{
  "schema": "https://sosec.io/static/research/cis-controls-v8-1-implementation-evidence-schema-july-2026-v2.json",
  "schema_name": "sosec.cis-controls-v8.1.implementation-evidence.v2",
  "artifact_version": "2.0.0",
  "generated_at": "2026-07-30T17:54:56Z",
  "cutoff": "2026-07-31",
  "framework": {
    "name": "CIS Controls",
    "edition": "v8.1",
    "controls": 18,
    "safeguards": 153,
    "source_set": {
      "navigator": {
        "url": "https://www.cisecurity.org/controls/cis-controls-navigator",
        "retrieved_at": "2026-07-30T16:31:55.659Z",
        "bytes": 2701228,
        "sha256": "2A8B34FAE24702155E4DA93EFB9B53A96B3BD12126F6661C9F5F76216BE2DE7B",
        "structured_comparison": {
          "safeguards": 153,
          "changed_id_title_description_ig_asset_class_records": 0
        }
      },
      "cas_control_pages": [
        {
          "control": 1,
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls1/",
          "retrieved_at": "2026-07-30T16:25:16.120Z",
          "bytes": 34170,
          "sha256": "AD366711310451131E32B0C9F9B8A9F1F9F15FF7114DB326E611EB25356769EF"
        },
        {
          "control": 2,
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls2/",
          "retrieved_at": "2026-07-30T16:25:28.206Z",
          "bytes": 40572,
          "sha256": "59F438759F8704D42D908FD3E9EF9D632BF2C2984A4F033713634B3AE616B64A"
        },
        {
          "control": 3,
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls3/",
          "retrieved_at": "2026-07-30T16:25:28.667Z",
          "bytes": 62712,
          "sha256": "11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09"
        },
        {
          "control": 4,
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls4/",
          "retrieved_at": "2026-07-30T16:25:29.565Z",
          "bytes": 54051,
          "sha256": "613D6086318545F0A7BA221AF501DC788ACDB3F79C3370D891E1D6EA2CF1190C"
        },
        {
          "control": 5,
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls5/",
          "retrieved_at": "2026-07-30T16:25:30.015Z",
          "bytes": 35579,
          "sha256": "067CD9797658BCF1080DAC4A01672E8CD9A550F6933CD3F3219369737E28A28A"
        },
        {
          "control": 6,
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls6/",
          "retrieved_at": "2026-07-30T16:25:30.470Z",
          "bytes": 35122,
          "sha256": "F05309C876FA1A941F5B41071EE4764DAA9848B4EB967755B390547FE1F078C5"
        },
        {
          "control": 7,
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls7/",
          "retrieved_at": "2026-07-30T16:25:31.916Z",
          "bytes": 42540,
          "sha256": "BA2036413BBF89630CCF02B4B304353CB97FCCEB11F22AD1F95FB6408A06830B"
        },
        {
          "control": 8,
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls8/",
          "retrieved_at": "2026-07-30T16:25:43.952Z",
          "bytes": 44150,
          "sha256": "BB5C01E764D3A2C232D06D1F839F90311343D93E4A858CB123E6D9911B5A4DC4"
        },
        {
          "control": 9,
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls9/",
          "retrieved_at": "2026-07-30T16:25:45.071Z",
          "bytes": 33622,
          "sha256": "893B95999A6ACDC28F3DE11419EF6E6640E491BA628EA37586763E76C0FF99C7"
        },
        {
          "control": 10,
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls10/",
          "retrieved_at": "2026-07-30T16:25:46.197Z",
          "bytes": 31011,
          "sha256": "BBDC6A8F61662575C58667EBB74C005F06950B21B0CF58D65E501814C00BE8B5"
        },
        {
          "control": 11,
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls11/",
          "retrieved_at": "2026-07-30T16:25:47.206Z",
          "bytes": 27304,
          "sha256": "64B9FC7DBD72CA64F77263A3253BCCD64F658CFD626A18DD543020FB8171C94F"
        },
        {
          "control": 12,
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls12/",
          "retrieved_at": "2026-07-30T16:25:48.241Z",
          "bytes": 43399,
          "sha256": "B86C7314F9857EE4AFD9ACAD5661B3A82B1F8B43C6C0D91165DE0B14B6531E53"
        },
        {
          "control": 13,
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls13/",
          "retrieved_at": "2026-07-30T16:26:00.266Z",
          "bytes": 46778,
          "sha256": "F31FFE89DE5087977E7CB6FBD81EC876602871F30C8EA815C0DF862CA40F65BF"
        },
        {
          "control": 14,
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls14/",
          "retrieved_at": "2026-07-30T16:26:01.267Z",
          "bytes": 49352,
          "sha256": "B3AB523467DE4AACC7A8227C3CC2056EE99F14A3A254D1769D5EAC5C90C30305"
        },
        {
          "control": 15,
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls15/",
          "retrieved_at": "2026-07-30T16:26:02.291Z",
          "bytes": 36086,
          "sha256": "6987C580534344D0FE4C30694EFBA342A165145B53FB87BFE53160867B099415"
        },
        {
          "control": 16,
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls16/",
          "retrieved_at": "2026-07-30T16:26:03.475Z",
          "bytes": 62629,
          "sha256": "78BEFD8EB1628E546CA330222996DCA16DD2C9EF7FC70A606844C44A4F64872E"
        },
        {
          "control": 17,
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls17/",
          "retrieved_at": "2026-07-30T16:26:04.625Z",
          "bytes": 41343,
          "sha256": "A6DCCA0952C7F7B3C5FD75C759EA550966B498275E2E955D804B3D61D116E575"
        },
        {
          "control": 18,
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls18/",
          "retrieved_at": "2026-07-30T16:26:16.590Z",
          "bytes": 25664,
          "sha256": "AA6508DA60A7DA98047C8EE9E1D8B688F97A3668EE857F585E9B87511299F62A"
        }
      ]
    }
  },
  "revision_statement": {
    "withdrawn_claim": {
      "en": "The July 28 article described the v1 template expansion as 13,020 atomic PRD requirements. This revision withdraws that characterization.",
      "zh": "7 月 28 日版把 v1 模板展开描述为 13,020 条原子 PRD 需求；本次修订撤回该定性。"
    },
    "v1_historical_artifact": {
      "path": "/static/research/cis-controls-v8-1-safeguard-prd-register-july-2026-v1.json",
      "sha256": "BC9BE410DFFE5278FE0C9D05DE397D26957FDCB3F9B189D8A183315238897FC6",
      "status": "superseded_historical_only",
      "rows": 13020,
      "exact_distinct_bilingual_text_pairs": 2017,
      "rows_in_duplicate_groups": 11483,
      "globally_repeated_baseline_texts": 38,
      "rows_from_those_global_texts": 5814
    },
    "current_model": {
      "en": "One shared evidence baseline, 153 Safeguard-specific implementation deltas, forty reproducible CAS findings, and five complete reference product PRDs.",
      "zh": "一套共享证据基线、153 项 Safeguard 特有实施增量、40 项可复现 CAS 发现，以及 5 个完整参考产品 PRD。"
    }
  },
  "provenance_classes": {
    "cis_official": {
      "en": "Unmodified or whitespace-normalized fields transcribed from the pinned CIS surface.",
      "zh": "来自固定 CIS 官方页面的原文或仅做空白归一的字段。"
    },
    "sosec_analysis": {
      "en": "SOSEC interpretation of source structure, variable lineage, decision risk, or missing effectiveness depth.",
      "zh": "SOSEC 对来源结构、变量谱系、决策风险或有效性深度缺口的分析。"
    },
    "example_local_solution": {
      "en": "A non-normative implementation option that requires local owner approval and validation.",
