{"change_levels":[{"level":"Baseline","meaning":"Establish visibility and minimum control","security_expression":"Know what exists, who owns it, what is exposed, and whether minimum controls work."},{"level":"Minor change","meaning":"Tune existing controls","security_expression":"Close ports, correct permissions, rotate keys, add alerts, tighten headers, shorten retention."},{"level":"Major change","meaning":"Replace or redesign components","security_expression":"Migrate auth, segment networks, change backup architecture, rebuild images, replace shared credentials."},{"level":"Structural change","meaning":"Alter trust boundaries and operating model","security_expression":"Immutable deployment, separate management plane, per-client runners, zero-trust access, isolated evidence stores."},{"level":"Paradigm change","meaning":"Make security adaptive and policy-driven","security_expression":"Continuous verification, signed policy-as-code, automated drift response, measured recovery, threat-informed control mutation."}],"internal_variables":["Object","Conditions","Actions","Tools","Resources","Outcomes","Feedback","Constraints","Value","Failure mode"],"internal_variable_matrix":[{"variable":"Object","baseline":"Enumerate drives, hosts, apps, identities, data, dependencies","minor_change":"Correct labels, owners, criticality, lifecycle","major_change":"Split high-risk objects; replace unsupported assets","structural_change":"Rebuild boundaries around tenants and management planes","paradigm_change":"Treat every asset as an ephemeral, attestable security object"},{"variable":"Conditions","baseline":"Record environment, exposure, privilege, backup, maintenance state","minor_change":"Add missing context and exception expiry","major_change":"Redesign operating conditions to remove unsafe assumptions","structural_change":"Make policy derive from environment and trust boundary","paradigm_change":"Continuously infer context and re-evaluate authorization"},{"variable":"Actions","baseline":"Inventory, audit, patch, back up","minor_change":"Tune, rotate, restrict, alert","major_change":"Migrate, rebuild, segment, re-key","structural_change":"Orchestrate canaries, immutable changes, isolated recovery","paradigm_change":"Closed-loop plan-test-change-verify-learn"},{"variable":"Tools","baseline":"Basic OS tools and passive scanners","minor_change":"Centralize versions, configs, parsers","major_change":"Replace manual scripts with controlled runners","structural_change":"Separate read-only, active-test, and change execution planes","paradigm_change":"Attested disposable workers selected by policy"},{"variable":"Resources","baseline":"Asset list, owner, credentials, backups","minor_change":"Better telemetry and runbooks","major_change":"Dedicated security data store and staging clone","structural_change":"Per-client infrastructure and out-of-band recovery","paradigm_change":"Dynamically allocated evidence, models, and simulation environments"},{"variable":"Outcomes","baseline":"Minimum controls visible","minor_change":"Fewer gaps and faster detection","major_change":"Reduced attack paths and blast radius","structural_change":"Failure contained by architecture","paradigm_change":"Measurable resilience and adaptive control effectiveness"},{"variable":"Feedback","baseline":"Tickets and periodic review","minor_change":"Automated retests and drift alerts","major_change":"Architecture decisions informed by recurring findings","structural_change":"Control failures trigger safe isolation or rollback","paradigm_change":"Feedback changes profiles, priorities, and test selection continuously"},{"variable":"Constraints","baseline":"Legal scope, uptime, privacy, budget","minor_change":"Explicit rate, time, and change ceilings","major_change":"Rework incompatible systems and contracts","structural_change":"Encode constraints as policy and tenant boundaries","paradigm_change":"Constraints become machine-verifiable preconditions"},{"variable":"Value","baseline":"Avoid preventable compromise","minor_change":"Reduce toil and client uncertainty","major_change":"Protect revenue, data, and recovery capability","structural_change":"Make client security scalable and provable","paradigm_change":"Security becomes a continuously measured service quality"},{"variable":"Failure mode","baseline":"Unknown assets, missed patches, weak backups","minor_change":"False positives, alert fatigue, stale exceptions","major_change":"Migration error, lockout, dependency breakage","structural_change":"Control-plane compromise, shared-tenant failure","paradigm_change":"Automation amplifies a bad policy unless governed and reversible"}],"meta_variables":[{"name":"Magnitude","question":"how much change or harm?"},{"name":"Rate","question":"how quickly?"},{"name":"Direction","question":"moving toward what?"},{"name":"Scope","question":"how broadly?"},{"name":"Depth","question":"how fundamentally?"},{"name":"Duration","question":"for how long?"},{"name":"Frequency","question":"how often?"},{"name":"Acceleration","question":"is the rate increasing or decreasing?"},{"name":"Variability","question":"how consistent or unpredictable?"},{"name":"Detectability","question":"how visible and measurable?"},{"name":"Reversibility","question":"can it be undone?"},{"name":"Propagation","question":"how does it spread?"},{"name":"Amplification","question":"what makes the effect larger?"},{"name":"Accumulation","question":"what builds up over time?"}],"note":"A checklist asks whether a control exists. The volumetric matrix asks how the control behaves across variables, meta-variables and five change levels."}