Ontology Comparison: Record Harm vs. Related Frameworks
This document maps the Record Harm Ontology to established frameworks in information security, archival science, and diplomatics.
Overview
The Record Harm Ontology focuses on ontological attacks on records — how records can be damaged, destroyed, or corrupted as informational entities. While it shares concerns with other frameworks, its scope and granularity differ:
- STRIDE (threat modeling): Focuses on system security threats
- CIA Triad (information security): Focuses on confidentiality, integrity, availability
- InterPARES Diplomatics: Focuses on record authenticity and trustworthiness
- Spoliation Doctrine (legal): Focuses on evidence destruction and concealment
Comparison Table
Record Harm ↔ STRIDE
| Record Harm | STRIDE Category | Notes |
|---|---|---|
| Fabrication | Tampering | Both involve creating/modifying false information |
| Alteration | Tampering | Direct modification of existing data |
| Destruction | Denial of Service (partial) | DoS is transient unavailability; Destruction is permanent loss |
| Suppression | Denial of Service (partial) | Suppression is deliberate concealment; DoS is service disruption |
| Denial | Repudiation | Both involve denying validity/authorship |
| Omission | (no direct mapping) | STRIDE has no completeness category. Not an inverse of Information Disclosure: omission attacks what the record contains, disclosure attacks who can read it — different aspects, not opposite ends of one. |
| ForgeryOfProvenance | Spoofing | Both involve falsifying identity/origin |
| Repudiation | Repudiation | Direct mapping |
| Contamination | Tampering | Mixing genuine with false |
| Decontextualization | (no direct mapping) | STRIDE doesn't model context stripping |
| Fragmentation | (no direct mapping) | STRIDE doesn't model record fragmentation |
| Obfuscation | (no direct mapping) | STRIDE doesn't model deliberate obscurity |
| (no mapping) | Information Disclosure | Deliberate gap: Leaked records are undamaged as records |
| (no mapping) | Elevation of Privilege | Outside record harm scope (system access, not record integrity) |
Key Differences:
- STRIDE is system-centric; Record Harm is record-centric
- STRIDE includes confidentiality (Information Disclosure); Record Harm deliberately excludes it — a leaked record is authentic, complete, and accessible
- Record Harm distinguishes Suppression from Destruction; STRIDE conflates both under Denial of Service
- Record Harm models composite harms; STRIDE categories are flat
Record Harm ↔ CIA Triad
| Record Harm | CIA Category | Notes |
|---|---|---|
| Destruction | Availability | Permanent loss vs. transient unavailability |
| Suppression | Availability | Deliberate concealment vs. system failure |
| Fabrication | Integrity | Creating false records |
| Alteration | Integrity | Modifying existing records |
| Contamination | Integrity | Mixing genuine with false |
| Omission | Integrity | Incomplete records |
| ForgeryOfProvenance | Integrity + Authenticity | Falsifying origin/custody |
| Denial | (no mapping) | Contesting legitimacy. Trustworthiness is a Record Harm aspect, not a CIA category — see the key difference below. |
| Repudiation | (no mapping) | Disavowing authorship. Same gap as Denial. |
| Decontextualization | Integrity | Stripping metadata/context |
| Fragmentation | Integrity + Availability | Breaking into disconnected pieces |
| Obfuscation | Availability | Degrading comprehensibility |
| (no mapping) | Confidentiality | Deliberate gap: See STRIDE notes above |
Key Differences:
- CIA is property-centric (what properties are violated); Record Harm is action-centric (what attacks occur)
- CIA Integrity is broad; Record Harm separates what it lumps together —
AlterationandOmissionboth violate integrity but are distinct primes, andFabricationis split off entirely as an attack on Authenticity - CIA Availability conflates destruction, suppression, and obfuscation; Record Harm separates them
- Record Harm adds Trustworthiness as a distinct aspect beyond CIA
Record Harm ↔ InterPARES Diplomatics
InterPARES (International Research on Permanent Authentic Records in Electronic Systems) provides a framework for archival authenticity.
| Record Harm | Diplomatics Concept | Notes |
|---|---|---|
| Authenticity (aspect) | Authenticity | Core shared concept |
| Context (aspect) | Archival Bond | Both emphasize provenance and relationships |
| Integrity (aspect) | Completeness | Both require wholeness |
| Fabrication | Forgery | Creating false records |
| Alteration | Corruption | Unauthorized modification |
| ForgeryOfProvenance | False Provenance | Falsifying archival context |
| Decontextualization | Loss of Archival Bond | Severing from context |
| Omission | Incompleteness | Missing elements |
| Destruction | Loss | Permanent removal |
| Suppression | Concealment | Deliberate hiding |
| Denial | Contestation of Authenticity | Challenging legitimacy |
| Fragmentation | Dispersal | Breaking archival unity |
| Contamination | Adulteration | Mixing genuine with false |
| Obfuscation | Obscuration | Degrading intelligibility |
| Repudiation | Disavowal of Authorship | Denying creation |
Key Similarities:
- Both emphasize authenticity and provenance
- Both recognize context as essential to record meaning
- Both distinguish form from content
Key Differences:
- Diplomatics is preservation-focused; Record Harm is attack-focused
- Diplomatics emphasizes archival bond (relationships between records); Record Harm models this via hasElement
- Diplomatics is community-calibrated; Record Harm includes inside-agent records (memories, beliefs)
Record Harm ↔ Spoliation Doctrine (Legal)
Spoliation doctrine addresses destruction or concealment of evidence in legal proceedings.
