{
  "schema": "metatron.intelligence.entity.v1",
  "id": "ENT-8cf26b30-7440-4907-afd6-a36ce2493bdc",
  "kind": "governance_document",
  "subtype": "binding_directive_precedent",
  "external_identifiers": [
    {
      "scheme": "metatron_governance_namespace",
      "value": "CISA_VDP",
      "issuer_id": null,
      "canonical_uri": "https://www.cisa.gov/sites/default/files/bod-20-01.pdf",
      "source": {
        "source_id": "SRC-6099bca8bc1c77ab",
        "url": "https://www.cisa.gov/sites/default/files/bod-20-01.pdf"
      },
      "valid_from": null,
      "valid_to": null,
      "observed_at": "2026-09-03",
      "status": "observed"
    }
  ],
  "sources": [
    {
      "source_id": "SRC-6099bca8bc1c77ab",
      "url": "https://www.cisa.gov/sites/default/files/bod-20-01.pdf",
      "title": "BOD 20-01: Develop and Publish a Vulnerability Disclosure Policy",
      "publisher": "Cybersecurity and Infrastructure Security Agency"
    },
    {
      "source_id": "METATRON-GOVERNANCE-CROSSWALK-V1",
      "url": "https://intelligence.metatron.marketing/governance/crosswalk.json",
      "title": "Metatron Intelligence governance namespace registry",
      "publisher": "Metatron Intelligence"
    }
  ],
  "statements": [
    {
      "statement_id": "STM-FC3BA4A4C7974306CF9C9D1054665B26",
      "subject_id": "ENT-8cf26b30-7440-4907-afd6-a36ce2493bdc",
      "predicate": "name",
      "value_or_object_id": "BOD 20-01: Develop and Publish a Vulnerability Disclosure Policy",
      "observed_at": "2026-09-03",
      "source_id": "METATRON-GOVERNANCE-CROSSWALK-V1",
      "source_locator": "frameworks[namespace=\"CISA_VDP\"].title",
      "valid_from": null,
      "valid_to": null,
      "confidence": "editorial_synthesis",
      "status": "observed"
    },
    {
      "statement_id": "STM-BAAE98DD1C967DE683A070BDC39F15DF",
      "subject_id": "ENT-8cf26b30-7440-4907-afd6-a36ce2493bdc",
      "predicate": "version",
      "value_or_object_id": "BOD-20-01",
      "observed_at": "2026-09-03",
      "source_id": "METATRON-GOVERNANCE-CROSSWALK-V1",
      "source_locator": "frameworks[namespace=\"CISA_VDP\"].version",
      "valid_from": null,
      "valid_to": null,
      "confidence": "editorial_synthesis",
      "status": "observed"
    },
    {
      "statement_id": "STM-4446688EC7EED40953244730A6963867",
      "subject_id": "ENT-8cf26b30-7440-4907-afd6-a36ce2493bdc",
      "predicate": "publisher",
      "value_or_object_id": "Cybersecurity and Infrastructure Security Agency",
      "observed_at": "2026-09-03",
      "source_id": "METATRON-GOVERNANCE-CROSSWALK-V1",
      "source_locator": "frameworks[namespace=\"CISA_VDP\"].publisher",
      "valid_from": null,
      "valid_to": null,
      "confidence": "editorial_synthesis",
      "status": "observed"
    },
    {
      "statement_id": "STM-59D56C8B104499CA40C93DD1E27E8402",
      "subject_id": "ENT-8cf26b30-7440-4907-afd6-a36ce2493bdc",
      "predicate": "publication_date",
      "value_or_object_id": "2020-09-02",
      "observed_at": "2026-09-03",
      "source_id": "METATRON-GOVERNANCE-CROSSWALK-V1",
      "source_locator": "frameworks[namespace=\"CISA_VDP\"].date",
      "valid_from": "2020-09-02",
      "valid_to": null,
      "confidence": "editorial_synthesis",
      "status": "observed"
    },
    {
      "statement_id": "STM-ABD44A438497D9D6829BFBC5BF2ACA9E",
      "subject_id": "ENT-8cf26b30-7440-4907-afd6-a36ce2493bdc",
      "predicate": "scope",
      "value_or_object_id": "Process precedent for an authorised reporting channel, scope, expectations, tracking and coordinated remediation.",
      "observed_at": "2026-09-03",
      "source_id": "METATRON-GOVERNANCE-CROSSWALK-V1",
      "source_locator": "frameworks[namespace=\"CISA_VDP\"].scope",
      "valid_from": null,
      "valid_to": null,
      "confidence": "editorial_synthesis",
      "status": "observed"
    },
    {
      "statement_id": "STM-E857BEC5FD9CC4F70B59C000E855A562",
      "subject_id": "ENT-8cf26b30-7440-4907-afd6-a36ce2493bdc",
      "predicate": "boundary",
      "value_or_object_id": "Its binding scope is U.S. federal civilian agencies and cybersecurity vulnerabilities, not general AI intelligence contributions.",
      "observed_at": "2026-09-03",
      "source_id": "METATRON-GOVERNANCE-CROSSWALK-V1",
      "source_locator": "frameworks[namespace=\"CISA_VDP\"].boundary",
      "valid_from": null,
      "valid_to": null,
      "confidence": "editorial_synthesis",
      "status": "observed"
    }
  ],
  "current_projection": {
    "name": {
      "value": "BOD 20-01: Develop and Publish a Vulnerability Disclosure Policy",
      "statement_ids": [
        "STM-FC3BA4A4C7974306CF9C9D1054665B26"
      ],
      "selection_policy": "single_reviewed_statement"
    },
    "version": {
      "value": "BOD-20-01",
      "statement_ids": [
        "STM-BAAE98DD1C967DE683A070BDC39F15DF"
      ],
      "selection_policy": "single_reviewed_statement"
    },
    "publisher": {
      "value": "Cybersecurity and Infrastructure Security Agency",
      "statement_ids": [
        "STM-4446688EC7EED40953244730A6963867"
      ],
      "selection_policy": "single_reviewed_statement"
    },
    "publication_date": {
      "value": "2020-09-02",
      "statement_ids": [
        "STM-59D56C8B104499CA40C93DD1E27E8402"
      ],
      "selection_policy": "single_reviewed_statement"
    },
    "scope": {
      "value": "Process precedent for an authorised reporting channel, scope, expectations, tracking and coordinated remediation.",
      "statement_ids": [
        "STM-ABD44A438497D9D6829BFBC5BF2ACA9E"
      ],
      "selection_policy": "single_reviewed_statement"
    },
    "boundary": {
      "value": "Its binding scope is U.S. federal civilian agencies and cybersecurity vulnerabilities, not general AI intelligence contributions.",
      "statement_ids": [
        "STM-E857BEC5FD9CC4F70B59C000E855A562"
      ],
      "selection_policy": "single_reviewed_statement"
    },
    "current_status": "unknown"
  },
  "claims": {
    "match_rule": "exact_source_url",
    "count": 0,
    "claim_ids": []
  },
  "relations": []
}
