Conformance Profiles
Profile-specific field obligations for Core, Enterprise, Regulatory, SOC/SIEM, and AI Security Extension uses.
Domain purpose
Profile-specific field obligations for Core, Enterprise, Regulatory, SOC/SIEM, and AI Security Extension uses.
Fields, modifiers, profiles and tests
CP-01Core
Implement L0, L1, L2, L6 with 11 mandatory fields.
CP-02Enterprise
Implement Core + L3, L4 with 18 mandatory fields.
CP-03Regulatory
Implement Enterprise + L6 extended with 22 mandatory fields.
CP-04SOC/SIEM
Implement Core + STIX mapping with 14 mandatory fields.
CP-05AI Security Extension
Implement Core + L5 (security subset) with 16 mandatory fields.
Implementation use
Determine applicability using the framework scope and system context. Implementation should be proportionate to risk and supported by evidence sufficient to validate the intended outcome.
Practitioner and validation guidance
Select the least profile that satisfies the intended use, then enforce its required and prohibited fields consistently.
- Validate the applicable profile and all conditional requirements.
- Retain source evidence, analyst rationale and transformation history.
- Record uncertainty and do not infer regulatory, certification or legal outcomes.