本文へ移動

概要に戻る

SvcV-9 Services Technology and Skills Forecast

Emerging technologies and software/hardware products that are expected to be available in a given set of time frames and that will affect future development of the architecture

ビューポイント: Services Viewpoint · https://mithril.fund/ontology/dm2/2.02/views#SvcV-9

Mithril に実例がある概念

概念 コード 件数 例
Activity o 558
  • 契約審査ライフサイクル
  • インシデントエスカレーションライフサイクル
  • 法人設立・組織変更
  • 請求・支払ライフサイクル
  • アクセス権プロビジョニングライフサイクル
  • 入退社ライフサイクル
  • 契約書ドラフト作成
  • 法務・条項審査
  • 財務条件審査
  • CEO 契約承認
  • 契約締結
  • 契約書保管
  • ほか 546 件(すべては JSON-LD に)
GeoPoliticalExtent df 2
  • European Economic Area
  • European Union
Guidance df 106
  • DE.AE-02 — Potentially adverse events are analyzed to better understand associated activities
  • DE.AE-03 — Information is correlated from multiple sources
  • DE.AE-04 — The estimated impact and scope of adverse events are understood
  • DE.AE-06 — Information on adverse events is provided to authorized staff and tools
  • DE.AE-07 — Cyber threat intelligence and other contextual information are integrated into the analysis
  • DE.AE-08 — Incidents are declared when adverse events meet the defined incident criteria
  • DE.CM-01 — Networks and network services are monitored to find potentially adverse events
  • DE.CM-02 — The physical environment is monitored to find potentially adverse events
  • DE.CM-03 — Personnel activity and technology usage are monitored to find potentially adverse events
  • DE.CM-06 — External service provider activities and services are monitored to find potentially adverse events
  • DE.CM-09 — Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • GV.OC-01 — The organizational mission is understood and informs cybersecurity risk management
  • ほか 94 件(すべては JSON-LD に)
Information dfo 19
  • EUR-Lex — EU 官報・連合法源ポータル
  • CourtListener / RECAP — US 連邦裁判例・ドocket コーパス
  • CanLII — カナダ判例・法源コーパス
  • AustLII — オーストラリア法情報研究所 (判例・法源コーパス)
  • Canada Justice Laws Website (カナダ連邦法令ポータル)
  • NZLII — ニュージーランド法情報研究所 (判例・法源コーパス)
  • Singapore Statutes Online — シンガポール法令公式ポータル (AGC Legislation Division 運営)
  • HUDOC — 欧州人権裁判所 (ECtHR) 判例データベース
  • Singapore Law Watch — 判例・法務ポータル (Singapore Academy of Law 運営)
  • US Treasury OFAC SDN List
  • UN Security Council Consolidated List
  • EU Financial Sanctions Database
  • ほか 7 件(すべては JSON-LD に)
Location dfo 1
  • Cloudflare global edge
Organization o 722
  • Kotoba Labs Inc.
  • cloud-kotoba (kotoba.cloud operator)
  • AWAI Network, L.L.C. (Delaware)
  • kotoba-lang (language substrate)
  • 1Password (AgileBits)
  • 42Crunch
  • ANY.RUN
  • AT&T Cybersecurity
  • AWS
  • Abnormal Security
  • Acronis
  • Akamai
  • ほか 710 件(すべては JSON-LD に)
OrganizationType o 6
  • Mithril organization account
  • VC fund
  • Portfolio company
  • ATT&CK intrusion set
  • Historical ransomware group (Ransomwatch)
  • orgbrain reference organization
PedigreeInformation dfo 8
  • Pedigree of VC fund catalog — 8 funds each with source-url (8 primary-fetched); 6 companies with sourced rounds
  • Pedigree of Compliance standards catalog — 16 of 16 frameworks with source-url
  • Pedigree of Sanctions watchlist catalog — 9 source lists with issuing authority and URL (6 declared-2026-03, 3 primary-fetched)
  • Pedigree of Legal data catalog — 52 records each with source-url (37 primary-fetched, 15 secondary-reported)
  • Pedigree of Public security knowledge — every claim carries prov:wasDerivedFrom one of 7 archived sources (CISA, MITRE, NIST, OTRF, OTRF, joshhighet/ransomwatch, Kotoba); snapshot baguqeera6fji5y3mgsvalio2cz7ca6kxlhojidwtsuqwx6klgf3wycr2gpca, 2026-09-13T23:53:34.337Z
  • Pedigree of Enterprise digital twin — every instance cites an in-repo source (2026-09-18T00:00:00+09:00)
  • Pedigree of orgbrain reference organization — kotoba-lang/kyber@055c94b00d71, 7 files pinned by sha256
  • Pedigree of NIST CSF 2.0 catalog — 106 subcategories from NIST CSWP 29 (2024-02-26, https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf)
PersonRoleType o 12
  • owner
  • admin
  • member
  • billing
  • CEO
  • CFO
  • COO
  • CTO
  • HR Manager
  • Finance Staff
  • IT Admin
  • board
Rule dfo 21
  • approve-spend
  • sign-contract
  • hire
  • fire
  • compliance
  • it-admin
  • SUPPORT_RATE_LIMIT 10/min per client address (503 by name on miss)
  • POST /v1/invoke verifies Biscuits against pinned root public key; absent key refuses every invocation by name
  • GDPR (EU 2016/679)
  • CCPA / CPRA (Cal. Civ. Code 1798)
  • FedRAMP (NIST SP 800-53 Rev.5 baseline)
  • HIPAA Security Rule (45 CFR 164 Subpart C)
  • ほか 9 件(すべては JSON-LD に)
Service n 10
  • CTEM
  • DAST
  • SAST
  • SPECT
  • VM
  • GRC
  • IR
  • DR
  • Stripe (live billing, AWAI account)
  • Cloudflare Workers / R2 / DO / custom domains
ServiceDescription n 8
  • CTEM — /security/services/
  • DAST — /security/services/
  • SAST — /security/services/
  • SPECT — /security/services/
  • VM — /security/services/
  • GRC — /security/services/
  • IR — /security/services/
  • DR — /security/services/
ServicePort n 3
  • POST /v1/security/govern
  • POST /v1/security/respond
  • POST /v1/security/recover
Standard df 9
  • ISO/IEC 27001:2022
  • SOC 2 (Type I / Type II)
  • PCI DSS 4.0
  • NIST Cybersecurity Framework 2.0
  • CIS Controls v8.1
  • ISO/IEC 27701:2019 (privacy extension)
  • CSA Cloud Controls Matrix v4
  • NIST Cybersecurity Framework 2.0
  • SCAP — 構成・脆弱性情報を交換する仕様群
System o 396
  • Mithril (mithril.fund)
  • kotoba-cloud-control-plane
  • kotoba-identity-authority
  • kotoba-research-authority
  • kotoba-cloud-database
  • kotobase-authn
  • R2 kotobase-graph-database-production (PUBLIC_BLOCKS)
  • R2 internal-security-nvd (NVD_BLOCKS, read-only allow-listed keys)
  • Durable Object PqKeyRegistry (SQLite, post-quantum key registry)
  • Durable Object BillingAccount (SQLite)
  • EDR / XDR
  • CMDB / 資産台帳
  • ほか 384 件(すべては JSON-LD に)
SystemType o 45
  • Vulnerability Assessment / VM
  • Attack Surface Management / EASM
  • Patch Management
  • Penetration Testing / PTaaS
  • Bug Bounty / Crowdsourced Testing
  • EDR / XDR
  • NDR / Network Detection
  • SIEM / Log Analytics
  • SOAR / Orchestration
  • Threat Intelligence
  • SBOM / VEX
  • AppSec (SAST/DAST/SCA)
  • ほか 33 件(すべては JSON-LD に)