| Record Harm | Spoliation Concept | Notes |
|---|---|---|
| Destruction | Destruction of Evidence | Direct mapping |
| Suppression | Concealment/Withholding | Hiding evidence from discovery |
| Alteration | Tampering with Evidence | Modifying evidence |
| Fabrication | Fabrication of Evidence | Creating false evidence |
| Omission | Selective Production | Withholding relevant documents |
| ForgeryOfProvenance | False Chain of Custody | Falsifying evidence handling |
| Contamination | Tainting Evidence | Mixing genuine with false |
| Denial | Contesting Authenticity | Challenging evidence validity |
| Repudiation | Disavowal | Denying authorship/authority |
| Decontextualization | Selective Quotation | Removing context to mislead |
| Fragmentation | Partial Production | Producing incomplete sets |
| Obfuscation | Burying in Volume | Making evidence hard to find |
Key Similarities:
- Both recognize destruction and concealment as distinct wrongs
- Both address chain of custody (ForgeryOfProvenance)
- Both recognize selective production (Omission)
Key Differences:
- Spoliation is adversarial (litigation context); Record Harm is general-purpose
- Spoliation focuses on intent and bad faith; Record Harm models the acts themselves
- Spoliation has legal remedies (adverse inference, sanctions); Record Harm is descriptive, not prescriptive
Unique Contributions of Record Harm Ontology
1. Inside-Agent Records (v3.1)
No other framework explicitly models:
- Memories as records
- Beliefs as records
- Self-directed harm (repression, self-deception, motivated forgetting)
- The agent/community boundary
Example: A witness repressing a memory is ex:Suppression where perpetrator = bearer. This is inexpressible in STRIDE, CIA, diplomatics, or spoliation.
2. Formal Dependency Structure
Record Harm uniquely provides:
- Distinction between prime (irreducible) and composite (derived) harms
- Explicit
buildsUponrelationships - Reasoner-derivable composite membership
- Transitive closure via SPARQL property paths
Example: ex:Obfuscation buildsUpon ex:Suppression, ex:Alteration — neither STRIDE nor CIA models this dependency.
3. Mereological Structure (v3.1)
Record Harm uniquely models:
- Records as composed of other records (
hasElement) - Community registers as records in their own right
- Non-admission as
Omissionfrom the register
Example: A parish register whose elements are individual testimonies. Refusing to admit a testimony is ex:Omission from that register.
4. Aspect-Based Targeting
Record Harm provides:
- 6 fundamental aspects (Existence, Authenticity, Integrity, Accessibility, Context, Trustworthiness)
- Multi-valued targeting (one harm can attack multiple aspects)
- Coverage guarantee (every aspect reachable from at least one prime)
Example: ex:Alteration targets both Authenticity and Integrity — CIA would only say "Integrity violation."
5. Event Layer with Severity
Record Harm separates:
- Harm types (abstract categories)
- Harm events (specific occurrences with dates, perpetrators, severity)
Example: Two ex:Destruction events can have different severities (destroying a parking receipt vs. a birth certificate).
Integration Guidance
For Information Security Practitioners
- Map STRIDE threats to Record Harms for evidence integrity analysis
- Use Record Harm for forensics where CIA Triad is too coarse
- Note the confidentiality gap — add your own confidentiality layer if needed
For Archivists and Records Managers
- Use Record Harm alongside diplomatics for threat modeling
- Model archival bonds via
hasElementfor collection integrity - Track provenance attacks via
ForgeryOfProvenance
For Legal Professionals
- Map spoliation claims to Record Harms for structured analysis
- Use severity scoring for proportionality arguments
- Track chain of custody via
ForgeryOfProvenanceevents
For AI Ethics and Misinformation Research
- Model disinformation campaigns as
HarmPatterninstances - Track inside-agent harms (belief manipulation, memory distortion)
- Use
Contaminationfor genuine/false mixing in information ecosystems
Limitations and Scope Boundaries
What Record Harm Does NOT Cover
- Confidentiality breaches — Deliberate exclusion (see notes above)
- System vulnerabilities — STRIDE is better for this
- Access control — Outside record harm scope
- Encryption/cryptography — Technical implementation, not ontological harm
- Pure non-creation — Witnessing without recording (see
ex:RecordHarmscope note)
What Record Harm DOES Cover
- Ontological attacks on records — Existence, authenticity, integrity, accessibility, context, trustworthiness
- Inside-agent and inside-community records — Memories, beliefs, registers, archives
- Self-directed harm — Repression, self-deception, motivated forgetting
- Composite harm structures — Dependencies and patterns
- Event tracking — Specific occurrences with severity and attribution
References
- STRIDE: Microsoft Threat Modeling Framework
- CIA Triad: Confidentiality, Integrity, Availability (foundational InfoSec model)
- InterPARES: International Research on Permanent Authentic Records in Electronic Systems
- Spoliation Doctrine: Legal doctrine on evidence destruction/concealment
- Record Harm Ontology: This ontology (v3.1)
Versioning
This document describes the Record Harm Ontology at v3.1 and carries no
version of its own. The ontology has a single version, asserted in
owl:versionInfo and recorded in CHANGELOG.md; a separate
per-document number would be a second version axis that drifts out of step
with the thing it describes — the same failure mode as v1's
isFundamentalRoot boolean drifting out of step with class membership.
When the mappings below change because the taxonomy changed, record it in the ontology's changelog entry for that release, not here.