Skip to main content

Cross-Project Correlation Register

Purpose

Define which project owns each shared concept and how consistency is reviewed.

Last Checked

2026-05-16

Canonical Ownership

Shared ConceptCanonical OwnerConsuming ProjectsConsistency Rule
Evidence labelsField ManualCustomer-Driven AI CTI, Israel Threat Actors CTIUse Observed, Reported, Assessed, Inferred, Unknown, Gap.
Source reliabilityField ManualCustomer-Driven AI CTI, Israel Threat Actors CTIUse A-F source reliability and 1-6 information credibility with caveats.
Confidence languageField ManualCustomer-Driven AI CTI, Israel Threat Actors CTIConfidence reflects evidence quality, access, corroboration, and analytic consistency; it is not probability.
ATT&CK mapping rulesField ManualCustomer-Driven AI CTI, Israel Threat Actors CTIMap behavior only when evidence supports a technique; otherwise mark Gap / Not mapped.
DRL modelField ManualCustomer-Driven AI CTI, Israel Threat Actors CTIOnly DRL-9 is production coverage. Lower levels are research, hunt, pilot, or validation states.
SOC handoffField ManualCustomer-Driven AI CTIInclude first checks, required logs, false positives, escalation, response authority, feedback loop.
AI-assisted CTI controlsField ManualCustomer-Driven AI CTIAI output cannot independently create attribution, confidence, or production-readiness decisions.
Customer delivery gatesCustomer-Driven AI CTIField Manual, Israel Threat Actors CTIUse gated execution for scoped customer work.
Actor/tool/TTP/detection knowledgeIsrael Threat Actors CTIField Manual, Customer-Driven AI CTIActor-specific claims require source, evidence label, freshness date, and caveat.
Production-readiness boundaryField ManualAllDo not market research or synthetic testing as production SOC coverage.

Review Workflow

  1. When a shared concept changes, update the canonical owner first.
  2. Update consuming projects only after the owner page is stable.
  3. Add or update crosslinks from consuming pages to the owner page.
  4. Run local build and internal link validation in each changed repository.
  5. Record the last checked date in this page and the sister-project correlation page.
  6. For detection readiness changes, verify the Israel CTI detection dashboard and Customer delivery gates do not overstate maturity.

Machine-Readable Register

The YAML source for this table is stored at:

data/correlation-register.yml