      "zh": "须由本地责任人批准和验证的非规范性实施示例。"
    }
  },
  "counts": {
    "shared_baseline_rules": 9,
    "safeguard_deltas": 153,
    "cas_findings": 40,
    "reference_product_prds": 5
  },
  "shared_baseline": [
    {
      "baseline_id": "BASE-01",
      "title": {
        "en": "Authoritative population",
        "zh": "权威总体"
      },
      "provenance": "sosec_analysis",
      "requirement": {
        "en": "Declare the in-scope object type, stable identity, inclusion and exclusion rules, source coverage, deduplication rule, and empty-population semantics before calculating coverage.",
        "zh": "计算覆盖率前，声明对象类型、稳定身份、纳入/排除规则、来源覆盖、去重规则和空总体语义。"
      },
      "acceptance": {
        "en": "An independent sample can be traced from source to register and from register back to a live or retired object; unknown and stale objects remain visible.",
        "zh": "独立样本可从来源追到台账，也可从台账追回存活或已退役对象；未知与陈旧对象仍然可见。"
      }
    },
    {
      "baseline_id": "BASE-02",
      "title": {
        "en": "Accountability and decision rights",
        "zh": "责任与决策权"
      },
      "provenance": "sosec_analysis",
      "requirement": {
        "en": "Name the control owner, system owner, evidence custodian, exception approver, and operator; separate incompatible approval and execution duties.",
        "zh": "明确控制责任人、系统责任人、证据保管人、例外批准人和操作人，并分离不相容的批准与执行职责。"
      },
      "acceptance": {
        "en": "Every control and exception resolves to active identities, delegated authority, escalation path, and a replacement rule for departed owners.",
        "zh": "每项控制与例外均能解析到有效身份、授权范围、升级路径和责任人离任后的替换规则。"
      }
    },
    {
      "baseline_id": "BASE-03",
      "title": {
        "en": "Enforcement and effective state",
        "zh": "执行点与有效状态"
      },
      "provenance": "sosec_analysis",
      "requirement": {
        "en": "Identify the exact policy engine, workflow gate, service, device, or human decision where the control changes an outcome; record intended and effective state separately.",
        "zh": "明确真正改变结果的策略引擎、流程闸门、服务、设备或人工决策点，并分开记录意图状态与有效状态。"
      },
      "acceptance": {
        "en": "A permitted path succeeds, a prohibited path is denied or routed to the declared response, and bypass paths are either covered or registered as residual risk.",
        "zh": "允许路径成功，禁止路径被拒绝或进入声明的响应流程；绕过路径要么受控，要么登记为残余风险。"
      }
    },
    {
      "baseline_id": "BASE-04",
      "title": {
        "en": "Evidence identity and freshness",
        "zh": "证据身份与新鲜度"
      },
      "provenance": "sosec_analysis",
      "requirement": {
        "en": "Bind evidence to object identity, source, collector or evaluator version, policy version, observation time, result, and retention; define freshness by the decision clock.",
        "zh": "把证据绑定到对象身份、来源、采集器或评估器版本、策略版本、观测时间、结果与保留期，并按决策时钟定义新鲜度。"
      },
      "acceptance": {
        "en": "Expired, failed, partial, or source-unhealthy evidence cannot silently retain a passing state; the UI and export expose its last trustworthy time.",
        "zh": "过期、失败、部分或来源不健康的证据不能静默保留通过状态；界面与导出显示其最后可信时间。"
      }
    },
    {
      "baseline_id": "BASE-05",
      "title": {
        "en": "Positive, negative, and fault-path verification",
        "zh": "正向、反向与故障路径验证"
      },
      "provenance": "sosec_analysis",
      "requirement": {
        "en": "Pair a known-good control with a known-bad or adversarial control and at least one source, evaluator, or enforcement failure; preserve the expected and observed result.",
        "zh": "为已知良好正控配对已知错误或对抗负控，并加入至少一种来源、评估器或执行故障；保存期望与实际结果。"
      },
      "acceptance": {
        "en": "The test identifies which boundary failed, does not convert missing telemetry into success, and is repeatable after policy, platform, or provider change.",
        "zh": "测试能定位失效边界，不把遥测缺失转换为成功，并能在策略、平台或服务商变化后重复。"
      }
    },
    {
      "baseline_id": "BASE-06",
      "title": {
        "en": "Exceptions with expiry",
        "zh": "会到期的例外"
      },
      "provenance": "sosec_analysis",
      "requirement": {
        "en": "An exception names exact objects and condition, approver, business reason, compensating control, residual risk, start and expiry, review cadence, and removal test.",
        "zh": "例外必须写明准确对象与条件、批准人、业务理由、补偿控制、残余风险、起止时间、复核周期和撤除测试。"
      },
      "acceptance": {
        "en": "Expiry closes or escalates the exception automatically; broad groups and inherited exceptions do not acquire new objects without a fresh decision.",
        "zh": "到期时自动关闭或升级例外；宽泛组和继承例外不会在无新决定时吸收新对象。"
      }
    },
    {
      "baseline_id": "BASE-07",
      "title": {
        "en": "Failure behavior and safe rollback",
        "zh": "失败行为与安全回滚"
      },
      "provenance": "sosec_analysis",
      "requirement": {
        "en": "Define fail-open, fail-closed, degraded, or manual-review behavior for source loss, evaluator error, partial deployment, conflict, and timeout; preserve the last known good state and a tested rollback.",
        "zh": "为来源中断、评估器错误、部分部署、冲突和超时定义放行、拒绝、降级或人工复核行为，并保留已知良好状态和测试过的回滚。"
      },
      "acceptance": {
        "en": "A fault injection reaches the named branch, leaves evidence, avoids a false green state, and restores service without deleting unresolved objects or exceptions.",
        "zh": "故障注入能到达具名分支、留下证据、不产生虚假绿色状态，并在不删除未决对象或例外的前提下恢复服务。"
      }
    },
    {
      "baseline_id": "BASE-08",
      "title": {
        "en": "Shared responsibility and provider proof",
        "zh": "共享责任与服务商证据"
      },
      "provenance": "sosec_analysis",
      "requirement": {
        "en": "For provider-operated controls, separate provider operation, tenant configuration, tenant telemetry, uncovered gap, contractual assurance, and exit or fallback path.",
        "zh": "对服务商运行的控制，分开记录服务商操作、租户配置、租户遥测、未覆盖缺口、合同保证以及退出或替代路径。"
      },
      "acceptance": {
        "en": "A provider report is accepted only for its named service, region, period, and control; tenant-side decisions and negative tests remain visible.",
        "zh": "服务商报告只在具名服务、地区、期间和控制范围内有效；租户侧决定与反向测试仍然可见。"
      }
    },
    {
      "baseline_id": "BASE-09",
      "title": {
        "en": "Lifecycle and closure",
        "zh": "生命周期与结案"
      },
      "provenance": "sosec_analysis",
      "requirement": {
        "en": "Define discovery, triage, enforcement, exception, remediation, verification, closure, reopening, and retirement events with stable object history.",
        "zh": "以稳定对象历史定义发现、分诊、执行、例外、修复、验证、关闭、重开与退役事件。"
      },
      "acceptance": {
        "en": "Closure requires the declared proof, later contradictory evidence reopens the object, and retired objects remain auditable without remaining in active coverage.",
        "zh": "结案必须具备声明的证明；后续矛盾证据会重开对象；退役对象可审计但不留在当前覆盖总体。"
      }
    }
  ],
  "safeguard_deltas": [
    {
      "delta_id": "DELTA-CIS-1.1",
      "safeguard_id": "1.1",
      "control": 1,
      "title": {
        "en": "Establish and Maintain Detailed Enterprise Asset Inventory",
        "zh": "企业资产总账"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Identify",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The population includes every device able to store or process enterprise data: managed and unmanaged endpoints, servers, network appliances, virtual machines, ephemeral cloud instances, containers' host/control-plane assets, mobile, IoT/OT, lab and regularly connected third-party devices. DNS names or IP observations are evidence sources, not stable asset identities.",
