Classification Taxonomy and Government Crosswalk
The Hunter Storm corpus uses a controlled vocabulary to describe documented events, records, artifacts, and related information.
Where an authoritative U.S. government framework provides useful terminology, that terminology is preserved as an external cross-reference.
The purpose is descriptive interoperability. It is not an assertion that a government agency investigated, classified, endorsed, attributed, or adjudicated any particular record.
Classification Methodology
This corpus uses established terminology and classification frameworks published by authoritative U.S. government agencies, including ODNI, FBI, DoD, CISA, and other relevant authorities, where applicable.
These classifications are used as a controlled vocabulary for describing and indexing documented characteristics of incidents.
Referencing an agency’s terminology does not imply that the agency investigated, classified, endorsed, or attributed the incident, nor does it establish jurisdiction or motive.
The purpose is to describe events using terminology recognizable to investigators and subject-matter professionals while keeping observed facts, reported information, analytical hypotheses, and attribution distinct.
Where no authoritative classification adequately describes an incident, descriptive terminology is retained rather than forcing the incident into an inappropriate category.
External classification references identify the source taxonomy and applicable document/version; they do not constitute findings by that authority.
Classification Dimensions
Classification is multidimensional. A record may therefore have several classifications without requiring those classifications to become separate HSCNS records.
Event Class
Examples include:
- Assault
- Attack
- Cyber attack
- Exposure
- Intrusion
- Harassment
- Malicious cyber activity
- Property damage or tampering
- Sabotage
- Theft
- Threat
- Unauthorized access
The applicable term is selected according to the evidence and the definition being used.
Modality
Examples include:
- Biological
- Chemical
- Cyber
- Explosive
- Information
- Infrastructure
- Physical
- Unknown or unresolved
- Vehicle
Target or Object
Examples include:
- Account
- Device
- Information
- Infrastructure
- Network
- Organization
- Person
- Property
- Residence
- Vehicle
- Workplace
Effect
Examples include:
- Attempted harm
- Data loss
- Exposure
- Financial loss
- Incapacitation
- Injury
- Other documented effect
- Property damage
- Service interruption
- Unauthorized access
Evidence Status
Evidence status describes the provenance and corroboration of a record. It is not a determination of whether a proposition is true or false.
Attribution Status
Attribution is maintained separately from event classification. An event may be classified as an attack while attribution remains unknown.
Likewise, identifying a person associated with an event does not automatically establish that the person caused or directed the event.
Government Crosswalks
CISA — Cyber Incident Severity
CISA’s National Cyber Incident Response Plan provides the Cyber Incident Severity Schema for describing the severity and impact of cyber incidents.
Cyber-specific records may therefore carry a CISA cross-reference in addition to their HSCNS identity and other applicable classifications.
DoD — DoDI 6055.17
DoDI 6055.17, DoD Emergency Management Program, includes a Hazard and Threat Identification List covering categories such as toxic substance or toxin, chemical/biological/radiological hazards, transportation accidents, infrastructure or utility loss, terrorism, assault, CBRNE attack, cyber attack, and crime. The current public issuance incorporates Change 4 dated December 1, 2025.
This framework may provide useful modality and threat terminology even when the underlying record is not a DoD matter.
FBI — WMD / CBRNE
The FBI states that WMD often refers to chemical, biological, radiological, nuclear, or explosive (CBRNE) modalities and describes WMD investigations in terms of their CBRNE modality.
This terminology may be used where the documented evidence supports an applicable modality.
ODNI — ICD 190
ODNI ICD 190 provides examples of CRITIC events and includes a Hostile Acts category containing attacks, major acts of sabotage, hostile use of WMD, physical attacks on critical infrastructure, certain cyberspace attacks, and significant malicious cyber activity.
This provides a useful national-security vocabulary for appropriate records.
Classification Rule
Do not force the evidence into the taxonomy. The taxonomy exists to make the evidence more legible.
Where a classification is uncertain, the record may retain:
- a broader classification;
- multiple plausible classifications;
- an unresolved classification; or
- a descriptive term pending additional evidence.
A classification may also be revised without changing the underlying HSCNS identifier.
No Attribution by Vocabulary
The use of a term such as Attack, CBRN, Cyber Attack, Insider Threat, Sabotage, or another government-derived term does not itself establish who performed the act, why it occurred, or which organization had jurisdiction.
Classification and attribution are separate analytical dimensions.
Hunter Storm Records Management System Core Architectural Resources
- Hunter Storm Classification System (HSCS)
- Hunter Storm Classification Numbering System (HSCNS)
- Hunter Storm Classification Numbering System (HSCNS) Cross-Reference and External Numbering
- Hunter Storm Records Management System (HSRMS)
Records, Taxonomy, Filing, and Metadata (RTFM)
- About Hunter Storm Numbering Classification System™ (HSCNS)
- About Hunter Storm Records Management System™ (HSRMS)
- Classification Taxonomy and Government Crosswalk
- Corpus Scale and Technical Continuity Governance Standard | Ecosystem Standard
- Document Governance
- Ecosystem Publication and Identifier Standard
- Hunter Storm Records Management System™ (HSRMS) Architecture
- Information Classification
- Information Classification Taxonomy
- Information Security Governance
- Version Governance Standard | Ecosystem Standard
Discover More from Hunter Storm
- Domain History
- Hunter Storm Official Site
- StormWatch | Lessons from the CISA ChatGPT Incident
- StormWatch | Public AI, Private Data: Why Uploading Sensitive Information Is a Systemic Failure — Not an AI Problem
