{
  "$schema": "https://cyclonedx.org/schema/bom-1.7.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.7",
  "serialNumber": "urn:uuid:56ddde38-9750-45dd-87db-31d791439f7b",
  "version": 1,
  "metadata": {
    "timestamp": "2026-07-11T00:00:00Z",
    "authors": [
      {
        "name": "Hypermedia Au Security Team"
      }
    ],
    "component": {
      "type": "data",
      "name": "Case Provenance BOM Specification",
      "version": "1.0.0"
    },
    "properties": [
      {
        "name": "cyberbench:artifact-kind",
        "value": "BOM (L1 — the case catalog / custody ledger)"
      },
      {
        "name": "cyberbench:layer",
        "value": "L1"
      },
      {
        "name": "cyberbench:fullname",
        "value": "Case Provenance BOM (versioned, sealed catalog; frozen vN = case-of-record)"
      }
    ]
  },
  "definitions": {
    "standards": [
      {
        "bom-ref": "case-provenance-v1.0.0",
        "name": "Hypermedia Security: Case Provenance BOM Specification",
        "version": "1.0.0",
        "description": "The L1 Case Provenance BOM: the signed, versioned catalog of everything in a case — the spine every other object hangs off. One document per case, born at the ingest-seal (version 1), re-issued and re-signed at every seal, frozen at the finalisation-seal as the portable case-of-record. It enumerates every artifact entry, mirrors derivation lineage, pins the custody chain, and is the resolution target for finding input references and publication catalog pins. ISO/IEC 27043 frames chain-of-custody preservation as a concurrent process running from incident detection until the last process; this document is where that process's record is catalogued and sealed.",
        "owner": "Hypermedia Au",
        "externalReferences": [
          {
            "type": "other",
            "url": "https://sec.hypermedia.au/schemas/case-provenance/v1.schema.json",
            "comment": "The BOM schema documents conforming to this standard validate against.",
            "properties": [
              {
                "name": "cyberbench:role",
                "value": "schema-url"
              }
            ]
          },
          {
            "type": "other",
            "url": "https://sec.hypermedia.au/standards/custody-chain/v1",
            "comment": "claim target",
            "properties": [
              {
                "name": "cyberbench:role",
                "value": "referenced-from"
              }
            ]
          },
          {
            "type": "other",
            "url": "https://sec.hypermedia.au/standards/analysis-provenance/v1",
            "comment": "inputRefs (SPEC-9)",
            "properties": [
              {
                "name": "cyberbench:role",
                "value": "referenced-from"
              }
            ]
          },
          {
            "type": "other",
            "url": "https://sec.hypermedia.au/standards/publication/v1",
            "comment": "finalisedCatalogRef (SPEC-12)",
            "properties": [
              {
                "name": "cyberbench:role",
                "value": "referenced-from"
              }
            ]
          },
          {
            "type": "other",
            "url": "https://sec.hypermedia.au/standards/case-catalog/v1",
            "comment": "SPEC-7 claim target",
            "properties": [
              {
                "name": "cyberbench:role",
                "value": "referenced-from"
              }
            ]
          },
          {
            "type": "documentation",
            "url": "https://cyclonedx.org/schema/bom-1.7.schema.json",
            "comment": "CycloneDX 1.7 schema — the signature property is an 'Enveloped signature in JSON Signature Format (JSF)'; dependencies[].ref 'references a component or service by its bom-ref attribute' and dependsOn lists 'the bom-ref identifiers of the components or services that are dependencies of this dependency object'"
          },
          {
            "type": "documentation",
            "url": "https://ecma-international.org/publications-and-standards/standards/ecma-424/",
            "comment": "ECMA-424 2nd edition (December 2025) — the CycloneDX 1.7 BOM specification"
          },
          {
            "type": "documentation",
            "url": "https://www.iso.org/standard/44407.html",
            "comment": "ISO/IEC 27043:2015 — verified against the standard text 2026-07-11: §11.5 Preserving chain of custody (a concurrent process performed from incident detection until the last process); §11.1 (concurrent processes run throughout to assure admissibility); §11.4 (endorses trusted PKI and time stamping to identify investigators and authenticate evidence); §3.6 (the definition of digital investigation embeds maintaining the chain of custody); §12 (custody preservation begins with real evidence handling). 27043's Clause 3 sources its evidence vocabulary from ISO/IEC 27037:2012 — the record-content detail cited by custody-chain/v1"