          "zh": "范围包括一切能够存储或处理企业数据的设备：受管与非受管终端、服务器、网络设备、虚机、云实例、容器宿主与控制面、移动设备、IoT/OT、实验设备，以及经常接入的第三方设备。IP、DNS 名和一次扫描结果只是观测线索，不能充当稳定资产身份。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Make one asset authority reconcile procurement, MDM/EDR, hypervisors, cloud organizations and accounts, network discovery, DHCP/IPAM, and disposal records. Give every record a durable identifier, owner, business purpose, approval state, location or tenancy, first/last seen time, and lifecycle state; define creation and retirement SLOs instead of waiting for the six-month review.",
          "zh": "指定一个资产权威台账，持续对账采购、MDM/EDR、虚拟化、云组织与账号、网络发现、DHCP/IPAM 和报废记录。每项至少保存稳定标识、责任人、用途、批准状态、位置或租户、首次/最后出现时间和生命周期状态；新增与退役用 SLO 管理，不能等半年复核才发现。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A scanner's silence never proves absence: sleeping laptops, private subnets, serverless services, SaaS tenants, isolated OT and travel devices need other sources. BYOD may be out of management but remains in the connection population. An exception identifies the device, custodian, network path, compensating restriction, expiry and removal test; a spreadsheet with no reconciliation is only a list.",
          "zh": "扫描器没看到不代表资产不存在；休眠笔记本、私网、Serverless、SaaS 租户、隔离 OT 和出差设备要靠别的来源。BYOD 可以不纳管，却仍在接入总体内。例外必须写明设备、保管人、接入路径、补偿限制、到期日和撤除测试；一张从不对账的表格只是名单。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Prove both completeness and field quality against an independently assembled aggregate population. Sample assets from cloud billing, switch tables, EDR, MDM and finance back to the register; seed one approved and one unauthorized test asset; verify creation, ownership, quarantine and retirement. Report matched, missing, duplicate, stale and ownerless counts with a declared empty-population rule.",
          "zh": "用独立拼出的“应有资产总体”同时检验覆盖率和字段质量。从云账单、交换表、EDR、MDM、财务各抽样回查台账，再投放一个授权和一个未授权测试资产，验证登记、认领、隔离与退役。分别报告匹配、缺失、重复、陈旧和无主记录，并先定义空总体怎么算。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "1.1",
          "control": 1,
          "title": {
            "en": "Establish and Maintain Detailed Enterprise Asset Inventory",
            "zh": "企业资产总账"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls1/",
          "snapshot_sha256": "AD366711310451131E32B0C9F9B8A9F1F9F15FF7114DB326E611EB25356769EF",
          "retrieved_at": "2026-07-30T16:25:16.120Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-002"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-1.2",
      "safeguard_id": "1.2",
      "control": 1,
      "title": {
        "en": "Address Unauthorized Assets",
        "zh": "处置未授权资产"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Respond",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The denominator is every asset observed outside the approved state, including unknown hardware, unmanaged virtual machines, stale cloud resources, rogue wireless devices and approved assets connected through an unapproved path. A detection can be false, but it cannot disappear merely because the device becomes unreachable.",
          "zh": "总体是所有未处于批准状态的资产，包括未知硬件、未管虚机、遗留云资源、私接无线设备，以及从未批准路径接入的已批准设备。发现可能误报，但资产后来离线，不能据此自动销案。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Define a weekly-or-faster disposition queue joining the asset register to NAC, MDM, EDR, cloud and network evidence. The asset owner and network or cloud control owner must choose remove, deny, quarantine or formally authorize; each choice records who acted, where enforcement occurred and when the case closes.",
          "zh": "至少每周把资产台账与 NAC、MDM、EDR、云和网络观测合并成处置队列。资产责任人与网络或云控制负责人必须在移除、拒绝、隔离、正式授权中作出决定，并记录谁在什么控制点执行、何时关闭。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Sleeping, roaming, powered-off and segmented assets stay open until custody or enforcement is established. Medical, OT or safety systems may use isolation instead of shutdown. A business request is not authorization until the register and enforcement policy agree, and recurring discoveries of the same asset reopen the root-cause problem.",
          "zh": "休眠、漫游、关机和被分段隔离的设备，在确认保管或强制策略前仍是开放事项。医疗、OT、安全关键设备可以隔离替代关机。业务申请只有在台账和强制策略一致后才算授权；同一资产反复出现说明根因仍未修。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Plant an unauthorized test device and cloud instance, then confirm detection, ticket creation, containment at every reachable path and final inventory update. The numerator is cases with an evidenced disposition inside the SLO, not cases a scanner failed to see again; retest from a second segment or identity before closure.",
          "zh": "在测试范围接入未授权设备并创建未授权云实例，验证发现、工单、所有可达路径上的隔离和最终台账更新。分子只计算 SLO 内有执行证据的处置，不能计算“扫描器后来没再看到”；结案前从第二网段或第二身份复测。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "1.2",
          "control": 1,
          "title": {
            "en": "Address Unauthorized Assets",
            "zh": "处置未授权资产"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls1/",
          "snapshot_sha256": "AD366711310451131E32B0C9F9B8A9F1F9F15FF7114DB326E611EB25356769EF",
          "retrieved_at": "2026-07-30T16:25:16.120Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-003"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-1.3",
      "safeguard_id": "1.3",
      "control": 1,
      "title": {
        "en": "Utilize an Active Discovery Tool",
        "zh": "主动发现"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Cover every scannable routed zone, address family, cloud network and remote-access range at the required cadence; distinguish excluded, unreachable and deliberately non-scannable space. Kubernetes pods, short-lived workloads and SaaS are not reliably represented by a periodic IP sweep.",
          "zh": "覆盖全部可安全扫描的路由网段、地址族、云网络和远程接入地址段，并明确排除、不可达和因安全原因不能主动扫描的区域。Kubernetes Pod、短命工作负载和 SaaS 不能靠周期性 IP 扫描完整表达。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Operate authenticated or unauthenticated discovery from enough vantage points to cross segmentation without bypassing safety constraints. Inventory the scanners themselves, pin scope and credentials, alert on failed jobs, normalize observations to durable asset identities, and feed new candidates into 1.1/1.2 at least daily.",
          "zh": "从足够多的视角执行有凭据或无凭据发现，跨越分段但不绕过安全限制。扫描器自身也入清单，固定范围和凭据，任务失败告警；观测归一到稳定资产身份，新对象至少每日进入 1.1/1.2 流程。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Discovery coverage is zones successfully completed divided by in-scope zones, not discovered assets divided by an existing inventory; the latter can exceed 100% and reward duplicates. Rate limits, IDS blocks and credential failure are failed coverage. Safety-sensitive OT requires approved passive or controller evidence, never an undocumented exclusion.",
          "zh": "覆盖率应为成功扫描的范围除以应扫范围，不能用“发现资产数/现有台账数”，后者会因重复而超过 100%。限流、IDS 拦截和凭据失败都是未覆盖。对安全敏感 OT，采用批准的被动或控制器证据，不能悄悄排除。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Measure scheduled zones, successfully scanned zones, address space attempted, responsive objects normalized, and discoveries reconciled. Seed a temporary host in a covered subnet and a cloud instance shorter-lived than one scan cycle; the first must be found, while the second demonstrates the residual gap that event sources must cover.",
          "zh": "统计计划网段、成功完成网段、尝试地址空间、归一对象和完成对账的发现。在覆盖网段放一个临时主机和一个寿命短于扫描周期的云实例：前者必须发现，后者用来证明需要事件源补洞。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "1.3",
