{
  "schema": "https://sosec.io/static/research/cis-controls-v8-1-cas-findings-schema-july-2026-v2.json",
  "schema_name": "sosec.cis-controls-v8.1.cas-findings-ledger.v2",
  "artifact_version": "2.0.0",
  "framework": {
    "name": "CIS Controls",
    "edition": "v8.1",
    "controls": 18,
    "safeguards": 153
  },
  "cutoff": "2026-07-31",
  "generated_at": "2026-07-30T16:55:56.758Z",
  "provenance_classes": {
    "cis_official": {
      "en": "Unmodified or whitespace-normalized fields transcribed from the pinned CIS surface.",
      "zh": "来自固定 CIS 官方页面的原文或仅做空白归一的字段。"
    },
    "sosec_analysis": {
      "en": "SOSEC interpretation of source structure, variable lineage, decision risk, or missing effectiveness depth.",
      "zh": "SOSEC 对来源结构、变量谱系、决策风险或有效性深度缺口的分析。"
    },
    "example_local_solution": {
      "en": "A non-normative implementation option that requires local owner approval and validation.",
      "zh": "须由本地责任人批准和验证的非规范性实施示例。"
    }
  },
  "source_set": {
    "navigator": {
      "url": "https://www.cisecurity.org/controls/cis-controls-navigator",
      "retrieved_at": "2026-07-30T16:31:55.659Z",
      "bytes": 2701228,
      "sha256": "2A8B34FAE24702155E4DA93EFB9B53A96B3BD12126F6661C9F5F76216BE2DE7B",
      "structured_comparison": {
        "safeguards": 153,
        "changed_id_title_description_ig_asset_class_records": 0
      }
    },
    "cas_control_pages": [
      {
        "control": 1,
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls1/",
        "retrieved_at": "2026-07-30T16:25:16.120Z",
        "bytes": 34170,
        "sha256": "AD366711310451131E32B0C9F9B8A9F1F9F15FF7114DB326E611EB25356769EF"
      },
      {
        "control": 2,
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls2/",
        "retrieved_at": "2026-07-30T16:25:28.206Z",
        "bytes": 40572,
        "sha256": "59F438759F8704D42D908FD3E9EF9D632BF2C2984A4F033713634B3AE616B64A"
      },
      {
        "control": 3,
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls3/",
        "retrieved_at": "2026-07-30T16:25:28.667Z",
        "bytes": 62712,
        "sha256": "11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09"
      },
      {
        "control": 4,
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls4/",
        "retrieved_at": "2026-07-30T16:25:29.565Z",
        "bytes": 54051,
        "sha256": "613D6086318545F0A7BA221AF501DC788ACDB3F79C3370D891E1D6EA2CF1190C"
      },
      {
        "control": 5,
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls5/",
        "retrieved_at": "2026-07-30T16:25:30.015Z",
        "bytes": 35579,
        "sha256": "067CD9797658BCF1080DAC4A01672E8CD9A550F6933CD3F3219369737E28A28A"
      },
      {
        "control": 6,
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls6/",
        "retrieved_at": "2026-07-30T16:25:30.470Z",
        "bytes": 35122,
        "sha256": "F05309C876FA1A941F5B41071EE4764DAA9848B4EB967755B390547FE1F078C5"
      },
      {
        "control": 7,
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls7/",
        "retrieved_at": "2026-07-30T16:25:31.916Z",
        "bytes": 42540,
        "sha256": "BA2036413BBF89630CCF02B4B304353CB97FCCEB11F22AD1F95FB6408A06830B"
      },
      {
        "control": 8,
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls8/",
        "retrieved_at": "2026-07-30T16:25:43.952Z",
        "bytes": 44150,
        "sha256": "BB5C01E764D3A2C232D06D1F839F90311343D93E4A858CB123E6D9911B5A4DC4"
      },
      {
        "control": 9,
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls9/",
        "retrieved_at": "2026-07-30T16:25:45.071Z",
        "bytes": 33622,
        "sha256": "893B95999A6ACDC28F3DE11419EF6E6640E491BA628EA37586763E76C0FF99C7"
      },
      {
        "control": 10,
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls10/",
        "retrieved_at": "2026-07-30T16:25:46.197Z",
        "bytes": 31011,
        "sha256": "BBDC6A8F61662575C58667EBB74C005F06950B21B0CF58D65E501814C00BE8B5"
      },
      {
        "control": 11,
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls11/",
        "retrieved_at": "2026-07-30T16:25:47.206Z",
        "bytes": 27304,
        "sha256": "64B9FC7DBD72CA64F77263A3253BCCD64F658CFD626A18DD543020FB8171C94F"
      },
      {
        "control": 12,
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls12/",
        "retrieved_at": "2026-07-30T16:25:48.241Z",
        "bytes": 43399,
        "sha256": "B86C7314F9857EE4AFD9ACAD5661B3A82B1F8B43C6C0D91165DE0B14B6531E53"
      },
      {
        "control": 13,
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls13/",
        "retrieved_at": "2026-07-30T16:26:00.266Z",
        "bytes": 46778,
        "sha256": "F31FFE89DE5087977E7CB6FBD81EC876602871F30C8EA815C0DF862CA40F65BF"
      },
      {
        "control": 14,
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls14/",
        "retrieved_at": "2026-07-30T16:26:01.267Z",
        "bytes": 49352,
        "sha256": "B3AB523467DE4AACC7A8227C3CC2056EE99F14A3A254D1769D5EAC5C90C30305"
      },
      {
        "control": 15,
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls15/",
        "retrieved_at": "2026-07-30T16:26:02.291Z",
        "bytes": 36086,
        "sha256": "6987C580534344D0FE4C30694EFBA342A165145B53FB87BFE53160867B099415"
      },
      {
        "control": 16,
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls16/",
        "retrieved_at": "2026-07-30T16:26:03.475Z",
        "bytes": 62629,
        "sha256": "78BEFD8EB1628E546CA330222996DCA16DD2C9EF7FC70A606844C44A4F64872E"
      },
      {
        "control": 17,
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls17/",
        "retrieved_at": "2026-07-30T16:26:04.625Z",
        "bytes": 41343,
        "sha256": "A6DCCA0952C7F7B3C5FD75C759EA550966B498275E2E955D804B3D61D116E575"
      },
      {
        "control": 18,
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls18/",
        "retrieved_at": "2026-07-30T16:26:16.590Z",
        "bytes": 25664,
        "sha256": "AA6508DA60A7DA98047C8EE9E1D8B688F97A3668EE857F585E9B87511299F62A"
      }
    ],
    "cas_page_byte_changes_since_2026_07_27": 0,
    "cas_safeguard_h2_count": 153,
    "cas_metrics_h3_count": 153,
    "retrieval_window_utc": {
      "started_at": "2026-07-30T16:25:16.120Z",
      "ended_at": "2026-07-30T16:31:55.659Z"
    }
  },
  "method": {
    "finding_count": 40,
    "inclusion": "A finding is included when a pinned official field, heading relation, variable lineage, formula, label, scope, or assumption can change an automated assessment or implementation decision.",
    "evidence_boundary": "The ledger audits published assessment text and source drift. It does not score an enterprise or establish operating effectiveness.",
    "metric_parser_correction": "4.12 and 13.10 contain metric tables under peer h3 headings immediately after Metrics; both metrics exist. The earlier heading-sensitive parser was wrong."
  },
  "findings": [
    {
      "finding_id": "CAS-2026-07-31-001",
      "safeguard_ids": [],
      "safeguard_titles": [],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "Navigator and CAS source set",
        "url": "https://www.cisecurity.org/controls/cis-controls-navigator",
        "retrieved_at": "2026-07-30T16:31:55.659Z",
        "snapshot_sha256": "2A8B34FAE24702155E4DA93EFB9B53A96B3BD12126F6661C9F5F76216BE2DE7B",
        "locator": "Cross-surface structured comparison"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": []
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "official-surface-drift",
        "finding_en": "The July 27, 2026 Navigator snapshot and the CAS pages last modified January 15, 2026 agree on all 153 identifiers and IG tiers but diverge on titles, descriptions, and asset classes. CAS therefore needs reconciliation against the current Navigator before import.",
        "impact_en": "A GRC import can preserve a stale or malformed normative field even when the identifier remains valid.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "固定 Navigator 与 CAS 在 153 个编号和 IG 层级上相符，但标题、描述和 Asset Class 存在表面差异；导入前必须声明每个字段采用哪一官方表面。",
        "impact_zh": "按编号直接合并会把过时或损坏的规范字段带入 GRC，同时隐藏来源漂移。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Pin each official surface separately, choose one declared authority per imported field, and report the disagreement instead of merging it silently.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "分别固定并哈希各官方表面；逐字段选定权威来源，所有分歧原样保留，不静默拼接。"
      },
      "reproduction": {
        "steps": [
          "Download the Navigator and all eighteen CAS Control pages.",
          "Hash each response before parsing.",
          "Parse Safeguard ID, title, description, IG and Asset Class from every surface.",
          "Compare fields by Safeguard ID and retain every disagreement."
        ],
        "expected": "The July 27, 2026 Navigator snapshot and the CAS pages last modified January 15, 2026 agree on all 153 identifiers and IG tiers but diverge on titles, descriptions, and asset classes. CAS therefore needs reconciliation against the current Navigator before import."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-002",
      "safeguard_ids": [
        "1.1"
      ],
      "safeguard_titles": [
        {
          "id": "1.1",
          "en": "Establish and Maintain Detailed Enterprise Asset Inventory",
          "zh": "企业资产总账"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls1/",
        "retrieved_at": "2026-07-30T16:25:16.120Z",
        "snapshot_sha256": "AD366711310451131E32B0C9F9B8A9F1F9F15FF7114DB326E611EB25356769EF",
        "locator": "Safeguard 1.1: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "1.1",
            "title": "Establish and Maintain Detailed Enterprise Asset Inventory",
            "asset_class": "Devices",
            "security_function": "Identify",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "GV1: Enterprise Asset Inventory The enterprise's list of current approved inventory to include all assets as outlined in the Safeguard. This list is a mix of manual and tool-generated endpoints that includes information such as authorized, non-authorized, IP address, device type, and any other information as defined by the enterprise. Aggregate Enterprise Asset Inventory - The enterprise's list of all devices detected, manually or through automated scans, since the last update to GV1. Date of last update to the Enterprise Asset Inventory",
            "operations": "Calculate the intersection of GV1 and Input 2 Enumerate items in GV1 that are not in Input 2 (M4) Enumerate items in Input 2 not in Input 1 (GV2: M5). These assets are considered unauthorized. Check items in Input 1 for complete or missing detailed information Enumerate items that have complete information (M6) Enumerate items that do not have complete information or missing information (M7). Calculate the time (in months) since the last update to Input 1 by using the current date and Input 3 (M8).",
            "measures": "M1 = GV1 M2 = Count of items in Input 2 M3 = Count of items in the intersection of GV1 and Input 2 M4 = Count of items in GV1 not found in Input 2 M5 = GV2 M6 = Count of items in GV1 that contain all necessary detailed information M7 = Count of items in GV1 that do not contain detailed information M8 = Months since the last update to GV1",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M1 is not provided or available, then this Safeguard is measured at a 0 and receives a failing score. The other metrics don't apply. If M8 is greater than six months, then this Safeguard is measured at a 0 and receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Accuracy Score",
                "content": "Metric | What percentage of the aggregate endpoint inventory is accounted for in the current enterprise asset inventory?\nCalculation | M3 / M2"
              },
              {
                "heading": "Metrics / Accuracy Score / Completeness Score",
                "content": "Metric | What percentage of the current enterprise asset inventory contains necessary detailed information?\nCalculation | M8 / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "formula",
        "finding_en": "CAS labels the completeness calculation as M8 / M1, although M8 is months since inventory update and M1 is the inventory object/count context; M6 is the count with complete information.",
        "impact_en": "The published formula is dimensionally invalid and cannot measure inventory completeness.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "CAS 把完整度写成 M8 / M1；M8 是距上次更新的月数，M1 是台账对象或数量上下文，量纲无法形成字段完整率。",
        "impact_zh": "公式无法表达资产记录字段是否完整，自动评分会产生无意义结果。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Preserve the official text, reject M8 / M1 as an automation formula, and calculate field completeness from records with all required fields divided by the defined in-scope asset population; publish the local formula as local semantics.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "保留官方原式作为证据；本地以必填字段完整的记录数除以已定义的在范围资产总体，并单独设置新鲜度门槛。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls1/.",
          "Verify the response SHA-256 equals AD366711310451131E32B0C9F9B8A9F1F9F15FF7114DB326E611EB25356769EF.",
          "Locate Safeguard 1.1 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "CAS labels the completeness calculation as M8 / M1, although M8 is months since inventory update and M1 is the inventory object/count context; M6 is the count with complete information."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-003",
      "safeguard_ids": [
        "1.2"
      ],
      "safeguard_titles": [
        {
          "id": "1.2",
          "en": "Address Unauthorized Assets",
          "zh": "处置未授权资产"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls1/",
        "retrieved_at": "2026-07-30T16:25:16.120Z",
        "snapshot_sha256": "AD366711310451131E32B0C9F9B8A9F1F9F15FF7114DB326E611EB25356769EF",
        "locator": "Safeguard 1.2: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "1.2",
            "title": "Address Unauthorized Assets",
            "asset_class": "Devices",
            "security_function": "Respond",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "GV1: Enterprise Asset Inventory GV2: Unauthorized Assets The enterprise-defined time frame for removing unauthorized assets (weekly or more often).",
            "operations": "If the optional disposition list is provided, the checks would be tailored to those dispositions. For the following, assume no disposition list is available:\nAt the time frame specified by Input 3, for each unauthorized asset in GV2, check to see if the asset is present in the updated asset inventory from GV1. For those items in GV2 that are not in GV1, scan the network to determine if the item is still reachable on the network. Enumerate the items from GV2 that are unreachable (M4) Enumerate the items from GV1 that are unreachable (M5)",
            "measures": "M1 = GV1 M2 = Count of GV2 M3 = Timeframe in days for Input 3 M4 = Count of items from GV2 that are unreachable after scan M5 = Count of items from GV1 that are unreachable after scan",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M3 is greater than seven days, then this Safeguard is measured at a 0 and receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Coverage",
                "content": "Metric | The ratio of unaccounted for, unauthorized assets, to the total assets in the asset inventory.\nCalculation | If the value of M4 is 0, there are no unauthorized assets that remain unaccounted for. In this case, the value of the metric is 1. Otherwise, the value is (M2 - M4) / M2."