          },
          {
            "type": "documentation",
            "url": "https://www.rfc-editor.org/rfc/rfc2119",
            "comment": "RFC 2119 (as clarified by RFC 8174) — requirement key words; only capitalised forms are normative"
          },
          {
            "type": "website",
            "url": "https://sec.hypermedia.au"
          }
        ],
        "requirements": [
          {
            "bom-ref": "cyclonedx-document",
            "identifier": "CPRV-001",
            "title": "CycloneDX Document",
            "text": "A Case Provenance BOM MUST be a CycloneDX 1.7 BOM with bomFormat 'CycloneDX', specVersion '1.7', a urn:uuid serialNumber stable across all versions of the case, a positive integer version, metadata.timestamp (ISO-8601) and metadata.component naming the catalog.",
            "descriptions": [
              "The serialNumber is the case catalog's permanent identity: BOM-Links from every other object (urn:cdx:<serialNumber>/<version>#<bom-ref>) resolve against it. It never changes across seals; only the version advances."
            ],
            "parent": "case-provenance-v1.0.0",
            "properties": [
              {
                "name": "requirement-uri",
                "value": "https://sec.hypermedia.au/standards/case-provenance/v1#cyclonedx-document"
              },
              {
                "name": "validation-method",
                "value": "schema"
              }
            ]
          },
          {
            "bom-ref": "versioned-per-seal",
            "identifier": "CPRV-002",
            "title": "Versioned Per Seal",
            "text": "The version MUST increase by exactly one at every seal and MUST NOT change between seals. cyberbench:sealType MUST be exactly one of: ingest, interim, finalisation (closed set). Version 1 MUST be produced by the ingest-seal. Between seals the document MUST NOT be re-signed or altered — custody events append to the ledger without touching the catalog.",
            "descriptions": [
              "Seals are checkpoints that snapshot-and-sign whatever state exists, not the moments objects are created. The publication-seal defined in the case taxonomy signs a Publication (L3), not a catalog version — which is why it is not a value here."
            ],
            "parent": "case-provenance-v1.0.0",
            "properties": [
              {
                "name": "requirement-uri",
                "value": "https://sec.hypermedia.au/standards/case-provenance/v1#versioned-per-seal"
              },
              {
                "name": "validation-method",
                "value": "schema"
              },
              {
                "name": "allowed-seal-types",
                "value": "ingest,interim,finalisation"
              },
              {
                "name": "vocabulary",
                "value": "closed"
              }
            ]
          },
          {
            "bom-ref": "component-enumeration",
            "identifier": "CPRV-003",
            "title": "Component Enumeration",
            "text": "components[] MUST enumerate every artifact entry in the case corpus at the moment of the seal — every piece of evidence and every derived artifact, each conforming to artifact-entry/v1. Nothing in the corpus may be absent from the sealed catalog.",
            "descriptions": [
              "The catalog is the complete signed index: the seal binds every hash, which is why individual entries carry no signatures of their own. Completeness at seal is independently attested by the case-catalog/v1 attestation."
            ],
            "parent": "case-provenance-v1.0.0",
            "properties": [
              {
                "name": "requirement-uri",
                "value": "https://sec.hypermedia.au/standards/case-provenance/v1#component-enumeration"
              },
              {
                "name": "validation-method",
                "value": "schema + corpus-comparison"
              },
              {
                "name": "component-standard",
                "value": "https://sec.hypermedia.au/standards/artifact-entry/v1"
              }
            ]
          },
          {
            "bom-ref": "lineage-dependencies",
            "identifier": "CPRV-004",
            "title": "Lineage Dependencies",
            "text": "dependencies[] SHOULD mirror every derivation edge in the corpus: for each derived artifact, an entry whose ref is the derived entry's bom-ref and whose dependsOn lists its source evidence bom-ref, matching the entry's own cyberbench:sourceEvidenceRef.",
            "descriptions": [
              "CycloneDX's dependency graph (ref → dependsOn, both by bom-ref) is the document-level mirror of the per-entry lineage property — one fact, readable from either end, expressing the W3C PROV derivation in native CycloneDX."