          "control": 1,
          "title": {
            "en": "Utilize an Active Discovery Tool",
            "zh": "主动发现"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls1/",
          "snapshot_sha256": "AD366711310451131E32B0C9F9B8A9F1F9F15FF7114DB326E611EB25356769EF",
          "retrieved_at": "2026-07-30T16:25:16.120Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-004",
          "CAS-2026-07-31-005"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-1.4",
      "safeguard_id": "1.4",
      "control": 1,
      "title": {
        "en": "Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory",
        "zh": "DHCP 与 IPAM 观测"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Identify",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The scope is every enterprise-managed DHCP service and equivalent address allocator across campuses, wireless, VPN, IPv4/IPv6, cloud and virtual networks. Static addresses, self-assigned IPv6, containers, NAT and SaaS remain outside DHCP's visibility and require complementary evidence.",
          "zh": "范围是园区、无线、VPN、IPv4/IPv6、云和虚拟网络中全部企业管理的 DHCP 或等效地址分配器。静态地址、IPv6 自分配、容器、NAT 和 SaaS 不在 DHCP 视野里，仍需其他证据。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Send authoritative lease and allocation events to a protected collector, preserve server, tenant, MAC or client identifier, hostname, address, lease time and network context, and reconcile them into the asset register at least weekly. The network owner also maintains a complete allocator inventory and clock synchronization.",
          "zh": "把权威租约与分配事件送到受保护收集端，保留服务器、租户、MAC 或客户端标识、主机名、地址、租期和网络上下文，至少每周回写资产台账。网络负责人同时维护分配器完整清单和时间同步。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A positive count of correctly logging servers is success, despite the current CAS text interpreting one such measure as stale inventory. DHCP identifies a network attachment, not device ownership or approval. Shared MACs, relay loss, randomized mobile identities and overlapping cloud addresses need tenant and relay context before records are merged.",
          "zh": "CAS 当前文本把“正确输出日志的服务器数大于零”解释成台账陈旧，正负含义写反。DHCP 只能证明一次网络接入，不能证明所有权或授权。共享 MAC、中继丢失、移动端随机身份和云内重叠地址，必须带租户与中继上下文再合并。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Generate a lease from a known test client, verify collection, parsing, asset matching and timely expiry; then use an unknown client to confirm it enters the unauthorized queue. Measure active allocators producing complete logs over all in-scope allocators and successful reconciliations over eligible lease events, with duplicates and privacy-randomized identifiers separated.",
          "zh": "用已知测试客户端申请租约，验证采集、解析、资产匹配和按时过期；再用未知客户端确认其进入未授权队列。覆盖率是完整产生日志的在管分配器/应管分配器，租约对账另算，并分开重复和隐私随机标识。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "1.4",
          "control": 1,
          "title": {
            "en": "Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory",
            "zh": "DHCP 与 IPAM 观测"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls1/",
          "snapshot_sha256": "AD366711310451131E32B0C9F9B8A9F1F9F15FF7114DB326E611EB25356769EF",
          "retrieved_at": "2026-07-30T16:25:16.120Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-006"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-1.5",
      "safeguard_id": "1.5",
      "control": 1,
      "title": {
        "en": "Use a Passive Asset Discovery Tool",
        "zh": "被动发现"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Devices",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Include network segments where passive telemetry can lawfully and technically observe asset presence, particularly unmanaged, fragile, IoT and OT populations. Encrypted payloads still expose useful flow, MAC, protocol and fingerprint observations. Switched, wireless, east-west cloud and host-only traffic may remain invisible.",
          "zh": "覆盖适合且允许被动观测资产存在的网段，尤其是非受管、脆弱、IoT 和 OT。加密载荷仍可提供流量、MAC、协议和指纹线索，但交换网络、无线、云东西向和仅主机内流量可能不可见。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Place passive sensors or consume switch, flow, wireless-controller and cloud-flow telemetry at documented choke points. Maintain sensor health, tap/SPAN loss, clock, parser version and segment mapping; deduplicate observations and route unknown assets to 1.2 without letting a fingerprint silently overwrite authoritative identity.",
          "zh": "在已记录的关键点放置被动探针，或消费交换机、流日志、无线控制器与云流量遥测；持续监控传感器健康、TAP/SPAN 丢包、时钟、解析器版本和网段映射。去重后把未知资产送入 1.2，指纹不能悄悄覆盖权威身份。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A sensor that is online but sees no expected heartbeat has failed. TLS, NAT, overlay networks and asymmetric routing limit attribution; passive discovery cannot establish software inventory or authorization by itself. Safety or privacy exclusions state the data fields omitted, retention, compensating source and review date.",
          "zh": "探针在线却看不到应有心跳也算失败。TLS、NAT、Overlay 和非对称路由会限制归因；被动发现本身不能证明软件清单或授权。安全或隐私例外需写明删去哪些字段、保留期、替代来源和复核日。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Replay a benign test protocol and attach an unregistered device on each representative segment. Prove packet or flow arrival, classification, inventory correlation and alert latency; measure observable segments with healthy data over all segments selected for passive coverage, plus packet-drop and unknown-fingerprint rates.",
          "zh": "在各类代表网段回放无害协议并接入未登记设备，验证包或流到达、识别、台账关联和告警时延。覆盖率是有健康数据的选定网段/选定网段总体，同时报告丢包与未知指纹率。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "1.5",
          "control": 1,
          "title": {
            "en": "Use a Passive Asset Discovery Tool",
            "zh": "被动发现"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls1/",
          "snapshot_sha256": "AD366711310451131E32B0C9F9B8A9F1F9F15FF7114DB326E611EB25356769EF",
          "retrieved_at": "2026-07-30T16:25:16.120Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-2.1",
      "safeguard_id": "2.1",
      "control": 2,
      "title": {
        "en": "Establish and Maintain a Software Inventory",
        "zh": "软件总账"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Identify",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The population includes operating systems, installed packages, browser and office extensions, mobile apps, firmware where managed as software, container images, language dependencies, SaaS applications, cloud marketplace images and internally built releases. A package name alone cannot distinguish edition, version, source or support state.",
          "zh": "软件总体包括操作系统、安装包、浏览器与办公扩展、移动应用、按软件管理的固件、容器镜像、语言依赖、SaaS、云市场镜像和自研发布物。只有产品名，无法分辨版本、版本线、来源和支持状态。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Reconcile endpoint and server inventory, package managers, MDM, container registries, SBOMs, CI/CD catalogs, cloud and SaaS administration into one software authority linked to assets and business owners. Record publisher, product, version, install or deployment location, authorization, source, support channel and lifecycle dates; review at least twice yearly and on material change.",
          "zh": "把终端/服务器采集、包管理器、MDM、镜像仓库、SBOM、CI/CD、云与 SaaS 管理面统一到软件权威台账，并关联资产和业务责任人。记录发布者、产品、版本、部署位置、授权、来源、支持渠道和生命周期；半年复核之外，变更也要触发更新。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Agent-only inventories miss portable binaries, build-time dependencies, dormant images, SaaS purchased outside SSO and firmware. An SBOM leaves the match to the running artifact unverified until the two are reconciled. Development tools may be authorized in build zones and forbidden in production; authorization therefore binds software, version, source, environment and purpose.",