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "assumption",
        "finding_en": "CAS permits an unreachable unauthorized asset to be treated as addressed.",
        "impact_en": "Sleep, travel, network segmentation, scan failure, or a powered-off rogue device can look like removal; disposition needs an enforcement or custody record.",
        "confidence": {
          "level": "medium",
          "reason": "The source wording and variable lineage are directly observable; the implementation consequence depends on the adopter architecture or risk decision."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "CAS 允许把已经无法触达的未授权资产视为已处置。",
        "impact_zh": "休眠、出差、分段、扫描失败或关机的资产可能在没有任何强制动作时获得处置积分。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Require positive disposition evidence and retain the item in the denominator when the observation source becomes silent.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "必须取得移除、隔离、拒绝、保管或批准的正向处置证据；观测源沉默时继续保留在分母。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls1/.",
          "Verify the response SHA-256 equals AD366711310451131E32B0C9F9B8A9F1F9F15FF7114DB326E611EB25356769EF.",
          "Locate Safeguard 1.2 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "CAS permits an unreachable unauthorized asset to be treated as addressed."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-004",
      "safeguard_ids": [
        "1.3"
      ],
      "safeguard_titles": [
        {
          "id": "1.3",
          "en": "Utilize an Active Discovery Tool",
          "zh": "主动发现"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls1/",
        "retrieved_at": "2026-07-30T16:25:16.120Z",
        "snapshot_sha256": "AD366711310451131E32B0C9F9B8A9F1F9F15FF7114DB326E611EB25356769EF",
        "locator": "Safeguard 1.3: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "1.3",
            "title": "Utilize an Active Discovery Tool",
            "asset_class": "Devices",
            "security_function": "Detect",
            "implementation_groups": [
              2,
              3
            ],
            "inputs": "GV1: Enterprise Asset Inventory The list of active discovery tool(s) used by the enterprise List consisting of the union from scan results conducted using all active asset discovery tool(s) within the enterprise (discovered assets). Timeframe between two active asset discovery tool scans. GV3: Configuration Standard",
            "operations": "Identify enterprise assets not discovered by the active discovery tools by comparing Input 1 and Input 3 (M2). Identify the configurations for active asset discovery tools that interface with GV1 by using GV3 Using the configuration information in GV3, check the approved configurations to verify that the tools are capable of interfacing with the asset inventory to make automatic updates. Enumerate those tools that are compliant (M3) Enumerate those that are not compliant (M4).",
            "measures": "M1 = Count of all discovered assets from Input 3 M2 = Count of undiscovered assets M3 = Count of properly configured tools M4 = Count of improperly configured tools M5 = Count of Input 2 M6 = Count of GV1 M7 = Timeframe in hours for Input 4",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M7 is greater than 24 hours, then this Safeguard is measured at a 0 and receives a failing score. The other metrics don't apply. If M5 is 0, then this Safeguard is measured at a 0 and receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Asset Discovery Coverage",
                "content": "Metric | Asset Discovery Coverage\nCalculation | M1 / M6"
              },
              {
                "heading": "Metrics / Asset Discovery Coverage / Tool Compliance Ratio",
                "content": "Metric | Tool Compliance Ratio\nCalculation | M3 / M2"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "formula",
        "finding_en": "CAS calls M3 / M2 a tool compliance ratio, while M3 counts properly configured tools and M2 counts undiscovered assets.",
        "impact_en": "The numerator and denominator describe different populations; use properly configured tools divided by all in-scope discovery tools.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "CAS 将正确配置的发现工具数 M3 除以未发现资产数 M2，两个变量来自不同总体。",
        "impact_zh": "工具合规率无法复现，且未发现资产变化会无关地改变工具得分。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Separate tool health from discovery coverage: use properly configured discovery tools over all in-scope tools, and reconcile unique discovered assets against a separately defined asset population.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "工具健康使用“正确配置工具/全部在范围工具”；资产发现覆盖另用独立资产总体核算。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls1/.",
          "Verify the response SHA-256 equals AD366711310451131E32B0C9F9B8A9F1F9F15FF7114DB326E611EB25356769EF.",
          "Locate Safeguard 1.3 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "CAS calls M3 / M2 a tool compliance ratio, while M3 counts properly configured tools and M2 counts undiscovered assets."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-005",
      "safeguard_ids": [
        "1.3"
      ],
      "safeguard_titles": [
        {
          "id": "1.3",
          "en": "Utilize an Active Discovery Tool",
          "zh": "主动发现"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls1/",
        "retrieved_at": "2026-07-30T16:25:16.120Z",
        "snapshot_sha256": "AD366711310451131E32B0C9F9B8A9F1F9F15FF7114DB326E611EB25356769EF",
        "locator": "Safeguard 1.3: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "1.3",
            "title": "Utilize an Active Discovery Tool",
            "asset_class": "Devices",
            "security_function": "Detect",
            "implementation_groups": [
              2,
              3
            ],
            "inputs": "GV1: Enterprise Asset Inventory The list of active discovery tool(s) used by the enterprise List consisting of the union from scan results conducted using all active asset discovery tool(s) within the enterprise (discovered assets). Timeframe between two active asset discovery tool scans. GV3: Configuration Standard",
            "operations": "Identify enterprise assets not discovered by the active discovery tools by comparing Input 1 and Input 3 (M2). Identify the configurations for active asset discovery tools that interface with GV1 by using GV3 Using the configuration information in GV3, check the approved configurations to verify that the tools are capable of interfacing with the asset inventory to make automatic updates. Enumerate those tools that are compliant (M3) Enumerate those that are not compliant (M4).",
            "measures": "M1 = Count of all discovered assets from Input 3 M2 = Count of undiscovered assets M3 = Count of properly configured tools M4 = Count of improperly configured tools M5 = Count of Input 2 M6 = Count of GV1 M7 = Timeframe in hours for Input 4",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M7 is greater than 24 hours, then this Safeguard is measured at a 0 and receives a failing score. The other metrics don't apply. If M5 is 0, then this Safeguard is measured at a 0 and receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Asset Discovery Coverage",
                "content": "Metric | Asset Discovery Coverage\nCalculation | M1 / M6"
              },
              {
                "heading": "Metrics / Asset Discovery Coverage / Tool Compliance Ratio",
                "content": "Metric | Tool Compliance Ratio\nCalculation | M3 / M2"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "denominator",
        "finding_en": "CAS uses discovered assets divided by inventory assets as discovery coverage.",
        "impact_en": "The result can exceed one and does not distinguish authorized, duplicate, transient, or false-positive observations; reconcile unique assets against the defined in-scope population.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "CAS 用已发现资产数除以台账资产数表示发现覆盖。",
        "impact_zh": "重复、瞬态和误识别会让结果超过 100%，也无法区分授权状态。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Separate tool health from discovery coverage: use properly configured discovery tools over all in-scope tools, and reconcile unique discovered assets against a separately defined asset population.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "对观测做稳定身份归一，再把唯一已发现资产与事先定义的在范围资产总体对账。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls1/.",
          "Verify the response SHA-256 equals AD366711310451131E32B0C9F9B8A9F1F9F15FF7114DB326E611EB25356769EF.",
          "Locate Safeguard 1.3 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "CAS uses discovered assets divided by inventory assets as discovery coverage."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-006",
      "safeguard_ids": [
        "1.4"
      ],
      "safeguard_titles": [
        {
          "id": "1.4",
          "en": "Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory",
          "zh": "DHCP 与 IPAM 观测"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls1/",
        "retrieved_at": "2026-07-30T16:25:16.120Z",
        "snapshot_sha256": "AD366711310451131E32B0C9F9B8A9F1F9F15FF7114DB326E611EB25356769EF",
        "locator": "Safeguard 1.4: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "1.4",
            "title": "Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory",
            "asset_class": "Devices",
            "security_function": "Identify",
            "implementation_groups": [
              2,
              3
            ],
            "inputs": "List of DHCP Servers GV41: List of Configuration Management Database (CMDB) Servers",
            "operations": "For each DHCP server, enumerate those where DHCP logging is enabled (M2) For each CMDB server, enumerate those where DHCP logs are used to update IP addresses (M4)",
            "measures": "M1 = Count of Input 1 M2 = Count of DHCP servers with logging enabled M3 = Count of Input 2 GV41 M4 = Count of CMDB servers configured to use DHCP logs to update IP addresses M5 = Count of devices in the DHCP server logs that are not included in the CMDB servers M6 = Count of devices in the DHCP server logs that are included in the CMDB servers M7 = Count of unique devices in the DHCP server logs",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "M4 > 0 indicates a non up-to-date asset inventory"
              },
              {
                "heading": "Metrics / DHCP Logging Quality",
                "content": "Metric | Ratio of appropriately configured DHCP logging enabled to known DHCP servers\nCalculation | M2 / M1"
              },
              {
                "heading": "Metrics / DHCP Logging Quality / CMDB Configuration Quality",
                "content": "Metric | Ratio of appropriately configured CMDB servers using DHCP logging to update IP addresses\nCalculation | M4 / M3"
              },
              {
                "heading": "Metrics / DHCP Logging Quality / CMDB Configuration Quality / CMDB Updating Accuracy",
                "content": "Metric | Ratio of DHCP-observed devices present in the CMDB\nCalculation | M6 / M7"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "contradiction",
        "finding_en": "CAS states that M4 greater than zero indicates a stale inventory, while M4 is defined as the count of CMDB servers configured to use DHCP logs.",
        "impact_en": "A positive control count is interpreted as failure; this condition cannot be automated safely.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "CAS 把 M4 大于零解释为台账陈旧，但 M4 定义为已经配置使用 DHCP 日志的 CMDB 服务器数。",
        "impact_zh": "正向控制数量被判作失败，无法安全自动化。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Do not automate the contradictory branch. Define one positive state, one failure state, and a negative test against the same object population.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "冻结官方原文；本地把正确产生日志的分配器作为成功分子，并用实际租约回放验证台账更新。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls1/.",
          "Verify the response SHA-256 equals AD366711310451131E32B0C9F9B8A9F1F9F15FF7114DB326E611EB25356769EF.",
          "Locate Safeguard 1.4 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "CAS states that M4 greater than zero indicates a stale inventory, while M4 is defined as the count of CMDB servers configured to use DHCP logs."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-007",
      "safeguard_ids": [
        "2.2"
      ],
      "safeguard_titles": [
        {
          "id": "2.2",
          "en": "Ensure Authorized Software is Currently Supported",
          "zh": "支持状态"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls2/",
        "retrieved_at": "2026-07-30T16:25:28.206Z",
        "snapshot_sha256": "59F438759F8704D42D908FD3E9EF9D632BF2C2984A4F033713634B3AE616B64A",
        "locator": "Safeguard 2.2: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "2.2",
            "title": "Ensure Authorized Software is Currently Supported",
            "asset_class": "Software",
            "security_function": "Identify",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "GV5: Authorized Software Inventory Including deployment mechanism and decommission date Authoritative source of information indicating supported/unsupported details by product. Exception documentation for unsupported software that is necessary for the fulfillment of the enterprise's mission. GV6: Last Update to Authorized Software Inventory",
            "operations": "For each item in GV5, perform a lookup in Input 2 to verify the supported/unsupported status. Enumerate each item labeled \"unsupported\" but \"supported\" based on Input 2 (M2) Enumerate each item labeled \"supported\" but \"unsupported\" based on Input 2 (M3). Identify and note truly \"unsupported\" items from Input 1 after conducting Operation 1 (M4). For each unsupported item identified in Operation 2, conduct a check using Input 3. Note items that do not have appropriate exception documentation (M5). Note items that do have appropriate exception documentation (M6). Compare the date of GV6 to the current date and note the timeframe in weeks (M7).",
            "measures": "M1 = Count of Input 1 M2 = Count of items in Input 1 that are mislabeled as unsupported M3 = Count of items in Input 1 that are mislabeled as supported M4 = Count of unsupported items M5 = Count of items in Input 1 that are no longer supported but exception documentation exists M6 = Count of items in Input 1 that are no longer supported and exception documentation does not exist M7 = Timeframe in weeks of the last update to the authorized software inventory",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M7 is greater than four, then this Safeguard is measured at a 0 and receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Percentage of Unsupported Software in Use",
                "content": "Metric | What percentage of authorized software inventory in use is unsupported?\nCalculation | M4 / M1"
              },
              {
                "heading": "Metrics / Percentage of Unsupported Software in Use / Rate of False Positives",
                "content": "Metric | What percentage of software listed as supported is actually not supported?\nCalculation | M3 / M1"
              },
              {
                "heading": "Metrics / Percentage of Unsupported Software in Use / Rate of False Positives / Rate of False Negatives",
                "content": "Metric | What percentage of software listed as unsupported is actually supported?\nCalculation | M2 / M1"
              },
              {
                "heading": "Metrics / Percentage of Unsupported Software in Use / Rate of False Positives / Rate of False Negatives / Percentage of unsupported software with exception documentation",
                "content": "Metric | What percentage of software listed as unsupported but appropriate exception documentation exists?\nCalculation | M5 / M4"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "measure-swap",
        "finding_en": "CAS operations assign M5 to unsupported items without exception documentation and M6 to items with documentation, but the Measures section reverses those meanings and the metric uses M5 / M4.",
        "impact_en": "The published metric can reward undocumented unsupported software as though it had an approved exception.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "2.2 的 Operations 与 Measures 对 M5、M6 的“有例外/无例外”含义互换，指标又使用 M5 / M4。",
        "impact_zh": "未记录例外的不受支持软件可能被当作已有批准例外而获得积分。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Bind every operation output to one measure name before calculating; reject the import while operation and measure labels disagree.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "先建立 Operation 到 Measure 的唯一变量谱系；在含义一致前拒绝自动评分。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls2/.",
          "Verify the response SHA-256 equals 59F438759F8704D42D908FD3E9EF9D632BF2C2984A4F033713634B3AE616B64A.",
          "Locate Safeguard 2.2 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "CAS operations assign M5 to unsupported items without exception documentation and M6 to items with documentation, but the Measures section reverses those meanings and the metric uses M5 / M4."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-008",
      "safeguard_ids": [
        "2.3"
      ],
      "safeguard_titles": [
        {
          "id": "2.3",
          "en": "Address Unauthorized Software",
          "zh": "未授权软件处置"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls2/",
        "retrieved_at": "2026-07-30T16:25:28.206Z",
        "snapshot_sha256": "59F438759F8704D42D908FD3E9EF9D632BF2C2984A4F033713634B3AE616B64A",
        "locator": "Safeguard 2.3: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "2.3",
            "title": "Address Unauthorized Software",
            "asset_class": "Software",
            "security_function": "Respond",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "GV5: Authorized Software Inventory GV1: Enterprise Asset Inventory Enterprise defined timeframe for scanning of enterprise assets. Enterprise defined allowable timeframe for resolution of discovered unauthorized software (recommend at least monthly)",
            "operations": "Identify the software capable enterprise assets in GV1 (GV7) Scan the assets identified in Operation 1 and note software present on each asset (M1) Compare the scan results to the authorized software list in GV5 Enumerate unauthorized software identified on assets (M2) Conduct a subsequent scan of assets identified in Operation 1 as dictated by the timeframe in Input 3 Compare to a list generated in Operation 3 (M2) For each software still present in Operation 4, check the authorized software list in GV5 Software that remains installed and is not listed in GV5 is placed on the unaddressed software list (M3) for that asset.",
            "measures": "M1 = The count of software installed on a given asset M2 = The count of unauthorized software installed on a given asset M3 = The count of unaddressed software installed on a given asset, identified by follow-up scan. M4 = Timeframe for resolution of discovered unauthorized software in weeks",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M4 is greater than four weeks, then this Safeguard is measured at a 0 and receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Unauthorized software Per Asset",
                "content": "Metric | Ensure unauthorized software installations are addressed\nCalculation | (M2-M3) / M3"
              },
              {
                "heading": "Metrics / Unauthorized software Per Asset / Unauthorized software for the enterprise",
                "content": "The enterprise metric is calculated by averaging the results calculated above per asset."
