CORE v1.0 · MODULE 10

ARGUS7 / DECISION SUPPORT

Strategy

Trasformare finding, rischio, impatto, confidenza e vincoli in azioni prioritarie, alternative e rischio residuo.

INPUTSOURCEMODULE ANALYSISEVIDENCEHUMAN REVIEWOUTPUT

01 / DECISION SUPPORT

Every visual element is derived from the case dataset.

Zoom, pan, filters, selection and details expose entities, relationships, Source IDs and Evidence IDs. No automatic rotation or random data.

IMPACT →LIKELIHOOD ↑RISK CONTEXT / DEMONSTRATION

02 / DEFENSIVE GOVERNANCE

From vulnerability to remediation priority.

A traceable view of the CISA BOD 26-04 context: intelligence, exposure, known exploitation, technical impact and human accountability.

OFFICIAL DIRECTIVE CONTEXT / DEFENSIVE GOVERNANCE

CISA BOD 26-04 prioritization model

TARGET ARCHITECTURE VISUALIZATION

This ARGUS7 view illustrates how evidence can support risk-based remediation decisions. It is not a CISA implementation, a compliance determination, or a live assessment of any organization.

01VULNERABILITY INTELLIGENCEOfficial vulnerability and exploitation context
02ASSET EXPOSUREAuthorized inventory, reachability and affected versions
03KNOWN EXPLOITATIONEvidence-qualified exploitation status
04TECHNICAL IMPACTService criticality, blast radius and constraints
05PRIORITIZED REMEDIATIONOwner, deadline, dependency and residual risk
DECISION RULEEvidence before urgency

Exposure and known exploitation raise priority; they do not independently establish compromise.

CONTROL GATEHuman accountability

Every proposed action retains an owner, rationale, dependency, due date and residual-risk statement.

PROVENANCEPublic-source traceability

Directive context remains linked to the original source and implementation guidance.

03 / MODULE SPECIFICATION

Purpose, responsibility and operational boundaries.

This page preserves the names, agents, routing and dependencies of the ARGUS7 baseline.

PURPOSE

Trasformare finding, rischio, impatto, confidenza e vincoli in azioni prioritarie, alternative e rischio residuo.

TARGET ARCHITECTURE
AINPUTS

INPUTS

  • Finding
  • Risk e impact
  • Confidence breakdown
  • Vincoli e dipendenze
BPROCESS

PROCESS

  • Hypothesis generation
  • Prioritization
  • Resource allocation
  • Dependency mapping
  • Residual-risk analysis
CACTIVATED AGENTS

ACTIVATED AGENTS

  • Strategy Orchestrator
  • Hypothesis Generation
  • Investigation Plan
  • Resource Allocation
DTOOLS / SOURCES

TOOLS / SOURCES

  • Layer 9 / MCP via n8n
  • Layer 8 Memory / RAG
  • Vector Search
  • Feedback moduli
EVALIDATION / EVIDENCE

VALIDATION / EVIDENCE

  • Success e stop condition
  • Alternative
  • Impatto / costo / rischio
  • HITL su escalation
FOUTPUT

OUTPUT

  • Recommended actions
  • Priority queue
  • Decision tree
  • Residual-risk statement
CONNECTED MODULES / COMPONENTS
InvestigationsCyberIntelFraudGovernance

04 / RISK ↔ CONTROL

Adversary activity and defensive response, without operationally abusable content.

Publicly documented TTPs are described for detection, triage and mitigation. Exploits, payloads and executable offensive procedures are not published.

RISK INPUT
  • Known exploitation
  • Asset exposure
  • Technical impact
  • Constraints
DECISION OUTPUT
  • Priority
  • Owner
  • Dependency
  • Residual risk

05 / CONNECTED CASES

The module does not operate in isolation.

The same case studies traverse multiple modules, using one data model and one evidence chain.