          "zh": "只靠 Agent 会漏掉便携程序、构建依赖、休眠镜像、未接 SSO 的影子 SaaS 和固件。存在 SBOM 不代表运行制品与其一致。开发工具可以在构建区获批、在生产区禁止，因此授权必须绑定软件、版本、来源、环境和用途。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Select samples from endpoints, clusters, repositories, cloud accounts and expense/SSO catalogs and trace both directions. Deploy an unauthorized package and an ephemeral container image to test detection. Report inventoried, unknown, unsupported, unowned, duplicate and unverifiable versions against a separately assembled deployment population.",
          "zh": "从终端、集群、仓库、云账号和费用/SSO 目录双向抽样。投放未授权软件包与短命容器镜像测试发现。以独立拼出的部署总体为分母，分别报告已登记、未知、不受支持、无主、重复和版本不可证实项。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "2.1",
          "control": 2,
          "title": {
            "en": "Establish and Maintain a Software Inventory",
            "zh": "软件总账"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls2/",
          "snapshot_sha256": "59F438759F8704D42D908FD3E9EF9D632BF2C2984A4F033713634B3AE616B64A",
          "retrieved_at": "2026-07-30T16:25:28.206Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-2.2",
      "safeguard_id": "2.2",
      "control": 2,
      "title": {
        "en": "Ensure Authorized Software is Currently Supported",
        "zh": "支持状态"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Identify",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Assess every authorized product and version against a named publisher or accountable internal support channel, including OS editions, firmware, libraries, container bases, appliances and SaaS features. “Still runs,” community activity and a reseller's assurance are not a supported lifecycle.",
          "zh": "逐项判断授权产品和版本是否有明确发布者或可问责的内部支持渠道，覆盖 OS 版本线、固件、库、容器基础、设备和 SaaS 功能。“还能运行”、社区有提交或代理商口头保证都不是受支持生命周期。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "The software owner records end-of-support dates, update channel, current supported target and migration decision. Review monthly or on vendor notice; unsupported items are upgraded, removed or placed under a time-bounded risk exception with isolation, monitoring and an exit plan.",
          "zh": "软件责任人记录停止支持日、更新渠道、当前受支持目标和迁移决定；至少每月或供应商通知时复核。不受支持项要升级、移除，或进入有期限的风险例外，带隔离、监测和退出计划。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "The current CAS measures reverse its “with exception” and “without exception” variables, so implementers must define their own stable denominator. Extended support counts only when a contract covers the exact edition and fixes the relevant risks. Frozen OT and embedded products need compensating controls and a replacement date, not permanent acceptance.",
          "zh": "CAS 把“有例外”和“无例外”变量写反，必须自建稳定分母。延长支持只有在合同覆盖准确版本并修复相关风险时才算。冻结的 OT/嵌入式系统需要补偿控制和替换日期，不能永久接受。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Verify lifecycle claims at the vendor or maintained-project source, then sample the deployed artifacts and use each artifact as the version authority. Measure supported deployments, documented exceptions and unapproved unsupported deployments over all authorized deployments; test that a simulated end-of-life notice opens affected-asset work.",
          "zh": "在厂商或维护项目的一手来源核验生命周期，并抽查实际部署版本而非台账标签。以全部授权部署为分母，分别计算受支持部署、书面例外和无批准的不受支持部署；模拟 EOL 通知，确认能生成受影响资产任务。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "2.2",
          "control": 2,
          "title": {
            "en": "Ensure Authorized Software is Currently Supported",
            "zh": "支持状态"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls2/",
          "snapshot_sha256": "59F438759F8704D42D908FD3E9EF9D632BF2C2984A4F033713634B3AE616B64A",
          "retrieved_at": "2026-07-30T16:25:28.206Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-007"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-2.3",
      "safeguard_id": "2.3",
      "control": 2,
      "title": {
        "en": "Address Unauthorized Software",
        "zh": "未授权软件处置"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Respond",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Include installed, portable, remotely executed, sideloaded, containerized and user-authorized SaaS software whose product, version, source, environment or purpose falls outside policy. Malware response may overlap, but ordinary unapproved utilities and shadow SaaS remain in this queue.",
          "zh": "范围包含以安装、便携、远程执行、侧载、容器和用户授权 SaaS 形式出现，且产品、版本、来源、环境或用途不符合政策的软件。恶意软件响应可能重叠，但普通未批准工具和影子 SaaS 仍归本项处理。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "At least monthly, join discovery to the authorized inventory and assign remove, block, quarantine or authorize decisions. Endpoint, cloud, platform and application owners enforce the action at the closest reliable control point and repair the acquisition path, privilege or repository policy that allowed recurrence.",
          "zh": "至少每月把发现结果与授权清单对账，作出移除、拦截、隔离或正式授权决定。终端、云、平台和应用负责人应在最可靠的控制点执行，并修复导致复发的采购路径、权限或仓库策略。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Forensic retention may delay deletion but requires execution prevention and custody. A hash allow rule cannot cover mutable scripts or signed-but-unapproved software. Developer freedom is bounded by environment and data access; recurring software after closure is a control failure, not a new isolated ticket.",
          "zh": "取证保全可以延迟删除，但需阻止执行并记录保管。哈希许可不能覆盖可变脚本或“已签名但未批准”软件。开发自由仍受环境和数据访问约束；结案后同一软件再出现，是控制失败，不是孤立新单。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Install a benign unapproved binary, extension and container in test scope; verify discovery, containment, ticket evidence and non-reinstallation. Use remediated unauthorized instances divided by all unauthorized instances found in the period; the CAS formula dividing by remaining findings becomes undefined at full remediation and can exceed one.",
          "zh": "在测试范围安装无害未批准二进制、扩展和容器，验证发现、控制、工单证据和不能再次安装。指标用周期内已处置未授权实例/全部发现实例；CAS 用“剩余未修项”作分母，全部修完时除零，部分情况下还会超过一。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "2.3",
          "control": 2,
          "title": {
            "en": "Address Unauthorized Software",
            "zh": "未授权软件处置"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls2/",
          "snapshot_sha256": "59F438759F8704D42D908FD3E9EF9D632BF2C2984A4F033713634B3AE616B64A",
          "retrieved_at": "2026-07-30T16:25:28.206Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-008"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-2.4",
      "safeguard_id": "2.4",
      "control": 2,
      "title": {
        "en": "Utilize Automated Software Inventory Tools",
        "zh": "自动化软件发现"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Cover all platforms capable of automated collection and declare where an agent, API, registry scan, package query or image analysis is used. Scanning only corporate laptops leaves servers, cloud images, containers, mobile, network appliances and remote assets outside the denominator.",