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "formula",
        "finding_en": "CAS calculates addressed unauthorized software as (M2 - M3) / M3, where M2 is initially unauthorized and M3 remains unaddressed.",
        "impact_en": "A fully remediated population divides by zero, and partial results can exceed one; the stable rate is (M2 - M3) / M2 with an explicit empty-population rule.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "CAS 将已处置未授权软件写成 (M2 - M3) / M3，其中 M3 是仍未处置数量。",
        "impact_zh": "全部修复时除零，部分修复时结果还可能超过 1。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Use (M2 - M3) / M2 with an explicit rule for M2 = 0, while retaining the official expression as source evidence.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "本地使用 (M2 - M3) / M2，并明确 M2 = 0 的空总体语义；官方原式保持不变作为来源证据。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls2/.",
          "Verify the response SHA-256 equals 59F438759F8704D42D908FD3E9EF9D632BF2C2984A4F033713634B3AE616B64A.",
          "Locate Safeguard 2.3 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "CAS calculates addressed unauthorized software as (M2 - M3) / M3, where M2 is initially unauthorized and M3 remains unaddressed."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-009",
      "safeguard_ids": [
        "2.5"
      ],
      "safeguard_titles": [
        {
          "id": "2.5",
          "en": "Allowlist Authorized Software",
          "zh": "应用允许清单"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls2/",
        "retrieved_at": "2026-07-30T16:25:28.206Z",
        "snapshot_sha256": "59F438759F8704D42D908FD3E9EF9D632BF2C2984A4F033713634B3AE616B64A",
        "locator": "Safeguard 2.5: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "2.5",
            "title": "Allowlist Authorized Software",
            "asset_class": "Software",
            "security_function": "Protect",
            "implementation_groups": [
              2,
              3
            ],
            "inputs": "GV7: Software Capable Assets GV5: Authorized Software Inventory GV3: Configuration Standard Date of last assessment of this Safeguard",
            "operations": "Using GV7 identify and enumerate assets capable of supporting allowlisting software (some assets may not enable third-party software installation or otherwise have constrained environments precluding the use of allowlisting software) (M1). Using GV5, identify all authorized allowlisting software within the enterprise (GV8) Using the output from Operation 1 and authorized allowlisting software GV8: Identify and enumerate allowlisting capable assets with allowlisting software installed (M2) Identify and enumerate allowlisting capable assets without allowlisting software installed (M3) Use GV3 to identify allowlisting software configurations (GV9) For each asset with allowlisting software installed (M2) from Operation 2, use the output from Operation 3 to: Identify and enumerate properly configured software (M4) Identify and enumerate improperly configured software (M5) Compare Input 4 to the current date and note the timeframe in months (M6)",
            "measures": "M1 = Count of enterprise assets capable of supporting allowlisting software M2 = Count of enterprise assets capable of supporting allowlisting software and have the software installed M3 = Count of enterprise assets capable of supporting allowlisting software and do not have the software installed M4 = Count of enterprise assets with allowlisting software that is properly configured M5 = Count of enterprise assets with allowlisting software that is properly configured M6 = Timeframe since the last assessment of this Safeguard",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M6 is greater than six months, then this Safeguard is measured at a 0 and receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Allow listing Installation Coverage",
                "content": "Metric | The percentage of enterprise assets capable of supporting allowlisting with allowlisting installed\nCalculation | M2 / M1"
              },
              {
                "heading": "Metrics / Allow listing Installation Coverage / Allowlisting Configuration Coverage",
                "content": "Metric | The percentage of enterprise assets with properly configured allowlisting installed\nCalculation | M4 / M2"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "duplicate-definition",
        "finding_en": "CAS defines both M4 and M5 as the count of properly configured allowlisting software, although the operations distinguish proper and improper configurations.",
        "impact_en": "The published measures cannot preserve the failure population.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "2.5 的 Measures 把 M4 与 M5 都定义成正确配置的允许清单软件，虽然 Operations 区分正确与错误配置。",
        "impact_zh": "失败总体在度量层消失，无法重建覆盖率。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Preserve the duplicate official definitions, block automatic scoring, and define distinct pass and fail populations locally.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "保留重复定义并停止自动评分；本地给正确与错误配置分别建立稳定变量。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls2/.",
          "Verify the response SHA-256 equals 59F438759F8704D42D908FD3E9EF9D632BF2C2984A4F033713634B3AE616B64A.",
          "Locate Safeguard 2.5 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "CAS defines both M4 and M5 as the count of properly configured allowlisting software, although the operations distinguish proper and improper configurations."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-010",
      "safeguard_ids": [
        "2.6"
      ],
      "safeguard_titles": [
        {
          "id": "2.6",
          "en": "Allowlist Authorized Libraries",
          "zh": "库允许清单"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls2/",
        "retrieved_at": "2026-07-30T16:25:28.206Z",
        "snapshot_sha256": "59F438759F8704D42D908FD3E9EF9D632BF2C2984A4F033713634B3AE616B64A",
        "locator": "Safeguard 2.6: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "2.6",
            "title": "Allowlist Authorized Libraries",
            "asset_class": "Software",
            "security_function": "Protect",
            "implementation_groups": [
              2,
              3
            ],
            "inputs": "GV8: Authorized Allowlisting Software The list of authorized software libraries GV9: Approved Configuration(s) for Allowlisting Software Date of the last assessment of this Safeguard",
            "operations": "For each item identified in GV8, use the approved configurations from GV9 and authorized library list from Input 2: Identify and enumerate allowlisting software properly configured to allow process loading of authorized libraries (M2) Identify and enumerate allowlisting software improperly configured to allow process loading of authorized libraries (M3) Compare the date from Input 4 to the current date and note the timeframe in months (M4).",
            "measures": "M1 = Count GV8 M2 = Count of properly configured allowlisting software M3 = Count of improperly configured allowlisting software M4 = Timeframe since the last assessment of this Safeguard",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M4 is greater than six months, then this Safeguard is measured at a 0 and receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Coverage",
                "content": "Metric | The percentage of appropriately configured allowlisting software instances within the enterprise.\nCalculation | M2 / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "dependency",
        "finding_en": "CAS lists the network-infrastructure configuration process in Safeguard 4.2 as a dependency for software-library allowlisting.",
        "impact_en": "The dependency is narrower and less relevant than the enterprise asset and software configuration process in 4.1; adopters should bind library policy to the actual host/application configuration authority.",
        "confidence": {
          "level": "medium",
          "reason": "The source wording and variable lineage are directly observable; the implementation consequence depends on the adopter architecture or risk decision."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "CAS 将 4.2 网络基础设施配置流程列为 2.6 软件库允许清单的依赖。",
        "impact_zh": "文字依赖不能建立真实的主机、应用构建或仓库信任边界，施工顺序可能被误导。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Treat the published dependency as advisory metadata; bind the local implementation to the actual control authority and document the divergence.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "把官方依赖当作需评审的元数据；本地绑定软件台账、安全构建和仓库控制，并记录偏离理由。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls2/.",
          "Verify the response SHA-256 equals 59F438759F8704D42D908FD3E9EF9D632BF2C2984A4F033713634B3AE616B64A.",
          "Locate Safeguard 2.6 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "CAS lists the network-infrastructure configuration process in Safeguard 4.2 as a dependency for software-library allowlisting."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-011",
      "safeguard_ids": [
        "3.2"
      ],
      "safeguard_titles": [
        {
          "id": "3.2",
          "en": "Establish and Maintain a Data Inventory",
          "zh": "数据清单"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls3/",
        "retrieved_at": "2026-07-30T16:25:28.667Z",
        "snapshot_sha256": "11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09",
        "locator": "Safeguard 3.2: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "3.2",
            "title": "Establish and Maintain a Data Inventory",
            "asset_class": "Data",
            "security_function": "Identify",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "GV11: Portion of Data Management Process Addressing Data Sensitivity GV12: Sensitive Data Inventory GV1: Enterprise Asset Inventory Date of the last update to the sensitive data inventory",
            "operations": "Use GV11 to map GV12 to sensitivity per the guidance in the data management process: Identify and enumerate items in the data set that have a mapping (M2) Identify and enumerate items in the data set that do not have a mapping (M3) Use GV1 and M2 from Operation 1 to map the data set to assets storing data: Identify and enumerate items that have complete and correct mapping to asset and sensitivity (M4) Identify and enumerate items that have partial mapping to sensitivity (M5) Use GV1 and M3 from Operation 2 to map the data set, without sensitivity mapping, to assets storing data: Identify and enumerate items that have partial mapping to assets (M6) Identify and enumerate items that have no mapping at all (M7) Compare current date to Input 4 and capture timeframe in months (M8)",
            "measures": "M1 = GV11 M2 = Count of sensitive data addressed in GV11 M3 = Count of sensitive data not addressed in GV11 M4 = Count of data with complete sensitivity and asset storage inventory M5 = Count of data with partial mapping to sensitivity M6 = Count of data with partial mapping to assets M7 = Count of data with no mapping to sensitivity or asset M8 = Timeframe since the last update to the sensitive data inventory in months M9 = Count of items in GV12",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M1 is 0, this Safeguard receives a failing score. The other metrics don't apply. If M9 is greater than 12 months, this Safeguard is scored at zero and receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Completeness of Sensitive Data Inventory",
                "content": "Metric | Percentage of data with complete information\nCalculation | M4 / M9"
              },
              {
                "heading": "Metrics / Completeness of Sensitive Data Inventory / Partial Completeness of Sensitive Data Inventory",
                "content": "Metric | Percentage of data with partial inventory\nCalculation | (M5 + M6) / M9"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "wrong-variable",
        "finding_en": "The age failure tests M9, the data-item count, instead of M8, the months since review.",
        "impact_en": "A large inventory can fail as though it were stale, while the intended freshness measure is ignored.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "3.2 的年龄失败条件检查 M9 数据条目数，而非 M8 复核距今天数或月数。",
        "impact_zh": "数据量越大越可能被误判陈旧，真正新鲜度变量反而未被使用。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Correct the local calculation only after a variable-lineage review, and retain the official token as an unresolved source finding.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "沿变量谱系修正本地新鲜度门槛，官方 M9 引用保留为未解决来源发现。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls3/.",
          "Verify the response SHA-256 equals 11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09.",
          "Locate Safeguard 3.2 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "The age failure tests M9, the data-item count, instead of M8, the months since review."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-012",
      "safeguard_ids": [
        "3.3"
      ],
      "safeguard_titles": [
        {
          "id": "3.3",
          "en": "Configure Data Access Control Lists",
          "zh": "数据访问权限"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls3/",
        "retrieved_at": "2026-07-30T16:25:28.667Z",
        "snapshot_sha256": "11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09",
        "locator": "Safeguard 3.3: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "3.3",
            "title": "Configure Data Access Control Lists",
            "asset_class": "Data",
            "security_function": "Protect",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "GV12: Sensitive Data Inventory GV1: Enterprise Asset Inventory GV3: Configuration Standard GV13: Portion of Data Management Process Capturing Data Owners GV14: Portion of Data Management Process Addressing Data Handling GV22: Inventory of Accounts",
            "operations": "Use the data management process, specifically GV13 and GV14, as guidelines to map user accounts to sensitive data in GV12: Identify and enumerate sensitive data correctly mapped to user accounts from GV22 (M1) Identify and enumerate sensitive data not correctly mapped to user accounts from GV22 (M2) For each enterprise asset in GV1 storing sensitive data, as outlined by GV12: Identify and enumerate all assets storing sensitive data (M3) Use GV3 to check and enumerate assets that are properly configured to only allow users as identified in Operation 1 (M4) Use GV3 to check and enumerate assets that are improperly configured to only allow users as identified in Operation 1 (M5)",
            "measures": "M1 = Count of sensitive data correctly mapped to user accounts per the data management process M2 = Count of sensitive data not correctly mapped to user accounts per the data management process M3 = Count of assets storing sensitive data M4 = Count of properly configured assets to support data access control M5 = Count of improperly configured assets to support data access control M6 = GV17 M7 = GV13 M8 = GV14",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If either M7 or M8 is 0, this Safeguard receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Completeness of User Access Control",
                "content": "Metric | Percentage of user accounts properly mapped to sensitive data\nCalculation | M1 / M6"
              },
              {
                "heading": "Metrics / Completeness of User Access Control / Properly Configured Assets",
                "content": "Metric | Percentage of assets properly configured to control access of sensitive data\nCalculation | M4 / M3"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "undefined-input",
        "finding_en": "M6 is assigned to GV17 although GV17 is not an input and denotes sensitive-data types elsewhere.",
        "impact_en": "The user-access numerator and denominator cannot be reproduced from the stated inputs.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "3.3 将 M6 赋给未列为输入的 GV17；GV17 在其他位置代表敏感数据类型。",
        "impact_zh": "用户访问分子与分母无法从声明输入复现。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Do not synthesize the missing input. Mark the official calculation non-reproducible and define the local data contract explicitly.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "不得虚构缺失输入；将官方计算标为不可复现，并在本地明确数据契约。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls3/.",
          "Verify the response SHA-256 equals 11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09.",
          "Locate Safeguard 3.3 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "M6 is assigned to GV17 although GV17 is not an input and denotes sensitive-data types elsewhere."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-013",
      "safeguard_ids": [
        "3.6"
      ],
      "safeguard_titles": [
        {
          "id": "3.6",
          "en": "Encrypt Data on End-User Devices",
          "zh": "终端全盘与数据加密"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls3/",
        "retrieved_at": "2026-07-30T16:25:28.667Z",
        "snapshot_sha256": "11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09",
        "locator": "Safeguard 3.6: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "3.6",
            "title": "Encrypt Data on End-User Devices",
            "asset_class": "Data",
            "security_function": "Protect",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "GV1: Enterprise Asset Inventory GV5: Authorized Software Inventory GV3: Configuration Standard",
            "operations": "For each asset in GV1, identify end-user devices: Enumerate the end-user devices (M1) Use GV5 to identify and enumerate the assets that have encryption software installed (M2) Use GV5 to identify and enumerate the assets without encryption software (M3) For each encryption software installed on assets (M2), use GV3 to determine whether the software is properly configured: Enumerate the encryption software that is properly configured (M4) Enumerate the encryption software that is improperly configured (M5)",
            "measures": "M1 = Count of approved end-user devices M2 = Count of approved end-user devices with encryption software installed M3 = Count of approved end-user devices without encryption software M4 = Count of properly configured end-user devices M5 = Count of improperly configured end-user devices",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": ""
              },
              {
                "heading": "Metrics / Installed Software Coverage",
                "content": "Metric | The percentage of approved mobile devices that are equipped with approved encryption software.\nCalculation | M2 / M1"
              },
              {
                "heading": "Metrics / Installed Software Coverage / Appropriately Configured Devices",
                "content": "Metric | The percentage of approved mobile devices equipped with approved encryption software that meet or exceed the approved configuration policy.\nCalculation | M4 / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "scope-drift",
        "finding_en": "The Safeguard and operations cover end-user devices, while the metric labels the population mobile devices.",
        "impact_en": "Desktop and laptop coverage can be silently lost by a literal implementation.",
        "confidence": {
          "level": "medium",
          "reason": "The source wording and variable lineage are directly observable; the implementation consequence depends on the adopter architecture or risk decision."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "Safeguard 与 Operations 指向终端设备，Metric 却把总体写成移动设备。",
        "impact_zh": "台式机和笔记本可能因字面导入从覆盖分母消失。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Define the denominator from the Safeguard scope and publish any narrower platform scope as an explicit local applicability decision.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "从 Safeguard 范围定义分母；任何缩窄到移动平台的决定都要作为本地适用性显式批准。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls3/.",
          "Verify the response SHA-256 equals 11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09.",
          "Locate Safeguard 3.6 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "The Safeguard and operations cover end-user devices, while the metric labels the population mobile devices."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-014",
      "safeguard_ids": [
        "3.11"
      ],
      "safeguard_titles": [
        {
          "id": "3.11",
          "en": "Encrypt Sensitive Data At Rest",
          "zh": "静态敏感数据加密"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls3/",
        "retrieved_at": "2026-07-30T16:25:28.667Z",
        "snapshot_sha256": "11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09",
        "locator": "Safeguard 3.11: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "3.11",
            "title": "Encrypt Sensitive Data At Rest",
            "asset_class": "Data",
            "security_function": "Protect",
            "implementation_groups": [
              2,
              3
            ],
            "inputs": "GV12: Sensitive Data Inventory GV4: Enterprise Network Architecture Documentation GV19: Enterprise Assets Storing Sensitive Data",
            "operations": "Use GV5 to identify and enumerate all encryption tools requiring secondary authentication systems (M1) Use GV12 and GV1 to identify and enumerate all enterprise assets storing sensitive data (GV19: M2) Compare the output of Operation 1 and Operation 2: Identify and enumerate assets with at least one encryption tool from M1 installed (M4) Identify and enumerate assets without at least one encryption tool from M1 installed (M5)",
            "measures": "M1 = Count of authorized encryption tools requiring secondary authentication systems M2 = Count of enterprise assets storing sensitive data M3 = Count of assets with at least one encryption tool installed M4 = Count of assets without at least one encryption tool installed",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": ""
              },
              {
                "heading": "Metrics / Coverage",
                "content": "Metric | The percentage of assets storing sensitive data covered by an encryption tool.\nCalculation | M3 / M2"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "measure-shift",
        "finding_en": "Operations reference GV5 and GV1 without listing them as inputs, produce M4/M5, and Measures relabel the same populations M3/M4.",
        "impact_en": "The published M3/M2 formula is not connected consistently to the stated operations.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "3.11 的 Operations 引用未列入 Inputs 的 GV5/GV1，并产生 M4/M5；Measures 又把同一总体改名为 M3/M4。",
        "impact_zh": "M3 / M2 公式无法一致连接到操作结果。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Create a variable lineage from input through operation, measure and metric; block scoring until each referenced variable has exactly one definition.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "为每个输入、操作、度量和指标建立唯一变量谱系，引用无法闭合前阻止评分。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls3/.",
