Classification Taxonomy and Government Crosswalk

The Hunter Storm corpus uses a controlled vocabulary to describe documented events, records, artifacts, and related information.

Where an authoritative U.S. government framework provides useful terminology, that terminology is preserved as an external cross-reference.

The purpose is descriptive interoperability. It is not an assertion that a government agency investigated, classified, endorsed, attributed, or adjudicated any particular record.

 

Classification Methodology

This corpus uses established terminology and classification frameworks published by authoritative U.S. government agencies, including ODNI, FBI, DoD, CISA, and other relevant authorities, where applicable.

These classifications are used as a controlled vocabulary for describing and indexing documented characteristics of incidents.

Referencing an agency’s terminology does not imply that the agency investigated, classified, endorsed, or attributed the incident, nor does it establish jurisdiction or motive.

The purpose is to describe events using terminology recognizable to investigators and subject-matter professionals while keeping observed facts, reported information, analytical hypotheses, and attribution distinct.

Where no authoritative classification adequately describes an incident, descriptive terminology is retained rather than forcing the incident into an inappropriate category.

External classification references identify the source taxonomy and applicable document/version; they do not constitute findings by that authority.

 

Classification Dimensions

Classification is multidimensional. A record may therefore have several classifications without requiring those classifications to become separate HSCNS records.

 

Event Class

Examples include:

  • Assault
  • Attack
  • Cyber attack
  • Exposure
  • Intrusion
  • Harassment
  • Malicious cyber activity
  • Property damage or tampering
  • Sabotage
  • Theft
  • Threat
  • Unauthorized access

 

The applicable term is selected according to the evidence and the definition being used.

 

Modality

Examples include:

  • Biological
  • Chemical
  • Cyber
  • Explosive
  • Information
  • Infrastructure
  • Physical
  • Unknown or unresolved
  • Vehicle

 

Target or Object

Examples include:

  • Account
  • Device
  • Information
  • Infrastructure
  • Network
  • Organization
  • Person
  • Property
  • Residence
  • Vehicle
  • Workplace

 

Effect

Examples include:

  • Attempted harm
  • Data loss
  • Exposure
  • Financial loss
  • Incapacitation
  • Injury
  • Other documented effect
  • Property damage
  • Service interruption
  • Unauthorized access

 

Evidence Status

Evidence status describes the provenance and corroboration of a record. It is not a determination of whether a proposition is true or false.

 

Attribution Status

Attribution is maintained separately from event classification. An event may be classified as an attack while attribution remains unknown.

Likewise, identifying a person associated with an event does not automatically establish that the person caused or directed the event.

 

Government Crosswalks

 

CISA — Cyber Incident Severity

CISA’s National Cyber Incident Response Plan provides the Cyber Incident Severity Schema for describing the severity and impact of cyber incidents.

Cyber-specific records may therefore carry a CISA cross-reference in addition to their HSCNS identity and other applicable classifications.

 

DoD — DoDI 6055.17

DoDI 6055.17, DoD Emergency Management Program, includes a Hazard and Threat Identification List covering categories such as toxic substance or toxin, chemical/biological/radiological hazards, transportation accidents, infrastructure or utility loss, terrorism, assault, CBRNE attack, cyber attack, and crime. The current public issuance incorporates Change 4 dated December 1, 2025.

This framework may provide useful modality and threat terminology even when the underlying record is not a DoD matter.

 

FBI — WMD / CBRNE

The FBI states that WMD often refers to chemical, biological, radiological, nuclear, or explosive (CBRNE) modalities and describes WMD investigations in terms of their CBRNE modality.

This terminology may be used where the documented evidence supports an applicable modality.

 

ODNI — ICD 190

ODNI ICD 190 provides examples of CRITIC events and includes a Hostile Acts category containing attacks, major acts of sabotage, hostile use of WMD, physical attacks on critical infrastructure, certain cyberspace attacks, and significant malicious cyber activity.

This provides a useful national-security vocabulary for appropriate records.

 

Classification Rule

Do not force the evidence into the taxonomy. The taxonomy exists to make the evidence more legible.

Where a classification is uncertain, the record may retain:

  • a broader classification;
  • multiple plausible classifications;
  • an unresolved classification; or
  • a descriptive term pending additional evidence.

 

A classification may also be revised without changing the underlying HSCNS identifier.

 

No Attribution by Vocabulary

The use of a term such as AttackCBRN, Cyber Attack, Insider Threat, Sabotage, or another government-derived term does not itself establish who performed the act, why it occurred, or which organization had jurisdiction.

Classification and attribution are separate analytical dimensions.


Hunter Storm Records Management System Core Architectural Resources

 


Records, Taxonomy, Filing, and Metadata (RTFM)

 


Discover More from Hunter Storm