          "zh": "覆盖所有能自动采集的平台，并说明使用 Agent、API、仓库扫描、包查询还是镜像分析。只扫办公电脑，会把服务器、云镜像、容器、移动设备、网络设备和远程资产留在分母外。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Operate tools on a defined schedule, monitor collection age and failures, normalize product/version identities, and reconcile results to both asset and software authorities. Event-driven deployment and registry sources should supplement periodic scans for workloads shorter than the scan interval.",
          "zh": "按固定周期运行工具，监测采集年龄和失败，归一产品/版本身份，并同时与资产、软件台账对账。对寿命短于扫描周期的工作负载，用部署事件和镜像仓库补充周期扫描。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Unsupported platforms and privacy constraints require a named alternative source. Credentials that cannot enumerate system scope, offline devices and rate-limited APIs are coverage failures. Automated discovery supplies observation, not approval, publisher authenticity or support status.",
          "zh": "不支持的平台和隐私约束要有具名替代来源。凭据无法枚举全局、设备离线、API 限流都是覆盖失败。自动发现提供观测，不提供批准、发布者真实性或支持状态。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Measure assets with fresh, successful, sufficiently detailed results over eligible assets, then sample raw evidence against the normalized inventory. Seed one package and one portable artifact; test detection, version accuracy and removal. A tool installed but not reporting does not count as covered.",
          "zh": "以“成功且新鲜、信息足够的结果/符合条件的资产”为覆盖率，再把原始证据抽回归一台账核验。投放一个安装包和一个便携制品，测试发现、版本准确度与移除；Agent 已安装但不回报不能算覆盖。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "2.4",
          "control": 2,
          "title": {
            "en": "Utilize Automated Software Inventory Tools",
            "zh": "自动化软件发现"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls2/",
          "snapshot_sha256": "59F438759F8704D42D908FD3E9EF9D632BF2C2984A4F033713634B3AE616B64A",
          "retrieved_at": "2026-07-30T16:25:28.206Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-2.5",
      "safeguard_id": "2.5",
      "control": 2,
      "title": {
        "en": "Allowlist Authorized Software",
        "zh": "应用允许清单"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The executable population includes binaries, packages, installers, interpreters and application launch paths in the protected environment. Define whether policy is deny-by-default, audit-only or publisher/path based; broad writable paths and “any signed code” silently collapse the boundary.",
          "zh": "执行总体包括受保护环境里的二进制、安装器、解释器和应用启动路径。必须说明是默认拒绝、仅审计，还是按发布者/路径放行；可写目录和“所有签名代码”一旦大范围允许，边界就被掏空。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Build policy from known business workflows and trusted distribution, enforce at OS, endpoint, container admission or application control, and maintain emergency and update paths. Start in observation, remove noise, then enforce by environment; application owner and security owner jointly approve changes and review at least twice yearly.",
          "zh": "从已知业务流程和可信分发建立策略，在 OS、终端、容器准入或应用控制层执行，并保留应急与更新通道。先观察、降噪，再按环境强制；应用与安全责任人共同批准变更，至少半年复核。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Allowlisting does not judge safe behavior and cannot replace vulnerability or malware controls. Interpreters, macros, plugins, containers and remote tools can execute through an allowed parent. Break-glass exceptions are narrow, logged, expiring and tested; audit mode is not enforcement.",
          "zh": "允许清单不判断行为安全，不能替代漏洞和恶意软件控制。解释器、宏、插件、容器和远程工具能借获批父进程执行。破窗例外必须窄、可审计、会到期并经过测试；审计模式不等于强制。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Run approved applications and updates as positive controls, then unsigned, renamed, copied-to-writable-path and signed-but-unapproved binaries as negative controls. Measure eligible assets with enforcing policy and blocked unauthorized executions; retain policy version, decision and exception identity.",
          "zh": "以获批应用和更新作正控，以未签名、改名、复制到可写路径以及“已签名但未批准”二进制作负控。统计真正执行策略的合格资产和被拒绝的未授权执行，保留策略版本、判定和例外身份。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "2.5",
          "control": 2,
          "title": {
            "en": "Allowlist Authorized Software",
            "zh": "应用允许清单"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls2/",
          "snapshot_sha256": "59F438759F8704D42D908FD3E9EF9D632BF2C2984A4F033713634B3AE616B64A",
          "retrieved_at": "2026-07-30T16:25:28.206Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-009"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-2.6",
      "safeguard_id": "2.6",
      "control": 2,
      "title": {
        "en": "Allowlist Authorized Libraries",
        "zh": "库允许清单"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The population is every dynamically or statically incorporated library, framework, package, plugin and shared object used at build or runtime, including transitive dependencies and container layers. Filename, import name or a broad publisher is too weak when packages can be substituted.",
          "zh": "总体是构建或运行时直接、传递、动态或静态引入的库、框架、包、插件和共享对象，也包括容器层。仅靠文件名、导入名或宽泛发布者，无法防止包替换。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Pin approved component identity, version or constrained range, source repository, integrity digest and permitted application/environment in lockfiles, artifact repositories, build policy and runtime loading controls where supported. Block public-package fallback and unreviewed plugin directories; assign component owners and an emergency update path.",
          "zh": "在锁文件、制品仓库、构建策略和可支持的运行时加载控制中，固定组件身份、版本或窄范围、来源、完整性摘要和允许的应用/环境；阻断公共仓库回退和未审查插件目录，并设置责任人与紧急更新通道。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Static linking and vendoring hide runtime package queries; dynamically generated code and customer plugins need separate trust boundaries. A vulnerable but approved library still fails Control 7/16. The CAS dependency on network configuration does not establish this safeguard; software inventory, secure builds and repository trust do.",
          "zh": "静态链接和 Vendoring 会躲过运行时包查询；动态生成代码与客户插件需要单独信任边界。已批准但有漏洞的库仍违反 Control 7/16。CAS 依赖网络配置并不能建立本项，真正基础是软件台账、安全构建和仓库信任。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Build the same application with an approved component, an unexpected transitive dependency, a dependency-confusion name and a modified digest. Prove admission rejection or an explicit review, artifact/SBOM linkage and runtime match for sampled deployments. Coverage is protected build/deploy paths, not merely components listed.",
          "zh": "用获批组件、意外传递依赖、依赖混淆名称和被修改摘要分别构建同一应用，验证拒绝或显式评审、制品/SBOM 关联和抽样运行一致。覆盖率看受保护的构建/部署路径，不看列了多少组件。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "2.6",
          "control": 2,
          "title": {
            "en": "Allowlist Authorized Libraries",
            "zh": "库允许清单"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls2/",
          "snapshot_sha256": "59F438759F8704D42D908FD3E9EF9D632BF2C2984A4F033713634B3AE616B64A",
          "retrieved_at": "2026-07-30T16:25:28.206Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-010"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-2.7",
      "safeguard_id": "2.7",
      "control": 2,
      "title": {
        "en": "Allowlist Authorized Scripts",
        "zh": "脚本允许清单"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Include shell, PowerShell, Python, JavaScript, office macros, CI/CD definitions, infrastructure-as-code hooks and other interpreted automation wherever scripts can alter enterprise state. Extension and interpreter signature alone do not identify the actual content.",