          "Verify the response SHA-256 equals 11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09.",
          "Locate Safeguard 3.11 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "Operations reference GV5 and GV1 without listing them as inputs, produce M4/M5, and Measures relabel the same populations M3/M4."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-015",
      "safeguard_ids": [
        "4.4"
      ],
      "safeguard_titles": [
        {
          "id": "4.4",
          "en": "Implement and Manage a Firewall on Servers",
          "zh": "服务器主机防火墙"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls4/",
        "retrieved_at": "2026-07-30T16:25:29.565Z",
        "snapshot_sha256": "613D6086318545F0A7BA221AF501DC788ACDB3F79C3370D891E1D6EA2CF1190C",
        "locator": "Safeguard 4.4: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "4.4",
            "title": "Implement and Manage a Firewall on Servers",
            "asset_class": "Devices",
            "security_function": "Protect",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "GV1: Enterprise Asset Inventory GV5: Authorized Software Inventory GV3: Configuration Standard",
            "operations": "Identify and enumerate servers capable of hosting a firewall using GV1 (M1) Identify and enumerate applications capable of hosting a firewall using GV5 (M2) Using configuration standards GV3 to check if firewalls are properly configured: Enumerate servers from Operation 1 with properly configured firewalls (M3) Enumerate servers from Operation 1 with improperly configured firewalls (M4) Enumerate applications from Operation 2 with properly configured firewalls (M3) Enumerate applications from Operation 2 with improperly configured firewalls (M4)",
            "measures": "M1 = Count of servers enterprise assets capable of hosting a firewall M2 = Count of applications of hosting a firewall M3 = Count of servers with properly configured firewalls M4 = Count of servers with improperly configured firewalls M5 = Count of applications with properly configured firewalls M6 = Count of applications with improperly configured firewalls",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": ""
              },
              {
                "heading": "Metrics / Implementation of Firewalls",
                "content": "Metric | The percentage of properly configured firewalls within the enterprise\nCalculation | (M3 + M5) / (M1 + M2)"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "measure-shift",
        "finding_en": "Application firewall operations reuse M3/M4, while Measures and the metric expect M5/M6.",
        "impact_en": "The application portion of the formula lacks a reproducible operation.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "4.4 的应用防火墙 Operations 使用 M3/M4，而 Measures 与 Metric 期望 M5/M6。",
        "impact_zh": "应用部分的指标没有可复现的操作来源。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Create a variable lineage from input through operation, measure and metric; block scoring until each referenced variable has exactly one definition.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "固定每个操作输出的变量名；变量谱系闭合前不计算应用防火墙覆盖率。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls4/.",
          "Verify the response SHA-256 equals 613D6086318545F0A7BA221AF501DC788ACDB3F79C3370D891E1D6EA2CF1190C.",
          "Locate Safeguard 4.4 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "Application firewall operations reuse M3/M4, while Measures and the metric expect M5/M6."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-016",
      "safeguard_ids": [
        "4.5"
      ],
      "safeguard_titles": [
        {
          "id": "4.5",
          "en": "Implement and Manage a Firewall on End-User Devices",
          "zh": "终端主机防火墙"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls4/",
        "retrieved_at": "2026-07-30T16:25:29.565Z",
        "snapshot_sha256": "613D6086318545F0A7BA221AF501DC788ACDB3F79C3370D891E1D6EA2CF1190C",
        "locator": "Safeguard 4.5: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "4.5",
            "title": "Implement and Manage a Firewall on End-User Devices",
            "asset_class": "Devices",
            "security_function": "Protect",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "GV1: Enterprise Asset Inventory GV5: Authorized Software Inventory GV3: Configuration Standard",
            "operations": "Identify and enumerate end-user devices capable of hosting a firewall or a deny rule using GV1 (M1) Using configuration standards GV3 to check if firewalls or deny rules are properly configured on end-user devices: Enumerate assets from Operation 1 with properly configured firewalls or a configured default deny rule (M3) Enumerate assets from Operation 1 with improperly configured firewalls and lacking a configured default deny rule (M4)",
            "measures": "M1 = Count of end-user devices capable of hosting a firewall M2 = Count of end-user devices with a properly configured firewall or default deny rule M3 = Count of end-user devices with an improperly configured firewall and lacking a configured default deny rule",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": ""
              },
              {
                "heading": "Metrics / Coverage",
                "content": "Metric | The percentage of properly configured firewalls or deny rule on end-user devices\nCalculation | M2 / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "measure-shift",
        "finding_en": "Operations produce proper/improper endpoint firewall counts as M3/M4; Measures relabel them M2/M3.",
        "impact_en": "A tool cannot bind the published numerator to the published operation safely.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "4.5 的 Operations 把正确/错误终端防火墙数记为 M3/M4，Measures 改成 M2/M3。",
        "impact_zh": "指标分子无法安全绑定到发布的操作。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Create a variable lineage from input through operation, measure and metric; block scoring until each referenced variable has exactly one definition.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "明确一个正确配置分子和一个失败总体；官方错位原样保留，本地另建变量映射。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls4/.",
          "Verify the response SHA-256 equals 613D6086318545F0A7BA221AF501DC788ACDB3F79C3370D891E1D6EA2CF1190C.",
          "Locate Safeguard 4.5 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "Operations produce proper/improper endpoint firewall counts as M3/M4; Measures relabel them M2/M3."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-017",
      "safeguard_ids": [
        "4.7"
      ],
      "safeguard_titles": [
        {
          "id": "4.7",
          "en": "Manage Default Accounts on Enterprise Assets and Software",
          "zh": "默认账户"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls4/",
        "retrieved_at": "2026-07-30T16:25:29.565Z",
        "snapshot_sha256": "613D6086318545F0A7BA221AF501DC788ACDB3F79C3370D891E1D6EA2CF1190C",
        "locator": "Safeguard 4.7: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "4.7",
            "title": "Manage Default Accounts on Enterprise Assets and Software",
            "asset_class": "Users",
            "security_function": "Protect",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "GV1: Enterprise Asset Inventory GV5: Authorized Software Inventory GV20: Unique Password Policy",
            "operations": "Use GV5 to identify and enumerate authorized operating software, applications, and third-party software that contain default accounts (M1) Use GV1 to identify and enumerate assets with software from Operation 1, installed (M2) For each asset identified in Operation 2, enumerate default accounts (M3) Check if default accounts can be disabled: Enumerate accounts that are disabled (M4) Enumerate accounts that are enabled (M5) If accounts cannot be disabled, ensure to change default passwords according to GV20: the enterprise's unique password policy: Enumerate accounts with changed passwords (M6)",
            "measures": "M1 = Count of software that uses default accounts M2 = Count of assets with software installed that uses default accounts M3 = Count of default accounts identified M4 = Count of default accounts that have been disabled M5 = Count of default accounts that are enabled M6 = Count of enabled default accounts with changed passwords",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": ""
              },
              {
                "heading": "Metrics / Unusable Default Accounts",
                "content": "Metric | The percentage of default accounts that have been rendered unusable\nCalculation | M4 + M6 / M3"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "formula-precedence",
        "finding_en": "The formula is written M4 + M6 / M3 without grouping the two secured-account populations.",
        "impact_en": "Standard arithmetic precedence can produce a value greater than one; the intended expression needs explicit parentheses.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "4.7 公式写成 M4 + M6 / M3，未给两个安全账户总体加括号。",
        "impact_zh": "按标准运算优先级可得到超过 1 的结果。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Require (M4 + M6) / M3 only after confirming the intended populations and parentheses; do not infer the grouping silently in imported CIS text.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "确认预期总体后，本地显式写成 (M4 + M6) / M3；不能静默替 CIS 原文补括号。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls4/.",
          "Verify the response SHA-256 equals 613D6086318545F0A7BA221AF501DC788ACDB3F79C3370D891E1D6EA2CF1190C.",
          "Locate Safeguard 4.7 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "The formula is written M4 + M6 / M3 without grouping the two secured-account populations."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-018",
      "safeguard_ids": [
        "4.12"
      ],
      "safeguard_titles": [
        {
          "id": "4.12",
          "en": "Separate Enterprise Workspaces on Mobile End-User Devices",
          "zh": "移动端企业工作区隔离"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls4/",
        "retrieved_at": "2026-07-30T16:25:29.565Z",
        "snapshot_sha256": "613D6086318545F0A7BA221AF501DC788ACDB3F79C3370D891E1D6EA2CF1190C",
        "locator": "Safeguard 4.12: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "4.12",
            "title": "Separate Enterprise Workspaces on Mobile End-User Devices",
            "asset_class": "Data",
            "security_function": "Protect",
            "implementation_groups": [
              3
            ],
            "inputs": "GV1: Enterprise Asset Inventory GV5: Authorized Software Inventory GV3: Configuration Standard",
            "operations": "Use GV5 to identify and enumerate authorized mobile device management software (M1) Use GV1 to identify mobile devices capable of supporting mobile device management software (M2) Compare the output of Operations 1 and 2: Identify and enumerate mobile devices with authorized mobile device management software (M3) Identify and enumerate mobile devices without authorized mobile device management software (M4) Use GV3 to check configurations of mobile devices with mobile device management software: Identify and enumerate mobile devices with properly configured mobile device management software to separate enterprise workspace (M5) Identify and enumerate mobile devices with improperly configured mobile device management software (M6)",
            "measures": "M1 = Count of authorized mobile device management software M2 = Count of mobile devices capable of supporting mobile device management software M3 = Count of mobile devices with mobile device management software M4 = Count of mobile devices without mobile device management software M5 = Count of assets with properly configured mobile device management software M6 = Count of assets with improperly configured mobile device management software",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": ""
              },
              {
                "heading": "Compliance of Separation of Enterprise Workspace",
                "content": "Metric | The percentage of mobile devices with properly separated enterprise workspace.\nCalculation | M5 / M2"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "heading-structure-and-metric-depth",
        "finding_en": "The CAS page contains a Metrics h3 immediately followed by a peer Compliance of Separation of Enterprise Workspace h3 and a metric table with calculation M5 / M2. The metric exists; the heading structure caused the earlier extractor to leave the Metrics bucket empty. The ratio measures configured workspace coverage and does not exercise clipboard, sharing, backup, notification, screenshot, or other transfer paths.",
        "impact_en": "A heading-sensitive parser can falsely report a missing metric, while a literal coverage score can still overstate separation effectiveness.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "4.12 页面在 Metrics h3 后紧接同级“Compliance of Separation of Enterprise Workspace”h3，并在表格给出 M5 / M2；指标存在，旧解析器因标题层级把表格切出 Metrics。该比率只测配置覆盖，不测试剪贴板、分享、备份、通知、截图等路径。",
        "impact_zh": "依赖标题层级的解析器会误报指标缺失；照搬覆盖率仍会高估工作区隔离的运行有效性。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Parse the adjacent heading as the metric table and retain M5 / M2 as the official design-coverage ratio; add local path tests for copy, share, backup, notification and screenshot before claiming effective separation.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "解析相邻同级标题下的指标表，并保留 M5 / M2 作为官方设计覆盖率；本地增加复制、分享、备份、通知和截图的路径测试。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls4/.",
          "Verify the response SHA-256 equals 613D6086318545F0A7BA221AF501DC788ACDB3F79C3370D891E1D6EA2CF1190C.",
          "Locate Safeguard 4.12 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "The CAS page contains a Metrics h3 immediately followed by a peer Compliance of Separation of Enterprise Workspace h3 and a metric table with calculation M5 / M2. The metric exists; the heading structure caused the earlier extractor to leave the Metrics bucket empty. The ratio measures configured workspace coverage and does not exercise clipboard, sharing, backup, notification, screenshot, or other transfer paths."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-019",
      "safeguard_ids": [
        "5.1"
      ],
      "safeguard_titles": [
        {
          "id": "5.1",
          "en": "Establish and Maintain an Inventory of Accounts",
          "zh": "账户总账"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls5/",
        "retrieved_at": "2026-07-30T16:25:30.015Z",
        "snapshot_sha256": "067CD9797658BCF1080DAC4A01672E8CD9A550F6933CD3F3219369737E28A28A",
        "locator": "Safeguard 5.1: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "5.1",
            "title": "Establish and Maintain an Inventory of Accounts",
            "asset_class": "Users",
            "security_function": "Identify",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "GV5: Authorized Software Inventory GV22: Inventory of Accounts Date of last review of the inventory of accounts",
            "operations": "Check if the enterprise maintains an inventory of user and administrative accounts (Input 2): If the inventory exists, M1 = 1 If the inventory does not exist, M1 = 0 Using the inventory of accounts GV22, determine if the inventory captures the following elements: person's name, username, start/stop dates, and department: Each element is assigned a value of 1 if it exists and 0 if it does not. Total the number of elements that exist (M3). Using GV22, check each account for elements: person's name, username, start/stop dates, and department: Identify and enumerate accounts with all elements (M4) Identify and enumerate accounts missing or with incomplete elements (M5) Use GV5 to identify authentication systems or other software that manages accounts GV23. Using the output of Operation 4, enumerate all current user and administrative accounts throughout the enterprise (M6) Compare the output of Operation 5 with GV22: Identify and enumerate accounts that are supposed to be active/enabled (M7) Identify and enumerate accounts that are supposed to be disabled/removed (M8) Compare the current date to the date provided in Input 3 and enumerate the timeframe in months (M9)",
            "measures": "M1 = Does the account inventory exist (Output of Operation 1) M2 = Count of accounts in GV22 M3 = Count of elements provided in the inventory M4 = Count of accounts in inventory with complete information M5 = Count of accounts in inventory with missing or incomplete information M6 = Count of current accounts identified through Operation 5 M7 = Count of authorized accounts M8 = Count of unauthorized accounts M9 = Timeframe of the last update in months",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M1 is 0, this Safeguard receives a failing score, and other metrics don't apply. If M9 is greater than three, this Safeguard is measured at a 0 and receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Completeness of Inventory",
                "content": "Metric | The percentage of minimum elements included in the inventory.\nCalculation | M3 / 4\nMetric | The percentage of accounts with complete information.\nCalculation | M4 / 2"
              },
              {
                "heading": "Metrics / Completeness of Inventory / Accuracy of Inventory",
                "content": "Metric | The percentage of accurately listed accounts in the inventory.\nCalculation | M8 / M6"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "formula",
        "finding_en": "Account-record completeness is written M4 / 2 although M4 counts complete accounts and M2 counts inventory accounts.",
        "impact_en": "The result grows with inventory size and is not a percentage.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "5.1 把账户记录完整度写成 M4 / 2，分母常量 2 不是账户总体 M2。",
        "impact_zh": "结果随账户数量增长，不能表示百分比。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Use complete account records divided by all account inventory records for completeness, and report unauthorized accounts as an error rate rather than accuracy.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "本地用字段完整账户数除以全部账户台账记录，并明确空总体语义。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls5/.",
          "Verify the response SHA-256 equals 067CD9797658BCF1080DAC4A01672E8CD9A550F6933CD3F3219369737E28A28A.",
          "Locate Safeguard 5.1 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "Account-record completeness is written M4 / 2 although M4 counts complete accounts and M2 counts inventory accounts."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-020",
      "safeguard_ids": [
        "5.1"
      ],
      "safeguard_titles": [
        {
          "id": "5.1",
          "en": "Establish and Maintain an Inventory of Accounts",
          "zh": "账户总账"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls5/",
        "retrieved_at": "2026-07-30T16:25:30.015Z",
        "snapshot_sha256": "067CD9797658BCF1080DAC4A01672E8CD9A550F6933CD3F3219369737E28A28A",
        "locator": "Safeguard 5.1: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "5.1",
            "title": "Establish and Maintain an Inventory of Accounts",
            "asset_class": "Users",
            "security_function": "Identify",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "GV5: Authorized Software Inventory GV22: Inventory of Accounts Date of last review of the inventory of accounts",
            "operations": "Check if the enterprise maintains an inventory of user and administrative accounts (Input 2): If the inventory exists, M1 = 1 If the inventory does not exist, M1 = 0 Using the inventory of accounts GV22, determine if the inventory captures the following elements: person's name, username, start/stop dates, and department: Each element is assigned a value of 1 if it exists and 0 if it does not. Total the number of elements that exist (M3). Using GV22, check each account for elements: person's name, username, start/stop dates, and department: Identify and enumerate accounts with all elements (M4) Identify and enumerate accounts missing or with incomplete elements (M5) Use GV5 to identify authentication systems or other software that manages accounts GV23. Using the output of Operation 4, enumerate all current user and administrative accounts throughout the enterprise (M6) Compare the output of Operation 5 with GV22: Identify and enumerate accounts that are supposed to be active/enabled (M7) Identify and enumerate accounts that are supposed to be disabled/removed (M8) Compare the current date to the date provided in Input 3 and enumerate the timeframe in months (M9)",
            "measures": "M1 = Does the account inventory exist (Output of Operation 1) M2 = Count of accounts in GV22 M3 = Count of elements provided in the inventory M4 = Count of accounts in inventory with complete information M5 = Count of accounts in inventory with missing or incomplete information M6 = Count of current accounts identified through Operation 5 M7 = Count of authorized accounts M8 = Count of unauthorized accounts M9 = Timeframe of the last update in months",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M1 is 0, this Safeguard receives a failing score, and other metrics don't apply. If M9 is greater than three, this Safeguard is measured at a 0 and receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Completeness of Inventory",
                "content": "Metric | The percentage of minimum elements included in the inventory.\nCalculation | M3 / 4\nMetric | The percentage of accounts with complete information.\nCalculation | M4 / 2"
              },
              {
                "heading": "Metrics / Completeness of Inventory / Accuracy of Inventory",
                "content": "Metric | The percentage of accurately listed accounts in the inventory.\nCalculation | M8 / M6"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "reversed-outcome",
        "finding_en": "The accuracy metric uses unauthorized accounts M8 divided by discovered accounts M6.",
        "impact_en": "A worse unauthorized-account rate is labelled higher accuracy.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "5.1 把未授权账户 M8 / 已发现账户 M6 标成准确度。",
        "impact_zh": "未授权账户越多，“准确度”反而越高。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Use complete account records divided by all account inventory records for completeness, and report unauthorized accounts as an error rate rather than accuracy.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "把该比率标作错误率；准确度需使用已授权且字段正确的账户总体。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls5/.",
          "Verify the response SHA-256 equals 067CD9797658BCF1080DAC4A01672E8CD9A550F6933CD3F3219369737E28A28A.",
          "Locate Safeguard 5.1 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "The accuracy metric uses unauthorized accounts M8 divided by discovered accounts M6."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-021",
