Knowledge Base Graph

CIAO COMMONS — FOUNDATIONAL DESCRIPTOR
C-AO/STD/KBG/001:2026 PUBLIC
Knowledge Base Graph
How the CIAO Standard structures knowledge across Information Assurance — Class B Foundational
Date Issued  21 June 2026
Review Date  21 June 2027
Cite as: CIAO Standard. (2026). Knowledge Base Graph. v1.1.3.7. C-AO/STD/KBG/001:2026. www.c-ao.com

1. Purpose & Authority

This descriptor sets out how the CIAO Standard organises knowledge. It is the conceptual companion to two existing foundational instruments: the Source Standards Register (which records what the Standard recognises and references) and the Standard Architecture (which sets out how the Standard’s content is structured into documents and tiers). Where those describe the catalogue and the document architecture, this descriptor describes the structure of meaning — the way concepts and control objectives relate to one another and locate themselves within the Standard.

It carries Class B — Foundational authority. It defines a frame; it does not restate the architecture or the register, which it references.

2. How the Standard sees knowledge

The CIAO Standard treats Information Assurance as a body of knowledge that can be structured as a layered graph. At the widest level sits the subject itself; beneath it, the Standard’s domains; within each domain, a conceptual frame that fixes scope and terminology; and beneath the frame, the concepts and control objectives that the domain governs — drawn from many recognised sources and harmonised into a single coherent view, so that where many sources converge on one objective, the member sees one statement, not many.

This is the organising idea behind the whole Standard: a member should meet one coherent body of knowledge, not a pile of overlapping documents.

3. The layers of the knowledge structure

Layer 0 — Subject. The widest frame is a field of knowledge. The Standard addresses one named subject: Information Assurance. Other fields of knowledge exist; the Standard does not enumerate them — it situates Information Assurance as its subject and builds downward from there.

Layer 1 — Domains. Information Assurance resolves into the Standard’s content domains — nine coherent areas of the subject, held together by a meta-domain that governs the Standard itself. Each domain is a distinct region of the knowledge graph.

Layer 2 — Domain conceptual frame. Within each domain, a foundational frame defines scope, terminology, and core concepts — the lens through which every other artefact in that domain is interpreted. In the content architecture, this is the Manual level: the foundational reference document for the domain, which sets the conceptual frame against which all other artefacts within the domain are interpreted.

Layer 3 — Sub-policies. Within a domain’s frame sit its sub-policies — a bounded set of policy areas. This is the layer a member governs directly: a small, coherent set per domain rather than a sprawling library.

Layer 4 — Control objectives. Beneath each sub-policy sit the harmonised control objectives the domain governs — drawn from many recognised sources and shown here in anonymised, illustrative form. This is the layer at which a recognised source that names a required policy resolves to a single objective. Where multiple sources converge, the graph carries one node with many connections; where a single source adds a genuine exception, that remains a distinct, visible node. The implementation controls that satisfy each objective sit one level deeper again.

Deeper layers. Finer artefacts and the detailed relationships between objectives are developed progressively and surfaced through the Standard’s content tiers. This descriptor establishes the frame; depth follows the tier ladder.

4. One structure, four mirrors

The knowledge structure is not a separate invention — it mirrors the structures the Standard already uses. But the mirrors are coupled on two axes, not one: each layer is first glimpsed a tier early and becomes a member’s full set at its home tier, while within any single document the same structure unfolds in greater depth as membership rises. Breadth and depth advance together — a member always sees a little further than they have yet climbed.

Knowledge layer Becomes, in the content Framework lens Full set unlocked at Organisational maturity
Subject — Information The Standard as a whole Commons (free, registered) Awareness
Domains — nine, held by a meta-domain A Manual per domain (the management-system frame) IMS-OPF Core Foundational
Sub-policies — a bounded set per domain The policy (the document a member governs) OPF Essential Defined & repeatable
Sub-sub-policies — harmonised control objectives In-page within each policy; indexed at Professional OPF Professional Measurable & scalable
Granular objectives — beneath each control objective In-page, deeper OPF-ECF Enterprise Managed & assured
Implementation controls — technical, process, operational The control framework, per-domain then whole-Standard ECF-IDF Conglomerate Optimising & leading

The three lenses climb in parallel: the OPF (Organisational Policy Framework) gathers the policy layers, the ECF (Control Framework) the technical and process controls, and the IDF (Information & Data Framework) the data-handling layer — each lens rolling up one tier above its components. The architecture already built needs no modification to parallel this graph: knowledge layer, content artefact, framework lens, tier and maturity move together, yet each arrives as a taste before it arrives in full, and deepens in place as a member climbs.

5. A simplified view (illustrative)

Click a domain, a sub-policy, then a control objective — the selected path lights up. Hover a box for its full title. Live from the ontology.

Read it top to bottom: one subjectnine domains → a handful of policies per domain → the control objectives beneath them → the technical controls that implement each. The point is the middle: instead of reading every standard separately, many standards meet on one objective.

Illustrative only. Domains and connections are shown to convey shape, not to enumerate the live structure, which members navigate through the Standard’s content surfaces.

6. Reference-only positioning

The Standard does not reproduce the text of the source standards it recognises. The concepts shown here are CIAO’s own harmonised expression, presented illustratively and without attribution to any single source’s wording. Members consult their own authorised copies of any source standard directly. The Standard provides the architectural layer above those sources, by which their requirements are organised and related — not a substitute for them.

7. Relationship to other instruments

Each refers up to the others rather than restating them.

8. Scope of this edition

This inaugural edition describes the knowledge structure at the foundational level — the layers and their mirrors. Finer relationship detail is developed progressively and surfaced through the Standard’s higher content tiers.

● LIVE CONTENT  ·  Verified 22 July 2026 at 23:02 UTC  ·  Version 1.1.3.7  ·  Always current at c-ao.com  ·  © CIAO Standard Secretariat 2026
Notices1 JulThe Monthly Standard release is scheduled for 2026-07-16.1 JulThe Annual Major release is scheduled for 2027-02-01.1 JulThe Monthly Standard release is scheduled for 2026-07-16.1 JulThe Annual Major release is scheduled for 2027-02-01.

Cite this page (APA)