          "zh": "包括 Shell、PowerShell、Python、JavaScript、办公宏、CI/CD 定义、基础设施代码钩子，以及所有可改变企业状态的解释执行内容。只看扩展名或解释器签名，不能识别脚本本身。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Enforce signed scripts, content hashes, controlled repositories, constrained interpreters and approved execution paths according to platform. Separate developer authoring from production execution, protect signing keys, record signer and review, and provide a logged, time-limited operational break-glass channel.",
          "zh": "按平台使用脚本签名、内容哈希、受控仓库、受限解释器和批准路径；把开发编写与生产执行分开，保护签名密钥，记录签署者与评审，并提供有日志、限时的运维破窗渠道。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Mutable network shares, generated scripts, notebooks and CI variables can change behavior without changing a filename. Signed malware or a compromised signing key remains allowed unless trust is revoked. Audit-only policies and user-writable allow paths do not pass; necessary unsigned legacy automation needs isolation, owner and retirement date.",
          "zh": "可写网络共享、生成脚本、Notebook 和 CI 变量能在文件名不变时改变行为。已签名恶意代码或被盗签名密钥仍会获准，除非撤销信任。仅审计、用户可写许可路径都不通过；必要的旧无签名脚本要隔离、具名并有退役日。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Execute an approved script, a one-byte-modified copy, an inline command, an encoded command and a trusted script from an untrusted path. Verify blocking or containment plus durable logs that preserve content identity and parent process; test key revocation and policy rollback.",
          "zh": "执行批准脚本、一字节修改副本、内联命令、编码命令和从不可信路径运行的可信脚本，验证阻断/隔离与能保留内容身份、父进程的持久日志；测试密钥撤销和策略回滚。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "2.7",
          "control": 2,
          "title": {
            "en": "Allowlist Authorized Scripts",
            "zh": "脚本允许清单"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls2/",
          "snapshot_sha256": "59F438759F8704D42D908FD3E9EF9D632BF2C2984A4F033713634B3AE616B64A",
          "retrieved_at": "2026-07-30T16:25:28.206Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-3.1",
      "safeguard_id": "3.1",
      "control": 3,
      "title": {
        "en": "Establish and Maintain a Data Management Process",
        "zh": "数据管理流程"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The process covers enterprise data through collection, creation, use, sharing, archival and disposal across endpoints, servers, databases, cloud, SaaS, backups, analytics, AI systems and service providers. Legal retention, privacy, security sensitivity and business value may impose different, sometimes conflicting clocks.",
          "zh": "流程覆盖数据从收集、创建、使用、共享、归档到销毁的全生命周期，横跨终端、服务器、数据库、云、SaaS、备份、分析、AI 和服务商。法律保留、隐私、安全敏感度与业务价值可能给出不同甚至冲突的时钟。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Assign a data owner and custodian model, sensitivity criteria, handling rules, minimum and maximum retention, disposal methods, approved transfer locations and exception authority. Legal, privacy, security and business owners resolve conflicts; review annually and whenever products, jurisdictions, providers or material data uses change.",
          "zh": "明确数据所有者与托管者、敏感度标准、处理规则、最短和最长保留、销毁方法、批准的传输位置及例外权。法务、隐私、安全和业务共同解决冲突；每年以及产品、司法辖区、服务商或重要用途变化时复核。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Unknown data starts at a conservative classification. Litigation hold suspends deletion only for the named scope and has release controls. Provider defaults, immutable backups, ML training copies and derived data require explicit treatment; a policy that says “retain as needed” or “securely delete” has no testable boundary.",
          "zh": "未知数据先按保守等级处理。诉讼保全只暂停具名范围的删除并需释放控制。服务商默认、不可变备份、ML 训练副本和派生数据都要明确；“按需保留”“安全删除”没有可测试边界。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Choose representative data types and trace each rule into a real system configuration and lifecycle event. Verify owner acknowledgement, retention and deletion jobs, transfer restrictions and exception decisions. The CAS document-completeness score establishes only that the design exists; enforcement requires observed job outcomes and transfer and exception decisions.",
          "zh": "挑选代表数据类型，把每条规则追到真实系统配置和生命周期事件，检查责任人确认、保留与删除任务、传输限制和例外决定。CAS 文档完整度分数只建立设计存在性；执行有效性需要任务结果、传输限制与例外决定的实测证据。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "3.1",
          "control": 3,
          "title": {
            "en": "Establish and Maintain a Data Management Process",
            "zh": "数据管理流程"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls3/",
          "snapshot_sha256": "11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09",
          "retrieved_at": "2026-07-30T16:25:28.667Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-3.2",
      "safeguard_id": "3.2",
      "control": 3,
      "title": {
        "en": "Establish and Maintain a Data Inventory",
        "zh": "数据清单"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Identify",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Inventory sensitive data sets and stores, their owners, purposes, classification, systems, regions, flows, processors, retention and deletion state; use a stable data-set or processing-activity identity as the counting unit, with individual rows and files retained as subordinate evidence. Include replicas, caches, logs, backups, test copies, exports and AI retrieval or training corpora.",
          "zh": "清点敏感数据集和存储位置、责任人、目的、分类、系统、地区、流向、处理方、保留与删除状态；用稳定的数据集或处理活动身份，不逐行逐文件凑数。副本、缓存、日志、备份、测试拷贝、导出以及 AI 检索/训练语料都在范围内。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Combine owner attestations with database/catalog scans, cloud and SaaS APIs, DLP discovery, schemas and data-flow records. Link each item to the asset/service inventory and management process, prioritize sensitive data, and update on creation or movement with at least annual reconciliation.",
          "zh": "把责任人声明与数据库/目录扫描、云和 SaaS API、DLP、Schema 和数据流记录结合，关联资产/服务台账与管理流程，优先敏感数据；创建、移动时更新，至少每年全量对账。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Encrypted or tokenized data remains in scope because keys, re-identification or use may preserve sensitivity. Unstructured, ephemeral, client-side, cross-account and provider-held copies need tailored discovery. The current CAS wrongly tests the item-count measure for age instead of its month measure; implement freshness independently.",
          "zh": "加密或 Token 化后，只要能用密钥、关联或业务用途重新识别，仍在范围。非结构化、短命、客户端、跨账号和服务商持有副本要用不同发现手段。CAS 错把条目数 M9 当“月数”比较，时效必须另算。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Seed labelled sensitive data into an approved store and an unapproved copy, then prove discovery, correct classification, owner routing and cleanup. Measure complete mappings over all discovered in-scope data sets, with unknown and partial mappings separate; sample inventory records back to live stores and vice versa.",
          "zh": "在批准存储和未批准副本各放一份有标签的敏感测试数据，验证发现、分类、路由责任人和清理。完整映射/全部发现数据集为指标，未知与部分映射单列，并从台账到实物、从实物到台账双向抽样。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "3.2",
          "control": 3,
          "title": {
            "en": "Establish and Maintain a Data Inventory",
            "zh": "数据清单"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls3/",
          "snapshot_sha256": "11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09",
          "retrieved_at": "2026-07-30T16:25:28.667Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-011"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-3.3",
      "safeguard_id": "3.3",
      "control": 3,
      "title": {
        "en": "Configure Data Access Control Lists",