      "safeguard_ids": [
        "5.5"
      ],
      "safeguard_titles": [
        {
          "id": "5.5",
          "en": "Establish and Maintain an Inventory of Service Accounts",
          "zh": "服务账户总账"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls5/",
        "retrieved_at": "2026-07-30T16:25:30.015Z",
        "snapshot_sha256": "067CD9797658BCF1080DAC4A01672E8CD9A550F6933CD3F3219369737E28A28A",
        "locator": "Safeguard 5.5: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "5.5",
            "title": "Establish and Maintain an Inventory of Service Accounts",
            "asset_class": "Users",
            "security_function": "Identify",
            "implementation_groups": [
              2,
              3
            ],
            "inputs": "GV23: Inventory of Authentication and Authorization Systems Inventory of Service Accounts Date of last review of the inventory of service accounts",
            "operations": "Check if the enterprise maintains an inventory of service accounts (Input 2): If the inventory exists, set M1 = 1. If the inventory does not exist, set M1 = 0. Using the inventory of accounts (Input 2), determine if the inventory captures the following elements: department owner, review date, and purpose: Each element is assigned a value of 1 if it exists and 0 if it does not. Total the number of elements that exist (M3). Using Input 2, check each account for elements: department owner, review date, and purpose: Identify and enumerate accounts with all elements (M4). Identify and enumerate accounts missing or with incomplete elements (M5). Use GV23 to identify authentication systems or other software that manages service accounts. Using the output of Operation 4, enumerate all current service accounts throughout the enterprise (M6). Compare the output of Operation 5 with Input 2: Identify and enumerate accounts that are supposed to be active/enabled (M7). Identify and enumerate accounts that are supposed to be disabled/removed (M8). Compare the current date to the date provided in Input 3 and enumerate the timeframe in months (M9).",
            "measures": "M1 = Does the account inventory exist (Output of Operation 1) M2 = Count of accounts in Input 2 M3 = Count of elements provided in inventory M4 = Count of accounts in inventory with complete information M5 = Count of accounts in inventory with missing or incomplete information M6 = Count of current service accounts identified through Operation 5 M7 = Count of authorized accounts M8 = Count of unauthorized accounts M9 = Timeframe of last update in months",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M1 is 0, this Safeguard receives a failing score and other metrics don't apply. If M9 is greater than three, this Safeguard is measured at a 0 and receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Completeness of Inventory",
                "content": "Metric | The percentage of minimum elements included in the inventory.\nCalculation | M3 / 4\nMetric | The percentage of accounts with complete information.\nCalculation | M4 / 2"
              },
              {
                "heading": "Metrics / Completeness of Inventory / Accuracy of Inventory",
                "content": "Metric | The percentage of accurately listed accounts in the inventory.\nCalculation | M8 / M6"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "formula-family",
        "finding_en": "Three required service-account fields are divided by four, complete accounts are divided by two, and unauthorized accounts are labelled accuracy.",
        "impact_en": "All three published inventory scores require reconstruction.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "5.5 的三组公式把三个必填字段除以 4、完整账户除以 2，并把未授权账户率称为准确度。",
        "impact_zh": "三个台账分数都无法直接用于决策。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Decompose the family into separate field-completeness and authorization outcomes, each with its own stable denominator.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "把字段完整性和授权状态拆为独立结果，各自使用稳定账户分母并设置空总体规则。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls5/.",
          "Verify the response SHA-256 equals 067CD9797658BCF1080DAC4A01672E8CD9A550F6933CD3F3219369737E28A28A.",
          "Locate Safeguard 5.5 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "Three required service-account fields are divided by four, complete accounts are divided by two, and unauthorized accounts are labelled accuracy."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-022",
      "safeguard_ids": [
        "6.2"
      ],
      "safeguard_titles": [
        {
          "id": "6.2",
          "en": "Establish an Access Revoking Process",
          "zh": "访问撤销流程"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls6/",
        "retrieved_at": "2026-07-30T16:25:30.470Z",
        "snapshot_sha256": "F05309C876FA1A941F5B41071EE4764DAA9848B4EB967755B390547FE1F078C5",
        "locator": "Safeguard 6.2: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "6.2",
            "title": "Establish an Access Revoking Process",
            "asset_class": "Documentation",
            "security_function": "Govern",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "Enterprise process for revoking access to enterprise assets",
            "operations": "Check to see if Input 1 exists: If the enterprise has an access revoking process, set M1 = 1. If the enterprise does not have an access revoking process, set M1 = 0. Using Input 1, check to see if the process includes, at a minimum, a way to revoke access upon termination, rights revocation, and role change of a user: For each element that is included, assign a value of 1. Sum the value of the elements included (M2).",
            "measures": "M1 = Output of Operation 1 M2 = Count of elements included in the access revoking process",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M1 is 0, the Safeguard receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Completeness of Process",
                "content": "Metric | The percentage of elements included in the access granting process\nCalculation | M2 / 3"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "label-drift",
        "finding_en": "The revocation-process metric is labelled completeness of the access granting process.",
        "impact_en": "Assessment exports can misidentify evidence and ownership for revocation.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "6.2 的撤权流程指标被标成访问授予流程完整度。",
        "impact_zh": "导出证据可能被分配给错误流程与责任人。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Keep metric identity and owner tied to the Safeguard action; correct only the local export label.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "按 Safeguard 行为保持指标身份和责任人，只修正本地展示标签并保留官方标签证据。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls6/.",
          "Verify the response SHA-256 equals F05309C876FA1A941F5B41071EE4764DAA9848B4EB967755B390547FE1F078C5.",
          "Locate Safeguard 6.2 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "The revocation-process metric is labelled completeness of the access granting process."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-023",
      "safeguard_ids": [
        "7.4"
      ],
      "safeguard_titles": [
        {
          "id": "7.4",
          "en": "Perform Automated Application Patch Management",
          "zh": "应用自动补丁"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls7/",
        "retrieved_at": "2026-07-30T16:25:31.916Z",
        "snapshot_sha256": "BA2036413BBF89630CCF02B4B304353CB97FCCEB11F22AD1F95FB6408A06830B",
        "locator": "Safeguard 7.4: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "7.4",
            "title": "Perform Automated Application Patch Management",
            "asset_class": "Software",
            "security_function": "Protect",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "GV5: Authorized Software Inventory GV1: Enterprise Asset Inventory Authoritative source of information indicating version details by product GV3: Configuration Standard GV24: Authorized Automated Patch Management Software",
            "operations": "Use GV5 to identify authorized applications within the enterprise. Use GV1 and the output of Operation 1 to identify the applications currently running on each asset (M1). For each asset, compare the version of the application to that listed in GV3: Identify and enumerate applications that are up to date (M2). Identify and enumerate applications that are not up to date (M3). For each application identified in Operation 2.2, determine whether there is a documented exception: Identify and enumerate applications with a documented exception (M4). Identify and enumerate applications without a documented exception (M5). Compare GV24 and Operation 1: Identify and enumerate applications covered by at least one automated patch management software (M7). Identify and enumerate applications not covered by at least one automated patch management software (M8). Check configurations of automated patch management software GV24 using GV3: Identify and enumerate those configured to run every 30 days or less (M9). Identify and enumerate those not configured to run every 30 days or less (M10).",
            "measures": "M1 = Count of authorized applications installed on an asset. M2 = Count of up-to-date applications installed on an asset. M3 = Count of applications installed on an asset that is not up to date. M4 = Count of not up to date applications with a documented exception. M5 = Count of not up to date applications without a documented exception. M6 = Count of GV24 authorized automated patch management software. M7 = Count of applications covered by at least one automated patch management software. M8 = Count of applications not covered by at least one automated patch management software. M9 = Count of automated patch management software properly configured to run every 30 days or less. M10 = Count of automated patch management software not properly configured to run every 30 days.",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": ""
              },
              {
                "heading": "Metrics / Update Effectiveness (Per Asset)",
                "content": "Metric | The percent of applications on an asset that are up to date\nCalculation | (M2 + M4) / M1"
              },
              {
                "heading": "Metrics / Update Effectiveness (Per Asset) / Update Effectiveness (Organizational)",
                "content": "Calculate the organizational metric by averaging the asset scores."
              },
              {
                "heading": "Metrics / Update Effectiveness (Per Asset) / Update Effectiveness (Organizational) / Coverage of Automation",
                "content": "Metric | The percent of operating systems covered by at least one automated patch management software.\nCalculation | M7 / M1\n1 | "
              },
              {
                "heading": "Metrics / Update Effectiveness (Per Asset) / Update Effectiveness (Organizational) / Coverage of Automation / Scan Compliance",
                "content": "Metric | The percent of automated patch management software configured to run every 30 days or less.\nCalculation | M9 / M6"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "copy-error",
        "finding_en": "Application patch coverage is described as operating-system coverage and the table contains a stray row.",
        "impact_en": "Generated reports can attach an application result to the wrong population.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "7.4 的应用补丁覆盖文字写成操作系统覆盖，表格还含多余行。",
        "impact_zh": "生成报告可能把应用结果挂到错误总体。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Preserve the official text in the source ledger, correct the local report label, and test the intended population explicitly.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "官方原文保留在账本；本地展示纠正为应用总体，并用应用补丁负控制验证。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls7/.",
          "Verify the response SHA-256 equals BA2036413BBF89630CCF02B4B304353CB97FCCEB11F22AD1F95FB6408A06830B.",
          "Locate Safeguard 7.4 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "Application patch coverage is described as operating-system coverage and the table contains a stray row."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-024",
      "safeguard_ids": [
        "7.7"
      ],
      "safeguard_titles": [
        {
          "id": "7.7",
          "en": "Remediate Detected Vulnerabilities",
          "zh": "漏洞修复与闭环"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls7/",
        "retrieved_at": "2026-07-30T16:25:31.916Z",
        "snapshot_sha256": "BA2036413BBF89630CCF02B4B304353CB97FCCEB11F22AD1F95FB6408A06830B",
        "locator": "Safeguard 7.7: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "7.7",
            "title": "Remediate Detected Vulnerabilities",
            "asset_class": "Software",
            "security_function": "Respond",
            "implementation_groups": [
              2,
              3
            ],
            "inputs": "GV1: Enterprise Asset Inventory Current vulnerability scan Previous vulnerability scan Date of current vulnerability scan Date of the previous vulnerability scan",
            "operations": "For each asset in GV1, compare Inputs 2 and 3: Identify and enumerate assets listed with the same vulnerability on both scans (M2) Identify and enumerate assets previously found in Input 3 that are no longer listed in Input 2 with the same vulnerability (M3) Compare Inputs 4 and 5 and capture the timeframe between scans in days (M4)",
            "measures": "M1 = Count of vulnerabilities identified in Input 3 M2 = Count of unremediated vulnerabilities M3 = Count of remediated vulnerabilities M4 = Timeframe in between scans",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": ""
              },
              {
                "heading": "Metrics / Remediation",
                "content": "Metric | The percentage of remediated vulnerabilities\nCalculation | M3 / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "unsafe-assumption",
        "finding_en": "CAS assumes a finding absent from the newest scan is remediated.",
        "impact_en": "Asset disappearance, credential failure, scope change, or scanner failure can be credited as a fix.",
        "confidence": {
          "level": "medium",
          "reason": "The source wording and variable lineage are directly observable; the implementation consequence depends on the adopter architecture or risk decision."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "7.7 假设最新扫描中消失的漏洞已经修复。",
        "impact_zh": "资产消失、凭据失败、范围变化或扫描器故障都可能被误记为修复。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Require stable object identity plus a successful retest or approved disposition; scanner silence is an unknown result.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "以稳定资产与发现身份关联成功复测或批准处置；扫描沉默记录为未知。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls7/.",
          "Verify the response SHA-256 equals BA2036413BBF89630CCF02B4B304353CB97FCCEB11F22AD1F95FB6408A06830B.",
          "Locate Safeguard 7.7 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "CAS assumes a finding absent from the newest scan is remediated."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-025",
      "safeguard_ids": [
        "8.4"
      ],
      "safeguard_titles": [
        {
          "id": "8.4",
          "en": "Standardize Time Synchronization",
          "zh": "时间同步"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls8/",
        "retrieved_at": "2026-07-30T16:25:43.952Z",
        "snapshot_sha256": "BB5C01E764D3A2C232D06D1F839F90311343D93E4A858CB123E6D9911B5A4DC4",
        "locator": "Safeguard 8.4: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "8.4",
            "title": "Standardize Time Synchronization",
            "asset_class": "Network",
            "security_function": "Protect",
            "implementation_groups": [
              2,
              3
            ],
            "inputs": "GV27: Assets Capable of Supporting Logging List of approved network time sources/NTP servers",
            "operations": "Using GV27, identify and enumerate assets capable of supporting time synchronization (M1): Check the configurations of the assets identified in Operation 1: Identify and enumerate the assets configured using at least two approved time sources from Input 2 (M2) Identify and enumerate the assets configured using time sources not on the approved list (M3) Identify and enumerate the assets not configured using time sources (M4)",
            "measures": "M1 = Count of logging-capable assets that support time synchronization M2 = Count of properly configured assets using at least two approved time sources M3 = Count of assets configured using non-approved time sources M4 = Count of assets not configured to use time sources",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": ""
              },
              {
                "heading": "Metrics / NTP Compliance Coverage",
                "content": "Metric | The percentage of assets properly configured with at least two approved synchronized time sources\nCalculation | M2 / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "official-surface-drift",
        "finding_en": "The current Navigator/core guide classify 8.4 as Data while CAS classifies it as Network.",
        "impact_en": "Asset-class filters can assign time synchronization to different owners or omit eligible assets.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "Navigator/核心指南把 8.4 归 Data，CAS 归 Network。",
        "impact_zh": "按 Asset Class 过滤可能把时间同步交给不同责任人或漏掉资产。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Pin each official surface separately, choose one declared authority per imported field, and report the disagreement instead of merging it silently.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "分别固定各表面，并为导入字段声明权威来源；分歧作为来源漂移保留。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls8/.",
          "Verify the response SHA-256 equals BB5C01E764D3A2C232D06D1F839F90311343D93E4A858CB123E6D9911B5A4DC4.",
          "Locate Safeguard 8.4 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "The current Navigator/core guide classify 8.4 as Data while CAS classifies it as Network."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-026",
      "safeguard_ids": [
        "8.5"
      ],
      "safeguard_titles": [
        {
          "id": "8.5",
          "en": "Collect Detailed Audit Logs",
          "zh": "详细审计字段"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls8/",
        "retrieved_at": "2026-07-30T16:25:43.952Z",
        "snapshot_sha256": "BB5C01E764D3A2C232D06D1F839F90311343D93E4A858CB123E6D9911B5A4DC4",
        "locator": "Safeguard 8.5: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "8.5",
            "title": "Collect Detailed Audit Logs",
            "asset_class": "Data",
            "security_function": "Detect",
            "implementation_groups": [
              2,
              3
            ],
            "inputs": "GV18: Enterprise Assets Storing, Processing, and Transmitting Sensitive Data GV26: Enterprise's Audit Log Management Process GV3: Configuration Standard",
            "operations": "Review GV26 for detailed logging requirements such as event source, date, username, timestamp, source addresses, and destination addresses. For each detailed logging requirement included, assign a value of 1. Sum all requirements included. (M2) For each asset in GV18 check configuration using GV3 as a guide Identify and enumerate assets properly configured to collect detailed logging requirements (M3) Identify and enumerate assets not properly configured to collect detailed logging requirements (M4)",
            "measures": "M1 = Count of assets capable of supporting logging GV27 M2 = Count of detailed logging requirements included in the log management process M3 = Count of assets properly configured to collect detailed logs M4 = Count of assets not properly configured to collect detailed logs",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": ""
              },
              {
                "heading": "Metrics / Completeness of Process",
                "content": "Metric | The percentage of detailed logging requirements included in the logging management process\nCalculation | M2 / 6"
              },
              {
                "heading": "Metrics / Completeness of Process / Logging Coverage",
                "content": "Metric | The percentage of assets properly configured to collect detailed logs\nCalculation | M3 / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "denominator-drift",
        "finding_en": "The Safeguard targets sensitive-data assets, but M1 is the broader GV27 logging-capable population and is not listed as an input.",
        "impact_en": "Coverage can be diluted or made irreproducible instead of measuring the intended sensitive population.",
        "confidence": {
          "level": "medium",
          "reason": "The source wording and variable lineage are directly observable; the implementation consequence depends on the adopter architecture or risk decision."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "8.5 目标是敏感数据资产，M1 却引用更宽的 GV27 可日志总体且 GV27 未列入 Inputs。",
        "impact_zh": "覆盖率可能被稀释，也无法由声明输入复现。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Define one eligible population before measurement and reject referenced global variables that are absent from Inputs.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "先定义敏感数据资产分母；缺失输入不补造，无法闭合的官方公式停止自动化。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls8/.",
          "Verify the response SHA-256 equals BB5C01E764D3A2C232D06D1F839F90311343D93E4A858CB123E6D9911B5A4DC4.",
          "Locate Safeguard 8.5 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "The Safeguard targets sensitive-data assets, but M1 is the broader GV27 logging-capable population and is not listed as an input."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-027",
      "safeguard_ids": [
        "9.1"
      ],
      "safeguard_titles": [
        {
          "id": "9.1",
          "en": "Ensure Use of Only Fully Supported Browsers and Email Clients",
          "zh": "受支持的浏览器与邮件客户端"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls9/",
        "retrieved_at": "2026-07-30T16:25:45.071Z",
        "snapshot_sha256": "893B95999A6ACDC28F3DE11419EF6E6640E491BA628EA37586763E76C0FF99C7",
        "locator": "Safeguard 9.1: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "9.1",
            "title": "Ensure Use of Only Fully Supported Browsers and Email Clients",
            "asset_class": "Software",
            "security_function": "Protect",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "GV5: Authorized Software Inventory Authoritative source of information indicating supported/unsupported details by product",