関係

概念 コード 件数 例
WholePartType ifo 164
  • 契約審査ライフサイクル → 契約書ドラフト作成
  • 契約審査ライフサイクル → 法務・条項審査
  • 契約審査ライフサイクル → 財務条件審査
  • 契約審査ライフサイクル → CEO 契約承認
  • 契約審査ライフサイクル → 契約締結
  • 契約審査ライフサイクル → 契約書保管
  • インシデントエスカレーションライフサイクル → インシデント検知・トリアージ
  • インシデントエスカレーションライフサイクル → 指揮本部設立・指揮官任命
  • ほか 156 件(すべては JSON-LD に)
activityPerformedByPerformer o 54
  • COO → 契約書ドラフト作成
  • COO → 法務・条項審査
  • CFO → 財務条件審査
  • CEO → CEO 契約承認
  • CFO → 契約締結
  • COO → 契約書保管
  • IT Admin → インシデント検知・トリアージ
  • COO → 指揮本部設立・指揮官任命
  • ほか 46 件(すべては JSON-LD に)
couple if 657
  • CTEM → VM (site:feedsFindingsTo)
  • DAST → VM (site:feedsFindingsTo)
  • SAST → VM (site:feedsFindingsTo)
  • SPECT → VM (site:feedsFindingsTo)
  • IR → DR (site:handsOffTo)
  • CTEM → Threat Intelligence (site:coversCategory)
  • CTEM → CSPM / CNAPP (site:coversCategory)
  • CTEM → Vulnerability Assessment / VM (site:coversCategory)
  • ほか 649 件(すべては JSON-LD に)
describedBy dfo 69
  • CTEM → CTEM — /security/services/
  • DAST → DAST — /security/services/
  • SAST → SAST — /security/services/
  • SPECT → SPECT — /security/services/
  • VM → VM — /security/services/
  • GRC → GRC — /security/services/
  • IR → IR — /security/services/
  • DR → DR — /security/services/
  • ほか 61 件(すべては JSON-LD に)
servicePortDescribedBy n 3
  • POST /v1/security/govern → GRC — /security/services/
  • POST /v1/security/respond → IR — /security/services/
  • POST /v1/security/recover → DR — /security/services/
typeInstance ifo 891
  • exposure management → continuous external attack-surface and asset inventory
  • exposure management → reachable attack-path identification
  • exposure management → asset context (public routes, dependencies, owner)
  • exposure management → exposure events fed to the VM ledger
  • dynamic testing → dynamic probing of running applications
  • dynamic testing → probing with authenticated scenarios
  • dynamic testing → runtime vulnerability detection as findings
  • static analysis → static source-code analysis
  • ほか 883 件(すべては JSON-LD に)
Mithril に実例がない概念 (133)

モデルの概念コード(o・n・np・s・df・dfo・if・ifo)は DoD のワークブックに凡例が公開されていないため、そのまま表示し、意味づけはしていません。