            ],
            "parent": "case-provenance-v1.0.0",
            "properties": [
              {
                "name": "requirement-uri",
                "value": "https://sec.hypermedia.au/standards/case-provenance/v1#lineage-dependencies"
              },
              {
                "name": "validation-method",
                "value": "cross-reference"
              }
            ]
          },
          {
            "bom-ref": "custody-pin",
            "identifier": "CPRV-005",
            "title": "Custody Pin",
            "text": "cyberbench:custodyChainRef MUST be present in every version and MUST resolve (BOM-Link + paired hash) to a custody-chain/v1 attestation whose claim targets this catalog.",
            "descriptions": [
              "ISO/IEC 27043 §11.5 defines preserving the chain of custody as a concurrent process performed from incident detection until the last process, and §3.6 writes maintaining the chain of custody into the very definition of a digital investigation — which is why this pin is a MUST on every version, not a finalisation nicety. The custody record's field-level contents are governed by custody-chain/v1 (whose sources sit in ISO/IEC 27037 §6.1, the acquisitive-stage standard 27043's own vocabulary builds on)."
            ],
            "parent": "case-provenance-v1.0.0",
            "properties": [
              {
                "name": "requirement-uri",
                "value": "https://sec.hypermedia.au/standards/case-provenance/v1#custody-pin"
              },
              {
                "name": "validation-method",
                "value": "cross-reference"
              },
              {
                "name": "target-standard",
                "value": "https://sec.hypermedia.au/standards/custody-chain/v1"
              },
              {
                "name": "iso-basis",
                "value": "ISO/IEC 27043 §11.5 + §3.6 (concurrent process, definition-level custody)"
              }
            ]
          },
          {
            "bom-ref": "sidecar-refs",
            "identifier": "CPRV-006",
            "title": "Sidecar References",
            "text": "The seal token reference (cyberbench:sealTsaTokenRef, every seal) and the Evidence Record reference (cyberbench:evidenceRecordRef, finalisation) MUST be recorded in the sidecar index keyed by this document's serialNumber and version, and MUST NOT appear as properties inside the sealed document. A verifier MUST treat their presence inside a sealed catalog as a broken seal.",
            "descriptions": [
              "Both artifacts are created after the seal signature and cover it — the token proves the signature's moment, and the Evidence Record's leaves include the signed document itself. Writing either reference into the document would require editing it after signing (breaking the seal) or a hash cycle (each containing the other's digest). The references are locators with no evidential weight: verification starts at the Evidence Record and the token and works inward — they prove the catalog, never the reverse."
            ],
            "parent": "case-provenance-v1.0.0",
            "properties": [
              {
                "name": "requirement-uri",
                "value": "https://sec.hypermedia.au/standards/case-provenance/v1#sidecar-refs"
              },
              {
                "name": "validation-method",
                "value": "schema + sidecar-join"
              },
              {
                "name": "sidecar-index",
                "value": "Timestamps/index.json, keyed serialNumber/version (timestamp-token/v1 #sidecar-index)"
              },
              {
                "name": "decision",
                "value": "owner 2026-07-11 — DECISION-evidence-record-referencing, Option A"
              }
            ]
          },
          {
            "bom-ref": "transparency-ref",
            "identifier": "CPRV-007",
            "title": "Transparency Reference",
            "text": "cyberbench:transparencyReceiptRef MUST be present and MUST be empty in the sovereign default. It MUST be populated only when a cross-org TransparencyLog implementation is wired, per transparency-receipt/v1.",
            "descriptions": [
              "The field existing empty is the seam: enabling cross-org transparency changes configuration and fills a field — it never changes the document shape. A verifier under the sovereign profile treats the empty value as correct, not as missing (transparency-receipt/v1 #sovereign-default-absence)."