            "operations": "Use GV5 to identify and enumerate web browser and email client software (M1) Compare each software identified in Operation 1 to Input 2 Identify and enumerate software labeled as \"supported\" that is currently supported (M2) Identify and enumerate software labeled as \"supported\" that is currently unsupported (M3) Identify and enumerate software labeled as \"unsupported\" that is currently unsupported (M4) Identify and enumerate software labeled as \"unsupported\" that is currently supported (M5)",
            "measures": "M1 = Count of authorized web browser and email client software M2 = Count of software labeled as \"supported\" and currently supported M3 = Count of software labeled as \"supported\" and currently unsupported M4 = Count of software labeled as \"supported\" and currently unsupported M5 = Count of software labeled as \"supported\" and currently supported",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": ""
              },
              {
                "heading": "Metrics / Percentage of Unsupported Web Browser/Email Client Software in Use",
                "content": "Metric | The percentage of unsupported web browser and email client software in use\nCalculation | (M3 + M4) / M1"
              },
              {
                "heading": "Metrics / Percentage of Unsupported Web Browser/Email Client Software in Use / Rate of False Positives",
                "content": "Metric | The percentage of authorized web browser and email client software labeled as \"supported\" but found to be unsupported\nCalculation | M3 / M1"
              },
              {
                "heading": "Metrics / Percentage of Unsupported Web Browser/Email Client Software in Use / Rate of False Positives / Rate of False Negatives",
                "content": "Metric | The percentage of authorized web browser and email client software labeled as \"unsupported\" but found to be supported\nCalculation | M5 / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "duplicate-definition",
        "finding_en": "M4 and M5 repeat the supported/unsupported definitions of other measures instead of preserving the four classification outcomes.",
        "impact_en": "The false-positive and false-negative metrics cannot be derived consistently.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "9.1 的 M4、M5 重复其他 supported/unsupported 定义，没有保留四种分类结果。",
        "impact_zh": "假阳性与假阴性指标无法一致推导。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Preserve the duplicate official definitions, block automatic scoring, and define distinct pass and fail populations locally.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "冻结重复定义，分别建立支持/不支持与正确/错误判定的四个本地总体。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls9/.",
          "Verify the response SHA-256 equals 893B95999A6ACDC28F3DE11419EF6E6640E491BA628EA37586763E76C0FF99C7.",
          "Locate Safeguard 9.1 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "M4 and M5 repeat the supported/unsupported definitions of other measures instead of preserving the four classification outcomes."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-028",
      "safeguard_ids": [
        "9.4"
      ],
      "safeguard_titles": [
        {
          "id": "9.4",
          "en": "Restrict Unnecessary or Unauthorized Browser and Email Client Extensions",
          "zh": "浏览器与邮件扩展"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls9/",
        "retrieved_at": "2026-07-30T16:25:45.071Z",
        "snapshot_sha256": "893B95999A6ACDC28F3DE11419EF6E6640E491BA628EA37586763E76C0FF99C7",
        "locator": "Safeguard 9.4: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "9.4",
            "title": "Restrict Unnecessary or Unauthorized Browser and Email Client Extensions",
            "asset_class": "Software",
            "security_function": "Protect",
            "implementation_groups": [
              2,
              3
            ],
            "inputs": "GV1: Enterprise Asset Inventory GV5: Authorized Software Inventory",
            "operations": "Use GV1 to identify and enumerate assets subject to browser/email plugin restrictions (M1) Use GV5 to identify authorized browser and email plugins For each asset listed in Operation 1, collect the list of installed browser plugins and compare to the output of Operation 2 Identify and enumerate assets with only authorized browser plugins installed or enabled (M2) Identify and enumerate assets with one or more unauthorized browser plugins installed or enabled (M3) For each asset listed in Operation 1, collect the list of installed email plugins and compare to the output of Operation 2 Identify and enumerate assets with only authorized email plugins installed or enabled (M4) Identify and enumerate assets with one or more unauthorized browser plugins installed or enabled (M5)",
            "measures": "M1 = Count of assets subject to browser/email plugin restrictions M2 = Count of assets with only authorized browser plugins installed or enabled M3 = Count of assets with unauthorized browser plugins installed or enabled M4 = Count of assets with only authorized email plugins installed or enabled M5 = Count of assets with unauthorized email plugins installed or enabled",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": ""
              },
              {
                "heading": "Metrics / Browser Plugin Enforcement Quality",
                "content": "Metric | The percentage of assets compliant with authorized browser plugins\nCalculation | M2 / M1"
              },
              {
                "heading": "Metrics / Browser Plugin Enforcement Quality / Email Client Plugin Enforcement Quality",
                "content": "Metric | The percentage of assets compliant with authorized email plugins\nCalculation | M4 / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "official-surface-drift",
        "finding_en": "Navigator uses the non-core asset class Applications; the core guide and CAS use Software.",
        "impact_en": "An asset-class-only GRC import can create a one-item orphan class.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "Navigator 将 9.4 归入非核心 Applications，核心指南与 CAS 使用 Software。",
        "impact_zh": "仅按资产类别导入会产生孤立类别。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Pin each official surface separately, choose one declared authority per imported field, and report the disagreement instead of merging it silently.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "以 Safeguard ID 为身份，声明展示 Asset Class 的选定来源并保留表面分歧。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls9/.",
          "Verify the response SHA-256 equals 893B95999A6ACDC28F3DE11419EF6E6640E491BA628EA37586763E76C0FF99C7.",
          "Locate Safeguard 9.4 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "Navigator uses the non-core asset class Applications; the core guide and CAS use Software."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-029",
      "safeguard_ids": [
        "9.5"
      ],
      "safeguard_titles": [
        {
          "id": "9.5",
          "en": "Implement DMARC",
          "zh": "DMARC、SPF 与 DKIM"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls9/",
        "retrieved_at": "2026-07-30T16:25:45.071Z",
        "snapshot_sha256": "893B95999A6ACDC28F3DE11419EF6E6640E491BA628EA37586763E76C0FF99C7",
        "locator": "Safeguard 9.5: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "9.5",
            "title": "Implement DMARC",
            "asset_class": "Network",
            "security_function": "Protect",
            "implementation_groups": [
              2,
              3
            ],
            "inputs": "DMARC Policy TXT record published in DNS The Mail Transfer Agent used by the enterprise The Mail User Agent used by the enterprise",
            "operations": "Check if enterprise has a DMARC policy If the enterprise has a DMARC policy, M1 = 1 If the enterprise does not have a DMARC policy, M1 = 0 Examine Input 2 for a value indicative of the use of DMARC If a value for DMARC is identified, M2 = 1 If a value for DMARC is not identified, M2 = 0 Examine Input 2 for a value indicative of the use of SPF If a value for SPF is identified, M3 = 1 If a value for SPF is not identified, M3 = 0 Examine Input 2 for a value indicative of the use of DKIM If a value for DKIM is identified, M4 = 1 If a value for DKIM is not identified, M4 = 0 Check if enterprise uses a Mail Transfer Agent If the enterprise uses a Mail Transfer Agent, M5 = 1 If the enterprise does not use a Mail Transfer Agent, M5 = 1 Check if enterprise uses a Mail User Agent If the enterprise uses a Mail User Agent, M6 = 1 If the enterprise does not use a Mail User Agent, M6 = 1",
            "measures": "M1 = Output of Operation 1 M2 = Output of Operation 2 M3 = Output of Operation 3 M4 = Output of Operation 4 M5 = Output of Operation 5 M6 = Output of Operation 6",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": ""
              },
              {
                "heading": "Metrics / DMARC Usage",
                "content": "Metric | Usage and configuration of DMARC/SPF/DKIM\nCalculation | (M1 + M2 + M3 + M4 + M5 + M6) / 6"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "operation-error",
        "finding_en": "DMARC, SPF, and DKIM are searched in the mail-agent input rather than the DNS-policy input, and both uses/does-not-use branches for MTA and MUA set the value to one.",
        "impact_en": "The six-part score can award points independent of actual mail authentication.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "9.5 在邮件代理输入中搜索 DMARC/SPF/DKIM，而非 DNS 策略输入；MTA/MUA 的使用与不使用分支都赋值 1。",
        "impact_zh": "六项得分可能与真实邮件认证无关。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Trace every searched token to the correct input object and require both positive and negative fixtures before scoring.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "让 DNS 记录只从 DNS 输入读取，并为 MTA/MUA 建立互斥正负夹具后再评分。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls9/.",
          "Verify the response SHA-256 equals 893B95999A6ACDC28F3DE11419EF6E6640E491BA628EA37586763E76C0FF99C7.",
          "Locate Safeguard 9.5 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "DMARC, SPF, and DKIM are searched in the mail-agent input rather than the DNS-policy input, and both uses/does-not-use branches for MTA and MUA set the value to one."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-030",
      "safeguard_ids": [
        "11.1"
      ],
      "safeguard_titles": [
        {
          "id": "11.1",
          "en": "Establish and Maintain a Data Recovery Process",
          "zh": "数据恢复流程"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls11/",
        "retrieved_at": "2026-07-30T16:25:47.206Z",
        "snapshot_sha256": "64B9FC7DBD72CA64F77263A3253BCCD64F658CFD626A18DD543020FB8171C94F",
        "locator": "Safeguard 11.1: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "11.1",
            "title": "Establish and Maintain a Data Recovery Process",
            "asset_class": "Documentation",
            "security_function": "Govern",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "Data Recovery Process for the enterprise Date of last update to the Data Recovery Process",
            "operations": "Check if the enterprise has a data recovery process Input 1 If so, M1 = 1 If not, M1 = 0 Examine the enterprise's data recovery process and determine if it addresses, at a minimum, the scope of data recovery activities, recovery prioritization, and the security of backup data For each element included within the process, assign the element a value of 1. M2 = sum of all the values. Compare the date of the last update to the data recovery process to the curren date and capture the timeframe in months (M3)",
            "measures": "M1 = Output of Operation 1 M2 = Sum of elements included in the data recovery process M3 = Timeframe in months of the last update to the data recovery process",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M1 is 0, the Safeguard receives a failing score. The other metrics don't apply. If M3 is greater than twelve, this Safeguard is measured at a 0 and receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Completeness",
                "content": "Metric | The percentage of elements included in the data recovery process\nCalculation | M2 / M3"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "formula",
        "finding_en": "Process completeness is calculated as component count M2 divided by review age in months M3.",
        "impact_en": "The score changes with calendar age and can divide by zero instead of measuring three required components.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "11.1 将流程组件数 M2 除以复核距今月数 M3。",
        "impact_zh": "分数随时间变化、可能除零，不能测量三个必需组件。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Score the three named process components against three and evaluate review age as a separate freshness gate; never divide component count by months.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "组件完整度按 3 个必需项单独计分，新鲜度作为独立时间门槛。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls11/.",
          "Verify the response SHA-256 equals 64B9FC7DBD72CA64F77263A3253BCCD64F658CFD626A18DD543020FB8171C94F.",
          "Locate Safeguard 11.1 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "Process completeness is calculated as component count M2 divided by review age in months M3."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-031",
      "safeguard_ids": [
        "12.2"
      ],
      "safeguard_titles": [
        {
          "id": "12.2",
          "en": "Establish and Maintain a Secure Network Architecture",
          "zh": "安全网络架构"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls12/",
        "retrieved_at": "2026-07-30T16:25:48.241Z",
        "snapshot_sha256": "B86C7314F9857EE4AFD9ACAD5661B3A82B1F8B43C6C0D91165DE0B14B6531E53",
        "locator": "Safeguard 12.2: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "12.2",
            "title": "Establish and Maintain a Secure Network Architecture",
            "asset_class": "Network",
            "security_function": "Protect",
            "implementation_groups": [
              2,
              3
            ],
            "inputs": "GV4: Enterprise Network Architecture Documentation GV5: Authorized Software Inventory",
            "operations": "Use the network architecture GV4 to identify and enumerate the segments within the enterprise network GV36 (M1) For each network segment identified in Operation 1, attempt to connect an unauthorized device Identify and enumerate segments that allow you to connect unauthorized devices (M2) Identify and enumerate segments that do not allow you to connect unauthorized devices (M3) Use GV5 to identify authorized availability monitoring software For each network segment identified in Operation 1, determine whether an authorized availability monitoring software from Operation 3 covers the segment Identify and enumerate segments that are covered by availability monitoring software (M4) Identify and enumerate segments that are not covered by availability monitoring software (M5)",
            "measures": "M1 = Count of network segments within the enterprise M2 = Count of segments not compliant with least privilege M3 = Count of segments compliant with least privilege M4 = Count of segments monitored for availability M5 = Count of segments not monitored for availability",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": ""
              },
              {
                "heading": "Metrics / Segmentation",
                "content": "Metric | If M1 is equal to 1, this metric is measured at a 0. Subsequent metrics can still be assessed.\nCalculation | If M1 <= 1, Fail or If M1 >= 1, Pass"
              },
              {
                "heading": "Metrics / Segmentation / Least Privilege",
                "content": "Metric | The percentage of network segments implementing least privilege\nCalculation | M3 / M1"
              },
              {
                "heading": "Metrics / Segmentation / Least Privilege / Availability",
                "content": "Metric | The percentage of network segments monitored for network availability\nCalculation | M4 / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "contradiction",
        "finding_en": "One network segment is covered by both the fail condition M1 <= 1 and pass condition M1 >= 1.",
        "impact_en": "The same architecture has two possible results before least-privilege or availability evidence is considered.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "12.2 的 M1 <= 1 失败条件与 M1 >= 1 通过条件在 1 个网段处重叠。",
        "impact_zh": "同一架构在未检查最小权限或可用性前可同时通过和失败。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Do not automate the contradictory branch. Define one positive state, one failure state, and a negative test against the same object population.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "不自动执行矛盾分支；本地定义互斥状态，并以同一网络总体做正负测试。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls12/.",
          "Verify the response SHA-256 equals B86C7314F9857EE4AFD9ACAD5661B3A82B1F8B43C6C0D91165DE0B14B6531E53.",
          "Locate Safeguard 12.2 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "One network segment is covered by both the fail condition M1 <= 1 and pass condition M1 >= 1."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-032",
      "safeguard_ids": [
        "12.5"
      ],
      "safeguard_titles": [
        {
          "id": "12.5",
          "en": "Centralize Network Authentication, Authorization, and AuCentralize network AAA",
          "zh": "集中网络 AAA"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls12/",
        "retrieved_at": "2026-07-30T16:25:48.241Z",
        "snapshot_sha256": "B86C7314F9857EE4AFD9ACAD5661B3A82B1F8B43C6C0D91165DE0B14B6531E53",
        "locator": "Safeguard 12.5: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "12.5",
            "title": "Centralize Network Authentication, Authorization, and AuCentralize network AAA",
            "asset_class": "Network",
            "security_function": "Protect",
            "implementation_groups": [
              2,
              3
            ],
            "inputs": "GV5: Authorized Software Inventory GV35: Assets that are Part of the Network Infrastructure",
            "operations": "Use GV5 to identify and enumerate all AAA services within the enterprise GV35 (M1) For each centralized AAA point identified in Operation 1, determine whether it is necessary or can be consolidated Identify and enumerate authentication points that are unnecessary or can be consolidated (M2) Identify and enumerate authentication points that are necessary and cannot be consolidated (M3) Use the output of Operation 1 to check if each asset in GV35 is covered by at least one AAA system Identify and enumerate network infrastructure assets that are covered by at least one AAA system (M4) Identify and enumerate network infrastructure assets that are not covered by an AAA system (M5)",
            "measures": "M1 = Count of AAA services within the enterprise M2 = Count of unnecessary AAA services M3 = Count of necessary AAA services M4 = Count of network infrastructure covered by AAA services M5 = Count of network infrastructure not covered by AAA services M6 = Count of GV35",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": ""
              },
              {
                "heading": "Metrics / Centralized AAA",
                "content": "Metric | Percentage of properly centralized AAA services\nCalculation | M3 / M1"
              },
              {
                "heading": "Metrics / Centralized AAA / Network Coverage",
                "content": "Metric | Percentage of network infrastructure assets managed through AAA\nCalculation | M4 / M6"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "title-corruption",
        "finding_en": "The CAS title duplicates and truncates the phrase for centralized network AAA.",
        "impact_en": "Literal imports publish a malformed control name even though the identifier remains valid.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "12.5 的 CAS 标题重复并截断集中式网络 AAA 文案。",
        "impact_zh": "字面导入会发布损坏标题。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Use the Safeguard ID as identity, preserve the malformed CAS title as evidence, and take the display title from the declared normative surface.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "用 Safeguard ID 作为身份，展示标题取自声明的规范表面，损坏 CAS 标题原样留作证据。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls12/.",
          "Verify the response SHA-256 equals B86C7314F9857EE4AFD9ACAD5661B3A82B1F8B43C6C0D91165DE0B14B6531E53.",
          "Locate Safeguard 12.5 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "The CAS title duplicates and truncates the phrase for centralized network AAA."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-033",
      "safeguard_ids": [
        "12.6"
      ],
      "safeguard_titles": [
        {
          "id": "12.6",
          "en": "Use of Secure Network Management and Communication Protocols",
          "zh": "安全网络管理与通信协议"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls12/",
        "retrieved_at": "2026-07-30T16:25:48.241Z",
        "snapshot_sha256": "B86C7314F9857EE4AFD9ACAD5661B3A82B1F8B43C6C0D91165DE0B14B6531E53",
        "locator": "Safeguard 12.6: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "12.6",
            "title": "Use of Secure Network Management and Communication Protocols",
            "asset_class": "Network",
            "security_function": "Protect",
            "implementation_groups": [
              2,
              3
            ],
            "inputs": "GV36: Segments within the Enterprise Network GV37: Network Infrastructure Configuration Standards Authorized list of secure network management and communication protocols",
            "operations": "For each network segment in GV36, use Input 3 to identify communication protocols Identify and enumerate segments using only communication protocols on the authorized list (M2) Identify and enumerate segments using communication protocols not on the authorized list (M3) For each communication protocol identified in Operation 1.1, check configuration standards GV37 Identify and enumerate segments using properly configured communication protocols (M4) Identify and enumerate segments using improperly configured communication protocols (M5) For each network segment in GV36, use Input 3 to identify network management protocols Identify and enumerate segments using only network management protocols on the authorized list (M6) Identify and enumerate segments using network management protocols not on the authorized list (M7) For each communication protocol identified in Operation 1.1, check configuration standards GV37 Identify and enumerate segments using properly configured network management protocols (M8) Identify and enumerate segments using improperly configured network management protocols (M9)",
