Linked Vulnerability Id
Objective
Capture and validate the linked vulnerability id element within the Incident vs. Vulnerability layer.
UAIF requirement
The incident record should implement the canonical linked_vulnerability_id field using the defined UAIF data type, validation constraints, and conditional rules.
Business impact
Preserves the different evidentiary and workflow treatment of incidents, vulnerabilities and observations.
Validation approach
Validate linked_vulnerability_id for declared JSON type and applicable conditional rules. Then review semantic consistency against the source incident evidence and the selected conformance profile.
Expected evidence
Retain the source record or analyst input for linked_vulnerability_id, schema-validation output, transformation history, selected profile, schema version and reviewer rationale where judgement is involved.
Mapping and source
UAIF Schema Specification; UAIF Technical Specification; JSON pointer /properties/linked_vulnerability_id.
Implementation guidance
Populate linked_vulnerability_id from an identified source or documented analyst decision. Enforce the schema constraints at record creation and update, preserve the original value and provenance, and surface validation failures without silently coercing data.
Assessment considerations
Sample records across normal, boundary and invalid conditions. Confirm that linked_vulnerability_id is populated only when applicable, conditional rules are enforced, provenance is retained and downstream systems do not change its meaning or precision.
Canonical schema definition
| JSON property | linked_vulnerability_id |
|---|---|
| Required in core profile | No |
| Type | "string" |
Source: UAIF Schema Specification and UAIF Core JSON Schema.