# Capability-Determined Threat Model Scope

- **Artifact ID:** CHQ-ASC-2026-001
- **Version:** v1.0
- **Status:** Ratified · Canonical
- **Public record:** https://record.cybersecurityhq.com/constraints/chq-asc-2026-001
- **Machine-record SHA-256:** `fb4f4720384d4763242534f4e0c4140a36c3b4de3a4eb757405c5fab996fecbf`

## Complete structured record

```json
{
  "id": "CHQ-ASC-2026-001",
  "legacy_ids": [
    "CHQ-ACJ-2026-001"
  ],
  "title": "Capability-Determined Threat Model Scope",
  "version": "v1.0",
  "issued": "2026-02-01",
  "status": "Ratified · Canonical",
  "doctrine_class": "Authoritative Canonical Judgment",
  "precedent": [],
  "purpose": "This Anticipatory Structural Constraint establishes the governing principle for determining threat model scope across all CHQ governance artifacts.\n\nIt is not domain-specific. It applies wherever inclusion or exclusion from a threat model, control scope, or accountability boundary is contested.",
  "core_judgment": "Threat model scope is determined by capability class and failure-mode equivalence.\n\nTrust, intent, contractual assurance, organizational relationship, monitoring arrangements, operational familiarity, or historical prevalence do not exclude an actor, access path, system, or service from threat model scope where capability and failure-mode equivalence are present.",
  "derivation": [
    "Threat models exist to enumerate failure modes, not actors of convenience",
    "Failure modes arise from capability, not declared intent",
    "Intent is unobservable at design time and mutable at runtime",
    "Trust is a control input, not a classification boundary",
    "Prevalence is a lagging indicator and cannot define structural risk",
    "Contractual or organizational boundaries do not alter execution capability"
  ],
  "scope_governs": [
    "Inclusion or exclusion of actors from organizational threat models",
    "Inclusion or exclusion of access paths from control scope",
    "Classification of systems, services, or intermediaries for security governance",
    "Evaluation of detection, prevention, or response strategies based on threat coverage",
    "Any CHQ Position, analysis, or assessment that depends on threat model scope determination"
  ],
  "scope_does_not_govern": [
    "Prioritization within threat models",
    "Likelihood estimation or adversary intent modeling",
    "Resource allocation decisions",
    "Selection or implementation of specific controls"
  ],
  "relationship_to_derived": "CHQ Positions that apply this constraint to specific domains inherit its authority but do not inherit its permanence.\n\nDomain-specific applications may be revised, retired, or superseded as empirical conditions, architectures, or practices change. This constraint does not change.",
  "irreversibility_statement": "This constraint contains no retirement triggers.\n\nIt is not subject to mandatory reassessment.\n\nIt may be superseded only by a successor Anticipatory Structural Constraint that explicitly demonstrates that capability-determined scope is logically invalid as a basis for threat model inclusion, not merely inconvenient, incomplete, or operationally burdensome.",
  "boundary_of_application": [
    "Assign liability",
    "Attribute causality",
    "Prescribe controls",
    "Validate or invalidate specific products or vendors",
    "Substitute for regulatory or legal compliance requirements"
  ],
  "attestation": "This constraint reflects CHQ's position that threat model integrity depends on capability-based inclusion. Exclusion based on trust, intent, relationship, or convenience is a governance failure, not a modeling choice.",
  "pdf_hash": "29b6ebb5b45377c65ae4c3221618b09f68d10095588fe3ed55394c7c380c136a",
  "nomenclature_clarifications": [
    {
      "date": "2026-09-22",
      "description": "Legacy judgment terminology replaced with Anticipatory Structural Constraint terminology",
      "meaning_changed": false,
      "prior_hash": "d15386581a577741b0b662a89bfb28be3351ea550675831ee8815b7e00275b03",
      "new_hash": "29b6ebb5b45377c65ae4c3221618b09f68d10095588fe3ed55394c7c380c136a"
    }
  ],
  "classification_scope": "EXTERNAL_INTERPRETIVE",
  "classification_resolution": "This constraint governs interpretation of an external structural condition.",
  "lifecycle_governance": {
    "error_correction": "A clerical, citation, date, identifier, or transcription error may be corrected only by a dated erratum that identifies the prior text, corrected text, evidence for the correction, affected hash, and whether meaning changed. Meaning-changing corrections are amendments, not errata.",
    "amendment": "A constraint may be amended only by a ratified, versioned amendment that preserves the prior version, states the changed proposition and rationale, recomputes the canonical hash, and notifies registered reliance. An amendment may clarify or narrow a constraint but may not silently replace its core judgment.",
    "successor": "A constraint may be superseded only by a separately identified successor that cites the predecessor, satisfies the predecessor's stated supersession test, states the exact proposition displaced, and records the effective transition. Prior versions remain historical and ineligible for new reliance after supersession.",
    "permanence": "Permanent means no automatic expiry or retirement trigger. It does not mean immune from demonstrated error, transparent amendment, or a successor that satisfies the canonical supersession test."
  },
  "governance_amendments": [
    {
      "date": "2026-09-22",
      "effective_version": "v1.0",
      "amendment_id": "CHQ-ASC-TEMPLATE-2026-001",
      "description": "Successor and reassessment language normalized as explicit artifact-governance metadata; individual canonical supersession tests remain controlling.",
      "canonical_hash_effect": "RECOMPUTED"
    },
    {
      "date": "2026-09-22",
      "effective_version": "v1.0",
      "amendment_id": "CHQ-PRS-2026-001-AMD-003",
      "description": "Class-wide error-correction, amendment, successor, and permanence semantics ratified as non-canonical governance metadata. ASC-006's internal-adjudication classification is formally resolved without changing its canonical constraint text.",
      "canonical_hash_effect": "UNCHANGED"
    }
  ]
}
```