            "measures": "M1 = Count of GV36 M2 = Count of segments using authorized communication protocols M3 = Count of segments using unauthorized communication protocols M4 = Count of segments using properly configured authorized communication protocols M5 = Count of segments using improperly configured authorized communication protocols M6 = Count of segments using unauthorized network management protocols M7 = Count of segments using unauthorized network management protocols M8 = Count of segments using properly configured authorized network management protocols M9 = Count of segments using improperly configured authorized network management protocols",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": ""
              },
              {
                "heading": "Metrics / Communication Protocol Coverage",
                "content": "Metric | The percentage of network segments using properly configured and authorized communication protocols\nCalculation | M4 / M1"
              },
              {
                "heading": "Metrics / Communication Protocol Coverage / Network Management Protocol Coverage",
                "content": "Metric | The percentage of network segments using properly configured and authorized network management protocols\nCalculation | M8 / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "duplicate-definition",
        "finding_en": "Both M6 and M7 are defined as unauthorized network management protocols despite operations distinguishing authorized and unauthorized populations.",
        "impact_en": "Management-protocol coverage cannot be reconstructed from the Measures section alone.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "12.6 把 M6、M7 都定义为未授权网络管理协议，尽管 Operations 区分授权与未授权。",
        "impact_zh": "只看 Measures 无法重建管理协议覆盖率。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Preserve the duplicate official definitions, block automatic scoring, and define distinct pass and fail populations locally.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "阻止自动评分并在本地为授权与未授权协议分别定义变量。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls12/.",
          "Verify the response SHA-256 equals B86C7314F9857EE4AFD9ACAD5661B3A82B1F8B43C6C0D91165DE0B14B6531E53.",
          "Locate Safeguard 12.6 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "Both M6 and M7 are defined as unauthorized network management protocols despite operations distinguishing authorized and unauthorized populations."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-034",
      "safeguard_ids": [
        "12.7"
      ],
      "safeguard_titles": [
        {
          "id": "12.7",
          "en": "Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure",
          "zh": "远程设备 VPN 与 AAA"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls12/",
        "retrieved_at": "2026-07-30T16:25:48.241Z",
        "snapshot_sha256": "B86C7314F9857EE4AFD9ACAD5661B3A82B1F8B43C6C0D91165DE0B14B6531E53",
        "locator": "Safeguard 12.7: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "12.7",
            "title": "Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure",
            "asset_class": "Devices",
            "security_function": "Protect",
            "implementation_groups": [
              2,
              3
            ],
            "inputs": "GV1: Enterprise Asset Inventory GV5: Authorized Software Inventory GV38: AAA Services within the Enterprise GV37: Network Infrastructure Configuration Standards",
            "operations": "Use GV1 to identify and enumerate remote enterprise assets GV39 (M1) Use GV1 and GV5 to identify and enumerate all VPN devices and software (M2) Use the output of Operation 2 and GV37 to check the configuration of the VPN Identify and enumerate VPN devices and software properly configured to require authentication prior to granting access (M3) Identify and enumerate VPN devices and software not properly configured to require authentication prior to granting access (M4) For each asset identified in Operation 1, check if is covered by a VPN device or software identified in Operation 3.1 Identify and enumerate assets that are covered by a VPN (M5) Identify and enumerate assets that are not covered by a VPN (M6) Use GV38 and GV37 to check configuration of AAA services Identify and enumerate AAA services properly configured to require authentication prior to granting access (M7) Identify and enumerate AAA services not properly configured to require authentication prior to granting access (M8) For each asset identified in Operation 1, check if it is covered by an AAA service identified in Operation 5.1 Identify and enumerate assets that are covered by an AAA service (M9) Identify and enumerate assets that are not covered by an AAA service (M10) Compare the output of Operation 4.1 and 6.1 Identify and enumerate assets covered by both VPN and AAA (M1)",
            "measures": "M1 = Count of remote enterprise assets M2 = Count of VPN devices and software M3 = Count of properly configured VPN devices and software M4 = Count of improperly configured VPN devices and software M5 = Count of remote assets covered by a properly configured VPN M6 = Count of remote assets not covered by a properly configured VPN M7 = Count of properly configured AAA services M8 = Count of improperly configured AAA services M9 = Count of remote assets covered by a properly configured AAA service M10 = Count of remote assets not covered by a properly configured AAA service M11 = Count of remote assets covered by both VPN and AAA M12 = Count of AAA services within the enterprise",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": ""
              },
              {
                "heading": "Metrics / VPN Compliance",
                "content": "Metric | The percentage of properly configured VPN devices and software\nCalculation | M3 / M2"
              },
              {
                "heading": "Metrics / VPN Compliance / AAA Compliance",
                "content": "Metric | The percentage of properly configured AAA services\nCalculation | M7 / M12"
              },
              {
                "heading": "Metrics / VPN Compliance / AAA Compliance / Coverage",
                "content": "Metric | The percentage of remote assets using VPN and AAA\nCalculation | M11 / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "wrong-variable",
        "finding_en": "The final operation assigns the VPN-and-AAA intersection to M1 instead of M11.",
        "impact_en": "A literal implementation overwrites the remote-asset denominator.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "12.7 最后一步把 VPN 与 AAA 交集赋给 M1，而非 M11。",
        "impact_zh": "字面实现会覆盖远程资产分母。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Correct the local calculation only after a variable-lineage review, and retain the official token as an unresolved source finding.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "本地沿谱系使用独立交集变量；官方 M1 赋值保持为来源发现。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls12/.",
          "Verify the response SHA-256 equals B86C7314F9857EE4AFD9ACAD5661B3A82B1F8B43C6C0D91165DE0B14B6531E53.",
          "Locate Safeguard 12.7 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "The final operation assigns the VPN-and-AAA intersection to M1 instead of M11."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-035",
      "safeguard_ids": [
        "13.10"
      ],
      "safeguard_titles": [
        {
          "id": "13.10",
          "en": "Perform Application Layer Filtering",
          "zh": "应用层过滤"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls13/",
        "retrieved_at": "2026-07-30T16:26:00.266Z",
        "snapshot_sha256": "F31FFE89DE5087977E7CB6FBD81EC876602871F30C8EA815C0DF862CA40F65BF",
        "locator": "Safeguard 13.10: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "13.10",
            "title": "Perform Application Layer Filtering",
            "asset_class": "Network",
            "security_function": "Protect",
            "implementation_groups": [
              3
            ],
            "inputs": "GV35: Assets that are Part of the Network Infrastructure GV5: Authorized Software Inventory",
            "operations": "Use GV5 to identify software used for application layer filtering For each asset in `GV35, determine whether it is covered by at least one software identified in Operation 1 Identify and enumerate assets covered by application layer filtering software (M2) Identify and enumerate assets not covered by application layer filtering software (M3)",
            "measures": "M1 = Count of network infrastructure assets M2 = Count of network infrastructure assets covered by the application layer filtering software M3 = Count of network infrastructure assets not covered by application layer filtering software",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": ""
              },
              {
                "heading": "Coverage",
                "content": "Metric | The percentage of network infrastructure assets covered by application layering software\nCalculation | M2 / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "heading-structure-and-metric-depth",
        "finding_en": "The CAS page contains a Metrics h3 immediately followed by a peer Coverage h3 and a metric table with calculation M2 / M1. The metric exists; the heading structure caused the earlier extractor to leave the Metrics bucket empty. Its denominator is network infrastructure assets, which does not enumerate application, API, protocol, route, or enforcement-mode paths.",
        "impact_en": "A heading-sensitive parser can falsely report a missing metric, while the published asset ratio can still leave application-layer path effectiveness unmeasured.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "13.10 页面在 Metrics h3 后紧接同级 Coverage h3，并在表格给出 M2 / M1；指标存在，旧解析器因标题层级把表格切出 Metrics。分母是网络基础设施资产，没有枚举应用、API、协议、路由和执行模式路径。",
        "impact_zh": "标题敏感解析器会误报指标缺失；资产比例仍可能漏掉应用层路径有效性。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Parse the adjacent Coverage heading as the official M2 / M1 metric; define a local denominator of required application, API, protocol and route paths and test allow, deny and bypass routes before claiming filtering effectiveness.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "解析相邻 Coverage 表并保留官方 M2 / M1；本地以必需应用/API/协议路径为分母，验证允许、拒绝与绕过路径。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls13/.",
          "Verify the response SHA-256 equals F31FFE89DE5087977E7CB6FBD81EC876602871F30C8EA815C0DF862CA40F65BF.",
          "Locate Safeguard 13.10 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "The CAS page contains a Metrics h3 immediately followed by a peer Coverage h3 and a metric table with calculation M2 / M1. The metric exists; the heading structure caused the earlier extractor to leave the Metrics bucket empty. Its denominator is network infrastructure assets, which does not enumerate application, API, protocol, route, or enforcement-mode paths."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-036",
      "safeguard_ids": [
        "14.2",
        "14.3",
        "14.4",
        "14.5",
        "14.6",
        "14.7",
        "14.8",
        "14.9"
      ],
      "safeguard_titles": [
        {
          "id": "14.2",
          "en": "Train Workforce Members to Recognize Social Engineering Attacks",
          "zh": "社会工程识别"
        },
        {
          "id": "14.3",
          "en": "Train Workforce Members on Authentication Best Practices",
          "zh": "认证最佳实践"
        },
        {
          "id": "14.4",
          "en": "Train Workforce on Data Handling Best Practices",
          "zh": "数据处理最佳实践"
        },
        {
          "id": "14.5",
          "en": "Train Workforce Members on Causes of Unintentional Data Exposure",
          "zh": "非故意数据暴露"
        },
        {
          "id": "14.6",
          "en": "Train Workforce Members on Recognizing and Reporting Security Incidents",
          "zh": "事件识别与报告"
        },
        {
          "id": "14.7",
          "en": "Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates",
          "zh": "缺失安全更新识别与报告"
        },
        {
          "id": "14.8",
          "en": "Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks",
          "zh": "不安全网络风险"
        },
        {
          "id": "14.9",
          "en": "Conduct Role-Specific Security Awareness and Skills Training",
          "zh": "角色化安全技能"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls14/",
        "retrieved_at": "2026-07-30T16:26:01.267Z",
        "snapshot_sha256": "B3AB523467DE4AACC7A8227C3CC2056EE99F14A3A254D1769D5EAC5C90C30305",
        "locator": "Safeguard 14.2-14.9: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "14.2",
            "title": "Train Workforce Members to Recognize Social Engineering Attacks",
            "asset_class": "Users",
            "security_function": "Protect",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "Recognizing Social Engineering Attacks training module GV43: List of Workforce Members List of most recent module training completion dates for each workforce member",
            "operations": "Check enterprise to determine if Input 1 exists If Input 1 exists, M1 = 1 If Input 1 does not exist, M1 = 0 For every member of the workforce in GV43, determine whether the member has completed training Identify and enumerate members who have completed at least initial training (M3) Identify and enumerate members who have not completed any training (M4) For every member of the workforce identified in Operation 2.1, identify the date of the most recently completed module training For every member of the workforce identified in Operation 2.1, use the output of Operation 4 and compare the date to the current date. Capture timeframe in months. Identify and enumerate members whose most recent training date is less than or equal to twelve months from the current date (M5) Identify and enumerate members whose most recent training date is greater than twelve months from the current date (M6)",
            "measures": "M1 = Output of Operation 1 M2 = Count of GV43 M3 = Count of workforce members that have completed training M4 = Count of workforce members that have not completed training M5 = Count of workforce members whose training is up to date M6 = Count of workforce members whose training is not up to date",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M1 is measured at a 0, this Safeguard receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Initial Training Compliance",
                "content": "Metric | The percentage of workforce members that have received initial training\nCalculation | M2 / M1"
              },
              {
                "heading": "Metrics / Initial Training Compliance / Up to Date Training",
                "content": "Metric | The percentage of compliant workforce members\nCalculation | M4 / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          },
          {
            "safeguard_id": "14.3",
            "title": "Train Workforce Members on Authentication Best Practices",
            "asset_class": "Users",
            "security_function": "Protect",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "Authentication Best Practices training module GV43: List of Workforce Members List of most recent module training completion dates for each workforce member",
            "operations": "Check enterprise to determine if Input 1 exists If Input 1 exists, M1 = 1 If Input 1 does not exist, M1 = 0 For every member of the workforce in GV43, determine whether the member has completed training Identify and enumerate members who have completed at least initial training (M3) Identify and enumerate members who have not completed any training (M4) For every member of the workforce identified in Operation 2.1, identify the date of most recently completed module training For every member of the workforce identified in Operation 2.1, use the output of Operation 4 and compare the date to the current date. Capture timeframe in months. Identify and enumerate members whose most recent training date is less than or equal to twelve months from the current date (M5) Identify and enumerate members whose most recent training date is greater than twelve months from the current date (M6)",
            "measures": "M1 = Output of Operation 1 M2 = Count of GV43 M3 = Count of workforce members that have completed training M4 = Count of workforce members that have not completed training M5 = Count of workforce members whose training is up to date M6 = Count of workforce members whose training is not up to date",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M1 is measured at a 0, this Safeguard receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Initial Training Compliance",
                "content": "Metric | The percentage of workforce members that have received initial training\nCalculation | M2 / M1"
              },
              {
                "heading": "Metrics / Initial Training Compliance / Up to Date Training",
                "content": "Metric | The percentage of compliant workforce members\nCalculation | M4 / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          },
          {
            "safeguard_id": "14.4",
            "title": "Train Workforce on Data Handling Best Practices",
            "asset_class": "Users",
            "security_function": "Protect",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "Data Handling Best Practices training module GV43: List of Workforce Members List of most recent module training completion dates for each workforce member",
            "operations": "Check enterprise to determine if Input 1 exists If Input 1 exists, M1 = 1 If Input 1 does not exist, M1 = 0 For every member of the workforce in GV43, determine whether the member has completed training Identify and enumerate members who have completed at least initial training (M3) Identify and enumerate members who have not completed any training (M4) For every member of the workforce identified in Operation 2.1, identify the date of most recently completed module training For every member of the workforce identified in Operation 2.1, use the output of Operation 4 and compare the date to the current date. Capture timeframe in months. Identify and enumerate members whose most recent training date is less than or equal to twelve months from the current date (M5) Identify and enumerate members whose most recent training date is greater than twelve months from the current date (M6)",
            "measures": "M1 = Output of Operation 1 M2 = Count of GV43 M3 = Count of workforce members that have completed training M4 = Count of workforce members that have not completed training M5 = Count of workforce members whose training is up to date M6 = Count of workforce members whose training is not up to date",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M1 is measured at a 0, this Safeguard receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Initial Training Compliance",
                "content": "Metric | The percentage of workforce members that have received initial training\nCalculation | M2 / M1"
              },
              {
                "heading": "Metrics / Initial Training Compliance / Up to Date Training",
                "content": "Metric | The percentage of compliant workforce members\nCalculation | M4 / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          },
          {
            "safeguard_id": "14.5",
            "title": "Train Workforce Members on Causes of Unintentional Data Exposure",
            "asset_class": "Users",
            "security_function": "Protect",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "Causes of Unintentional Data Exposure training module GV43: List of Workforce Members List of most recent module training completion dates for each workforce member",
            "operations": "Check enterprise to determine if Input 1 exists If Input 1 exists, M1 = 1 If Input 1 does not exist, M1 = 0 For every member of the workforce in GV43, determine whether the member has completed training Identify and enumerate members who have completed at least initial training (M3) Identify and enumerate members who have not completed any training (M4) For every member of the workforce identified in Operation 2.1, identify the date of most recently completed module training For every member of the workforce identified in Operation 2.1, use the output of Operation 4 and compare the date to the current date. Capture timeframe in months. Identify and enumerate members whose most recent training date is less than or equal to twelve months from the current date (M5) Identify and enumerate members whose most recent training date is greater than twelve months from the current date (M6)",
            "measures": "M1 = Output of Operation 1 M2 = Count of GV43 M3 = Count of workforce members that have completed training M4 = Count of workforce members that have not completed training M5 = Count of workforce members whose training is up to date M6 = Count of workforce members whose training is not up to date",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M1 is measured at a 0, this Safeguard receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Initial Training Compliance",
                "content": "Metric | The percentage of workforce members that have received initial training\nCalculation | M2 / M1"
              },
              {
                "heading": "Metrics / Initial Training Compliance / Up to Date Training",
                "content": "Metric | The percentage of compliant workforce members\nCalculation | M4 / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          },
          {
            "safeguard_id": "14.6",
            "title": "Train Workforce Members on Recognizing and Reporting Security Incidents",
            "asset_class": "Users",
            "security_function": "Protect",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "Recognizing and Reporting Security Incidents training module GV43: List of Workforce Members List of most recent module training completion dates for each workforce member",
            "operations": "Check enterprise to determine if Input 1 exists If Input 1 exists, M1 = 1 If Input 1 does not exist, M1 = 0 For every member of the workforce in GV43, determine whether the member has completed training Identify and enumerate members who have completed at least initial training (M3) Identify and enumerate members who have not completed any training (M4) For every member of the workforce identified in Operation 2.1, identify the date of most recently completed module training For every member of the workforce identified in Operation 2.1, use the output of Operation 4 and compare the date to the current date. Capture timeframe in months. Identify and enumerate members whose most recent training date is less than or equal to twelve months from the current date (M5) Identify and enumerate members whose most recent training date is greater than twelve months from the current date (M6)",
