722
  • Kotoba Labs Inc.
  • cloud-kotoba (kotoba.cloud operator)
  • AWAI Network, L.L.C. (Delaware)
  • kotoba-lang (language substrate)
  • 1Password (AgileBits)
  • 42Crunch
  • ANY.RUN
  • AT&T Cybersecurity
  • AWS
  • Abnormal Security
  • Acronis
  • Akamai
  • and 710 more (all in the JSON-LD)
OrganizationType o 6
  • Mithril organization account
  • VC fund
  • Portfolio company
  • ATT&CK intrusion set
  • Historical ransomware group (Ransomwatch)
  • orgbrain reference organization
PedigreeInformation dfo 8
  • Pedigree of VC fund catalog — 8 funds each with source-url (8 primary-fetched); 6 companies with sourced rounds
  • Pedigree of Compliance standards catalog — 16 of 16 frameworks with source-url
  • Pedigree of Sanctions watchlist catalog — 9 source lists with issuing authority and URL (6 declared-2026-03, 3 primary-fetched)
  • Pedigree of Legal data catalog — 52 records each with source-url (37 primary-fetched, 15 secondary-reported)
  • Pedigree of Public security knowledge — every claim carries prov:wasDerivedFrom one of 7 archived sources (CISA, MITRE, NIST, OTRF, OTRF, joshhighet/ransomwatch, Kotoba); snapshot baguqeera6fji5y3mgsvalio2cz7ca6kxlhojidwtsuqwx6klgf3wycr2gpca, 2026-09-13T23:53:34.337Z
  • Pedigree of Enterprise digital twin — every instance cites an in-repo source (2026-09-18T00:00:00+09:00)
  • Pedigree of orgbrain reference organization — kotoba-lang/kyber@055c94b00d71, 7 files pinned by sha256
  • Pedigree of NIST CSF 2.0 catalog — 106 subcategories from NIST CSWP 29 (2024-02-26, https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf)
PersonRoleType o 12
  • owner
  • admin
  • member
  • billing
  • CEO
  • CFO
  • COO
  • CTO
  • HR Manager
  • Finance Staff
  • IT Admin
  • board
RegionOfCountry o 2
  • California
  • Delaware
Rule dfo 21
  • approve-spend
  • sign-contract
  • hire
  • fire
  • compliance
  • it-admin
  • SUPPORT_RATE_LIMIT 10/min per client address (503 by name on miss)
  • POST /v1/invoke verifies Biscuits against pinned root public key; absent key refuses every invocation by name
  • GDPR (EU 2016/679)
  • CCPA / CPRA (Cal. Civ. Code 1798)
  • FedRAMP (NIST SP 800-53 Rev.5 baseline)
  • HIPAA Security Rule (45 CFR 164 Subpart C)
  • and 9 more (all in the JSON-LD)
Standard df 9
  • ISO/IEC 27001:2022
  • SOC 2 (Type I / Type II)
  • PCI DSS 4.0
  • NIST Cybersecurity Framework 2.0
  • CIS Controls v8.1
  • ISO/IEC 27701:2019 (privacy extension)
  • CSA Cloud Controls Matrix v4
  • NIST Cybersecurity Framework 2.0
  • SCAP — 構成・脆弱性情報を交換する仕様群
System n 396
  • Mithril (mithril.fund)
  • kotoba-cloud-control-plane
  • kotoba-identity-authority
  • kotoba-research-authority
  • kotoba-cloud-database
  • kotobase-authn
  • R2 kotobase-graph-database-production (PUBLIC_BLOCKS)
  • R2 internal-security-nvd (NVD_BLOCKS, read-only allow-listed keys)
  • Durable Object PqKeyRegistry (SQLite, post-quantum key registry)
  • Durable Object BillingAccount (SQLite)
  • EDR / XDR
  • CMDB / 資産台帳
  • and 384 more (all in the JSON-LD)
SystemType o 45
  • Vulnerability Assessment / VM
  • Attack Surface Management / EASM
  • Patch Management
  • Penetration Testing / PTaaS
  • Bug Bounty / Crowdsourced Testing
  • EDR / XDR
  • NDR / Network Detection
  • SIEM / Log Analytics
  • SOAR / Orchestration
  • Threat Intelligence
  • SBOM / VEX
  • AppSec (SAST/DAST/SCA)
  • and 33 more (all in the JSON-LD)

Relations

Concept Code Count Examples
WholePartType ifo 164
  • 契約審査ライフサイクル → 契約書ドラフト作成
  • 契約審査ライフサイクル → 法務・条項審査
  • 契約審査ライフサイクル → 財務条件審査
  • 契約審査ライフサイクル → CEO 契約承認
  • 契約審査ライフサイクル → 契約締結
  • 契約審査ライフサイクル → 契約書保管
  • インシデントエスカレーションライフサイクル → インシデント検知・トリアージ
  • インシデントエスカレーションライフサイクル → 指揮本部設立・指揮官任命
  • and 156 more (all in the JSON-LD)
activityPerformedByPerformer n 54
  • COO → 契約書ドラフト作成
  • COO → 法務・条項審査
  • CFO → 財務条件審査
  • CEO → CEO 契約承認
  • CFO → 契約締結
  • COO → 契約書保管
  • IT Admin → インシデント検知・トリアージ
  • COO → 指揮本部設立・指揮官任命
  • and 46 more (all in the JSON-LD)
couple if 657
  • CTEM → VM (site:feedsFindingsTo)
  • DAST → VM (site:feedsFindingsTo)
  • SAST → VM (site:feedsFindingsTo)
  • SPECT → VM (site:feedsFindingsTo)
  • IR → DR (site:handsOffTo)
  • CTEM → Threat Intelligence (site:coversCategory)
  • CTEM → CSPM / CNAPP (site:coversCategory)
  • CTEM → Vulnerability Assessment / VM (site:coversCategory)
  • and 649 more (all in the JSON-LD)
describedBy dfo 69
  • CTEM → CTEM — /security/services/
  • DAST → DAST — /security/services/
  • SAST → SAST — /security/services/
  • SPECT → SPECT — /security/services/
  • VM → VM — /security/services/
  • GRC → GRC — /security/services/
  • IR → IR — /security/services/
  • DR → DR — /security/services/
  • and 61 more (all in the JSON-LD)
individualResourceInLocation o 3
  • Japan → cloud-kotoba (kotoba.cloud operator)
  • Delaware → AWAI Network, L.L.C. (Delaware)
  • Japan → kotoba-lang (language substrate)
personRoleTypePartOfPerformer o 12
  • Mithril organization account → owner
  • Mithril organization account → admin
  • Mithril organization account → member
  • Mithril organization account → billing
  • orgbrain reference organization → CEO
  • orgbrain reference organization → CFO
  • orgbrain reference organization → COO
  • orgbrain reference organization → CTO
  • and 4 more (all in the JSON-LD)
regionOfCountryPartOfCountry o 2
  • United States → California
  • United States → Delaware
typeInstance ifo 891
  • exposure management → continuous external attack-surface and asset inventory
  • exposure management → reachable attack-path identification
  • exposure management → asset context (public routes, dependencies, owner)
  • exposure management → exposure events fed to the VM ledger
  • dynamic testing → dynamic probing of running applications
  • dynamic testing → probing with authenticated scenarios
  • dynamic testing → runtime vulnerability detection as findings
  • static analysis → static source-code analysis
  • and 883 more (all in the JSON-LD)
Concepts without Mithril instances (187)

The model concept codes (o, n, np, s, df, dfo, if, ifo) are shown verbatim: the DoD workbook publishes no legend for them, and none is assigned here.