            ],
            "parent": "case-provenance-v1.0.0",
            "properties": [
              {
                "name": "requirement-uri",
                "value": "https://sec.hypermedia.au/standards/case-provenance/v1#transparency-ref"
              },
              {
                "name": "validation-method",
                "value": "schema + profile-conditional"
              },
              {
                "name": "target-standard",
                "value": "https://sec.hypermedia.au/standards/transparency-receipt/v1"
              }
            ]
          },
          {
            "bom-ref": "seal-signature",
            "identifier": "CPRV-008",
            "title": "Seal Signature",
            "text": "Every sealed version MUST carry an enveloped JSF signature (ES256, Fulcio keyless) over the document, and metadata.authors[] MUST match the identity in the signing certificate. Every seal signature MUST be covered by that seal's RFC 3161 token proving it was created within the ephemeral certificate's validity window (timestamp-token/v1 #cert-window-proof).",
            "descriptions": [
              "CycloneDX 1.7 defines the signature property as an enveloped signature in JSON Signature Format (JSF) — the seal is native to the document format, not a wrapper. The identity-plus-external-time pairing is what ISO/IEC 27043 §11.4 itself points at: trusted PKI and time stamping to identify the different investigators and authenticate evidence. Identity comparisons are made between Fulcio-verified identities, never name strings."
            ],
            "parent": "case-provenance-v1.0.0",
            "properties": [
              {
                "name": "requirement-uri",
                "value": "https://sec.hypermedia.au/standards/case-provenance/v1#seal-signature"
              },
              {
                "name": "validation-method",
                "value": "cryptographic-signature"
              },
              {
                "name": "iso-basis",
                "value": "ISO/IEC 27043 §11.4 (trusted PKI + time stamping endorsement)"
              }
            ]
          },
          {
            "bom-ref": "frozen-at-finalisation",
            "identifier": "CPRV-009",
            "title": "Frozen At Finalisation",
            "text": "The finalisation-seal produces the final version: the corpus closes, the Evidence Record is built over it, and no further catalog version may be issued for the case. References into any version remain valid forever and MUST NOT be rewritten as versions advance: the version in a BOM-Link only locates; the paired contentHash proves the bytes. An object citing the catalog MUST cite the version current at its own creation time.",
            "descriptions": [
              "Reference survival is why continuous work and versioned sealing coexist: a finding promoted while the catalog stood at version 2 cites …/2#evidence-001, and that reference still proves the same bytes when the catalog freezes at version N, because evidence is immutable and the hash never changes. The frozen final version is the portable case-of-record the Publication pins."
            ],
            "parent": "case-provenance-v1.0.0",
            "properties": [
              {
                "name": "requirement-uri",
                "value": "https://sec.hypermedia.au/standards/case-provenance/v1#frozen-at-finalisation"
              },
              {
                "name": "validation-method",
                "value": "chain-verification"
              },
              {
                "name": "citation-convention",
                "value": "cite the version current at creation time; never rewrite"
              }
            ]
          },
          {
            "bom-ref": "case-identity",
            "identifier": "CPRV-010",
            "title": "Case Identity",
            "text": "cyberbench:caseId MUST be present and identical across all versions. cyberbench:corpusSize SHOULD state the component count at seal. cyberbench:rslHead MAY carry the gittuf Reference State Log head commit at seal time, only where gittuf is enabled.",
            "descriptions": [
              "caseId is the human/case-management join; serialNumber is the cryptographic one. corpusSize is a cheap self-consistency check a verifier can test against components[].length before doing any hashing."
            ],
            "parent": "case-provenance-v1.0.0",
            "properties": [
              {
                "name": "requirement-uri",
                "value": "https://sec.hypermedia.au/standards/case-provenance/v1#case-identity"
              },
              {
                "name": "validation-method",
                "value": "schema"
              }
            ]
          }
        ]
      }
    ]
  }
}