            "measures": "M1 = Output of Operation 1 M2 = Count of GV43 M3 = Count of workforce members that have completed training M4 = Count of workforce members that have not completed training M5 = Count of workforce members whose training is up to date M6 = Count of workforce members whose training is not up to date",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M1 is measured at a 0, this Safeguard receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Initial Training Compliance",
                "content": "Metric | The percentage of workforce members that have received initial training\nCalculation | M2 / M1"
              },
              {
                "heading": "Metrics / Initial Training Compliance / Up to Date Training",
                "content": "Metric | The percentage of compliant workforce members\nCalculation | M4 / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          },
          {
            "safeguard_id": "14.7",
            "title": "Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates",
            "asset_class": "Users",
            "security_function": "Protect",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "How to Identify and Report if Their Enterprise Assets are Missing Security Updates training module GV43: List of Workforce Members List of most recent module training completion dates for each workforce member",
            "operations": "Check enterprise to determine if Input 1 exists If Input 1 exists, M1 = 1 If Input 1 does not exist, M1 = 0 For every member of the workforce in GV43, determine whether the member has completed training Identify and enumerate members who have completed at least initial training (M3) Identify and enumerate members who have not completed any training (M4) For every member of the workforce identified in Operation 2.1, identify the date of most recently completed module training For every member of the workforce identified in Operation 2.1, use the output of Operation 4 and compare the date to the current date. Capture timeframe in months. Identify and enumerate members whose most recent training date is less than or equal to twelve months from the current date (M5) Identify and enumerate members whose most recent training date is greater than twelve months from the current date (M6)",
            "measures": "M1 = Output of Operation 1 M2 = Count of GV43 M3 = Count of workforce members that have completed training M4 = Count of workforce members that have not completed training M5 = Count of workforce members whose training is up to date M6 = Count of workforce members whose training is not up to date",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M1 is measured at a 0, this Safeguard receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Initial Training Compliance",
                "content": "Metric | The percentage of workforce members that have received initial training\nCalculation | M2 / M1"
              },
              {
                "heading": "Metrics / Initial Training Compliance / Up to Date Training",
                "content": "Metric | The percentage of compliant workforce members\nCalculation | M4 / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          },
          {
            "safeguard_id": "14.8",
            "title": "Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks",
            "asset_class": "Users",
            "security_function": "Protect",
            "implementation_groups": [
              1,
              2,
              3
            ],
            "inputs": "Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks training module GV43: List of Workforce Members List of most recent module training completion dates for each workforce member",
            "operations": "Check enterprise to determine if Input 1 exists If Input 1 exists, M1 = 1 If Input 1 does not exist, M1 = 0 For every member of the workforce in GV43, determine whether the member has completed training Identify and enumerate members who have completed at least initial training (M3) Identify and enumerate members who have not completed any training (M4) For every member of the workforce identified in Operation 2.1, identify the date of most recently completed module training For every member of the workforce identified in Operation 2.1, use the output of Operation 4 and compare the date to the current date. Capture timeframe in months. Identify and enumerate members whose most recent training date is less than or equal to twelve months from the current date (M5) Identify and enumerate members whose most recent training date is greater than twelve months from the current date (M6)",
            "measures": "M1 = Output of Operation 1 M2 = Count of GV43 M3 = Count of workforce members that have completed training M4 = Count of workforce members that have not completed training M5 = Count of workforce members whose training is up to date M6 = Count of workforce members whose training is not up to date",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M1 is measured at a 0, this Safeguard receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Initial Training Compliance",
                "content": "Metric | The percentage of workforce members that have received initial training\nCalculation | M2 / M1"
              },
              {
                "heading": "Metrics / Initial Training Compliance / Up to Date Training",
                "content": "Metric | The percentage of compliant workforce members\nCalculation | M4 / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          },
          {
            "safeguard_id": "14.9",
            "title": "Conduct Role-Specific Security Awareness and Skills Training",
            "asset_class": "Users",
            "security_function": "Protect",
            "implementation_groups": [
              2,
              3
            ],
            "inputs": "Role-Specific Security Awareness and Skills Training module GV43: List of Workforce Members List of most recent module training completion dates for each workforce member",
            "operations": "Check enterprise to determine if Input 1 exists If Input 1 exists, M1 = 1 If Input 1 does not exist, M1 = 0 For every member of the workforce in GV43, determine whether the member has completed training Identify and enumerate members who have completed at least initial training (M3) Identify and enumerate members who have not completed any training (M4) For every member of the workforce identified in Operation 2.1, identify the date of most recently completed module training For every member of the workforce identified in Operation 2.1, use the output of Operation 4 and compare the date to the current date. Capture timeframe in months. Identify and enumerate members whose most recent training date is less than or equal to twelve months from the current date (M5) Identify and enumerate members whose most recent training date is greater than twelve months from the current date (M6)",
            "measures": "M1 = Output of Operation 1 M2 = Count of GV43 M3 = Count of workforce members that have completed training M4 = Count of workforce members that have not completed training M5 = Count of workforce members whose training is up to date M6 = Count of workforce members whose training is not up to date",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M1 is measured at a 0, this Safeguard receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Initial Training Compliance",
                "content": "Metric | The percentage of workforce members that have received initial training\nCalculation | M2 / M1"
              },
              {
                "heading": "Metrics / Initial Training Compliance / Up to Date Training",
                "content": "Metric | The percentage of compliant workforce members\nCalculation | M4 / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "repeated-formula",
        "finding_en": "Eight module pages divide workforce population M2 and non-completion M4 by the program-exists Boolean M1.",
        "impact_en": "The displayed 'percentage' becomes a headcount and the second metric rewards non-completion.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "14.2–14.9 八个模块都用员工人数 M2 和未完成人数 M4 除以“项目存在”布尔值 M1。",
        "impact_zh": "所谓百分比会变成人头数，第二项还奖励未完成。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "For each module, separate program existence, eligible workforce population and completion count; calculate completion against the workforce denominator and never divide a headcount by a Boolean.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "逐模块分开项目存在、合格员工总体与完成人数；完成率只除以员工分母，绝不除布尔值。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls14/.",
          "Verify the response SHA-256 equals B3AB523467DE4AACC7A8227C3CC2056EE99F14A3A254D1769D5EAC5C90C30305.",
          "Locate Safeguard 14.2-14.9 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "Eight module pages divide workforce population M2 and non-completion M4 by the program-exists Boolean M1."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-037",
      "safeguard_ids": [
        "15.5"
      ],
      "safeguard_titles": [
        {
          "id": "15.5",
          "en": "Assess Service Providers",
          "zh": "服务提供商评估"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls15/",
        "retrieved_at": "2026-07-30T16:26:02.291Z",
        "snapshot_sha256": "6987C580534344D0FE4C30694EFBA342A165145B53FB87BFE53160867B099415",
        "locator": "Safeguard 15.5: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "15.5",
            "title": "Assess Service Providers",
            "asset_class": "Users",
            "security_function": "Govern",
            "implementation_groups": [
              3
            ],
            "inputs": "GV44: Service Provider Inventory List GV45: Service Provider Management Policy",
            "operations": "Use GV45 to determine if the enterprise policy includes monitoring guidance for service providers If the assessment scope exists, M1 = 1 If the assessment scope does not exist, M1 = 0 Use GV44 to determine if each listed service provider has monitoring guidance included in the policy Identify and enumerate service providers with monitoring guidance (M3) Identify and enumerate service providers without monitoring guidance (M4)",
            "measures": "M1 = Output of Operation 1 M2 = Count of service providers in inventory M3 = Count of service providers with monitoring guidance M4 = Count of service providers without monitoring guidance",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M1 is a 0, this Safeguard receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Compliance",
                "content": "Metric | The percentage of service providers with monitoring guidance included in policy\nCalculation | M3 / M2"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "wrong-control",
        "finding_en": "The provider-assessment operations and metric evaluate whether monitoring guidance exists, duplicating 15.6.",
        "impact_en": "An organization can receive assessment credit without assessing a provider.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "15.5 的供应商评估 Operations/Metric 实际检查监控指南是否存在，重复 15.6。",
        "impact_zh": "组织可能未评估供应商却取得评估积分。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Do not award provider-assessment credit from monitoring guidance; require an assessment object, result, date and provider identity.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "只有具名供应商、评估对象、结果、日期和责任人的证据才能获得 15.5 信用。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls15/.",
          "Verify the response SHA-256 equals 6987C580534344D0FE4C30694EFBA342A165145B53FB87BFE53160867B099415.",
          "Locate Safeguard 15.5 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "The provider-assessment operations and metric evaluate whether monitoring guidance exists, duplicating 15.6."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-038",
      "safeguard_ids": [
        "16.4"
      ],
      "safeguard_titles": [
        {
          "id": "16.4",
          "en": "Establish and Manage an Inventory of Third-Party Software Components",
          "zh": "第三方组件与 SBOM"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls16/",
        "retrieved_at": "2026-07-30T16:26:03.475Z",
        "snapshot_sha256": "78BEFD8EB1628E546CA330222996DCA16DD2C9EF7FC70A606844C44A4F64872E",
        "locator": "Safeguard 16.4: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "16.4",
            "title": "Establish and Manage an Inventory of Third-Party Software Components",
            "asset_class": "Software",
            "security_function": "Identfy",
            "implementation_groups": [
              2,
              3
            ],
            "inputs": "GV47: Inventory of Third-Party Software Components Date of last review or update of the inventory",
            "operations": "Determine whether GV47 exists within the enterprise If Input 1 exists, M1 = 1 If Input 1 does not exist, M1 = 0 Use GV47 and determine whether each software component listed includes, at a minimum, the following information: risk associated with components, whether the component is supported Identify and enumerate software components with complete information (M3) Identify and enumerate software components with missing information (M4) Compare the date of Input 2 to the current date and capture the timeframe in days (M5)",
            "measures": "M1 = Output of Operation 1 M2 = Count of GV47 M3 = Count of software components with complete information M4 = Count of software components with missing information M5 = Timeframe since the last review or update of the inventory",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": "If M1 is 0, this Safeguard receives a failing score. The other metrics don't apply. If M5 is greater than twelve months, then this Safeguard is measured at a 0 and receives a failing score. The other metrics don't apply."
              },
              {
                "heading": "Metrics / Completeness of Inventory",
                "content": "Metric | The percent of components included in the secure application development process\nCalculation | M3 / M2"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "cadence-and-metadata",
        "finding_en": "The security function is misspelled Identfy, and a freshness measure recorded in days is failed only after twelve months despite the Safeguard's monthly review.",
        "impact_en": "Metadata imports break and an eleven-month-old component inventory can pass.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "16.4 的 Security Function 拼成 Identfy；以天记录的新鲜度却在 12 个月后才失败，而 Safeguard 要求每月复核。",
        "impact_zh": "元数据导入会破损，11 个月未更新的组件台账仍可能通过。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Correct the local metadata label and apply the Safeguard cadence as a separate freshness gate measured in the same unit.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "本地修正元数据标签，并以同一时间单位把月度要求作为独立新鲜度门槛。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls16/.",
          "Verify the response SHA-256 equals 78BEFD8EB1628E546CA330222996DCA16DD2C9EF7FC70A606844C44A4F64872E.",
          "Locate Safeguard 16.4 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "The security function is misspelled Identfy, and a freshness measure recorded in days is failed only after twelve months despite the Safeguard's monthly review."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-039",
      "safeguard_ids": [
        "16.8"
      ],
      "safeguard_titles": [
        {
          "id": "16.8",
          "en": "Separate Production and Non-Production Systems",
          "zh": "生产与非生产隔离"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls16/",
        "retrieved_at": "2026-07-30T16:26:03.475Z",
        "snapshot_sha256": "78BEFD8EB1628E546CA330222996DCA16DD2C9EF7FC70A606844C44A4F64872E",
        "locator": "Safeguard 16.8: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "16.8",
            "title": "Separate Production and Non-Production Systems",
            "asset_class": "Network",
            "security_function": "Protect",
            "implementation_groups": [
              2,
              3
            ],
            "inputs": "GV1: Enterprise Asset Inventory",
            "operations": "Use GV1 to identify and enumerate production systems (M1) For each production system identified in Operation 1, use GV1 to identify if at least one non-production system exists for the system Identify and enumerate production systems with at least one non-production system (M2) Identify and enumerate production systems without a non-production system (M3)",
            "measures": "M1 = Count of production systems M2 = Count of production systems with a non-production system to complement M3 = Count of production systems without a non-production system to complement",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": ""
              },
              {
                "heading": "Metrics / Coverage",
                "content": "Metric | The percentage of non-production systems with an existing production system\nCalculation | M2 / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "metric-label",
        "finding_en": "The formula counts production systems with non-production counterparts, but the metric text says the reverse.",
        "impact_en": "The reported population can be mislabelled even before the separation itself is tested.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "16.8 公式统计“有非生产对应环境的生产系统”，Metric 文字却描述反向总体。",
        "impact_zh": "即使隔离测试尚未发生，报告总体也会被错标。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Keep the official formula and correct the local description only after proving which population the numerator and denominator represent.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "先确认分子分母对象，再仅修正本地指标描述；官方公式和文字都保留。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls16/.",
          "Verify the response SHA-256 equals 78BEFD8EB1628E546CA330222996DCA16DD2C9EF7FC70A606844C44A4F64872E.",
          "Locate Safeguard 16.8 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "The formula counts production systems with non-production counterparts, but the metric text says the reverse."
      }
    },
    {
      "finding_id": "CAS-2026-07-31-040",
      "safeguard_ids": [
        "18.3"
      ],
      "safeguard_titles": [
        {
          "id": "18.3",
          "en": "Remediate Penetration Test Findings",
          "zh": "渗透发现修复"
        }
      ],
      "source": {
        "publisher": "Center for Internet Security",
        "surface": "CIS Controls Assessment Specification",
        "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls18/",
        "retrieved_at": "2026-07-30T16:26:16.590Z",
        "snapshot_sha256": "AA6508DA60A7DA98047C8EE9E1D8B688F97A3668EE857F585E9B87511299F62A",
        "locator": "Safeguard 18.3: Inputs, Operations, Measures, Metrics and adjacent metric heading"
      },
      "official_fact": {
        "provenance": "cis_official",
        "records": [
          {
            "safeguard_id": "18.3",
            "title": "Remediate Penetration Test Findings",
            "asset_class": "Network",
            "security_function": "Protect",
            "implementation_groups": [
              2,
              3
            ],
            "inputs": "GV53: Penetration Testing Program Documentation GV54: Most Recent External Penetration Report External penetration report prior to most recent report",
            "operations": "Use the findings in Input 3 to identify and enumerate the vulnerabilities outlined (M1) Use the findings in GV54 to identify the vulnerabilities outlined Compare the output of Operation 1 and Operation 1 Identify and enumerate vulnerabilities found in Input 3 that continue to be in Input 2 (M2) Identify and enumerate vulnerabilities found in Input 3 that no longer appear in Input 2 (M3) Using the program documentation from GV53, determine whether the output of Operation 3.2 is still within scope based on enterprise's policy Identify and enumerate vulnerabilities within scope (M4) Identify and enumerate vulnerabilities out of scope (M5)",
            "measures": "M1 = Count of initial vulnerabilities identified by a penetration test M2 = Count of successfully remediated vulnerabilities M3 = Count of vulnerabilities that have not been remediated M4 = Count of unremediated vulnerabilities still in scope M5 = Count of unremediated vulnerabilities out of scope",
            "metric_sections": [
              {
                "heading": "Metrics",
                "content": ""
              },
              {
                "heading": "Metrics / Compliance",
                "content": "Metric | The percent of successfully remediated or still within scope vulnerabilities identified in the initial penetration test findings.\nCalculation | (M3 + M4) / M1"
              }
            ],
            "normalization": "HTML tags removed and whitespace collapsed by the pinned extractor; wording and variable tokens are otherwise unchanged."
          }
        ]
      },
      "sosec_analysis": {
        "provenance": "sosec_analysis",
        "type": "reversed-outcome",
        "finding_en": "Operations describe M2 as continuing findings and M3 as disappeared findings, Measures reverse the meanings, and the formula combines M3 with still-in-scope M4.",
        "impact_en": "The published metric can reward unremediated findings and cannot prove a retest.",
        "confidence": {
          "level": "high",
          "reason": "The finding is reproducible from pinned official headings, variable definitions, operation text, labels, or formulas without relying on a live enterprise."
        },
        "status": "present_in_2026-07-31_snapshot",
        "finding_zh": "18.3 的 Operations 把 M2 定义为持续发现、M3 为消失发现，Measures 反向定义，公式又把 M3 与仍在范围 M4 组合。",
        "impact_zh": "未修复发现可能被奖励，且无法证明复测。"
      },
      "example_local_response": {
        "provenance": "example_local_solution",
        "proposal_en": "Reconstruct continuing, disappeared and retested findings from stable finding identities; require a successful retest before remediation credit.",
        "normative": false,
        "owner_must_confirm": true,
        "proposal_zh": "用稳定发现身份重建持续、消失和已复测总体；只有成功复测才计修复。"
      },
      "reproduction": {
        "steps": [
          "Download https://cas.docs.cisecurity.org/en/latest/source/Controls18/.",
          "Verify the response SHA-256 equals AA6508DA60A7DA98047C8EE9E1D8B688F97A3668EE857F585E9B87511299F62A.",
          "Locate Safeguard 18.3 and read Inputs, Operations, Measures, Metrics, plus the immediately following h3 and table.",
          "Trace each referenced GV or M variable from input through operation, measure and metric; reproduce the finding without silently correcting the source."
        ],
        "expected": "Operations describe M2 as continuing findings and M3 as disappeared findings, Measures reverse the meanings, and the formula combines M3 with still-in-scope M4."
      }
    }
  ]
}