        "zh": "数据访问权限"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The access population includes human, service, workload, support and provider identities reaching sensitive data through files, databases, APIs, applications, analytics, backups and administrative planes. A front-end role leaves enforcement on storage, export and emergency paths unverified.",
          "zh": "访问总体包含通过文件、数据库、API、应用、分析、备份和管理面接触敏感数据的人、服务、工作负载、支持和服务商身份。前端角色生效，不代表存储、导出和应急路径执行同一决定。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Translate owner-approved need-to-know into group, role, ACL, row/column, object and key policies at the authoritative control points. Remove direct grants, separate administration from data use, review inherited and public access, and make joiner/mover/leaver plus emergency access update every layer.",
          "zh": "把数据所有者批准的知情需要，落实为组、角色、ACL、行列、对象和密钥策略；清除直接授权，分开系统管理与数据使用，审查继承/公开访问，使入转离与应急访问同步更新每一层。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Counts of mapped data and account types are not interchangeable, despite the CAS formula. Shared accounts and ownerless data cannot pass. Encryption without separate key authorization does not repair an open ACL; database owners, cloud support and backup operators require explicit, logged boundaries and expiring exceptions.",
          "zh": "CAS 把“映射数据数”和“账户类型数”相除，量纲不同。共享账户和无主数据不能通过。加密若没有独立密钥授权，修不好开放 ACL；数据库所有者、云支持、备份人员需显式、可审计且会到期的边界。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "For sampled data sets, enumerate effective permissions and reconcile them to approved identities. Test an allowed user, a denied user, a stale group member, a service identity and an administrator through normal and alternate paths; retain policy, evaluator, decision and data-set identity.",
          "zh": "对抽样数据集枚举有效权限，并与批准身份对账。分别用允许用户、拒绝用户、过期组成员、服务身份和管理员走正常/替代路径，保留策略、评估器、决定和数据集身份。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "3.3",
          "control": 3,
          "title": {
            "en": "Configure Data Access Control Lists",
            "zh": "数据访问权限"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls3/",
          "snapshot_sha256": "11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09",
          "retrieved_at": "2026-07-30T16:25:28.667Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-012"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-3.4",
      "safeguard_id": "3.4",
      "control": 3,
      "title": {
        "en": "Enforce Data Retention",
        "zh": "保留期限执行"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The boundary includes primary stores, replicas, queues, logs, search indexes, endpoints, exports, backups and provider copies. Each data category needs both minimum and maximum periods, with event-based triggers where appropriate; the longest system default must not silently become policy.",
          "zh": "范围包括主存储、副本、队列、日志、搜索索引、终端、导出、备份和服务商副本。每类数据需要最短与最长周期，必要时由事件触发；不能让系统最长默认值悄悄变成政策。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Map rules to deletion, archival, legal-hold and backup-expiry jobs owned by data and platform teams. Store the triggering event, jurisdiction, policy version and hold state with the record or data set; monitor failed and delayed jobs and propagate deletion downstream.",
          "zh": "把规则落实为删除、归档、诉讼保全和备份到期任务，由数据与平台团队负责；把触发事件、司法辖区、政策版本和保全状态与记录或数据集绑定，监控失败/延迟并向下游传播删除。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Immutable backups may defer physical deletion until media expiry, so access isolation and documented maximum cycle define the compensating boundary. Regulatory conflicts are resolved per data set and jurisdiction. Unknown creation dates, orphan exports and indefinite “archive” tiers are failures until bounded.",
          "zh": "不可变备份可把物理删除推迟到介质到期，此时隔离访问和明确最长周期构成补偿边界。法规冲突按数据集与司法辖区解决。创建时间未知、孤儿导出和“永久归档”在得到边界前都失败。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Create test records with short expiry and hold states, advance time, then verify preservation before minimum, deletion after maximum, replica/index/cache propagation and auditable hold release. Measure eligible data sets whose live configurations and observed outcomes meet policy, not merely those with a written duration.",
          "zh": "创建短到期和被保全的测试记录，推进时间，验证最短期前保留、最长期后删除、对副本/索引/缓存传播以及保全释放可审计。指标看真实配置与结果都符合政策的数据集，不看有没有写周期。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "3.4",
          "control": 3,
          "title": {
            "en": "Enforce Data Retention",
            "zh": "保留期限执行"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls3/",
          "snapshot_sha256": "11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09",
          "retrieved_at": "2026-07-30T16:25:28.667Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-3.5",
      "safeguard_id": "3.5",
      "control": 3,
      "title": {
        "en": "Securely Dispose of Data",
        "zh": "安全处置"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Cover logical records, files, cryptographic keys, removable media, failed drives, cloud volumes, snapshots, backups, paper and provider-held data. Disposal means the information cannot be feasibly recovered under the declared threat model, not that a UI object disappeared.",
          "zh": "覆盖逻辑记录、文件、加密密钥、可移动介质、故障硬盘、云卷、快照、备份、纸张和服务商持有数据。销毁指在声明威胁模型下无法合理恢复，不是界面对象消失。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Select deletion, cryptographic erasure, overwrite, media destruction or provider workflow according to sensitivity and medium. Separate authorization from execution, maintain chain of custody, verify destruction vendors and ensure replicas, indexes, keys and retention locks are addressed.",
          "zh": "按敏感度和介质选择删除、密码擦除、覆写、物理销毁或服务商流程；授权与执行分离，维护保管链，验证销毁供应商，并处理副本、索引、密钥和保留锁。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Flash wear levelling, snapshots, immutable storage and SaaS deletion windows limit immediate erasure. Legal hold blocks only the named records. Key destruction counts only when no plaintext or alternate key remains. Reconcile the disposed population to vendor certification before accepting completion.",
          "zh": "闪存磨损均衡、快照、不可变存储和 SaaS 删除窗口会限制即时擦除。诉讼保全只拦截具名记录。只有不存在明文与备用密钥时，销毁密钥才算销毁；供应商证书未对总体，不能证明所有对象都处理了。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Run a controlled deletion through each disposal path and verify storage, backup, search, API and recovery behavior after the stated completion time. Inspect destruction certificates against asset/media identifiers and sample sanitized media with an approved recovery test.",
          "zh": "每条销毁路径走一份受控数据，在承诺完成时间后检查存储、备份、搜索、API 和恢复行为。把销毁证明与资产/介质标识对账，并用获批恢复测试抽样净化介质。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "3.5",
          "control": 3,
          "title": {
            "en": "Securely Dispose of Data",
            "zh": "安全处置"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls3/",
          "snapshot_sha256": "11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09",
          "retrieved_at": "2026-07-30T16:25:28.667Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-3.6",
      "safeguard_id": "3.6",
      "control": 3,
      "title": {
        "en": "Encrypt Data on End-User Devices",
        "zh": "终端全盘与数据加密"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Include enterprise data on laptops, desktops and managed mobile devices, plus local caches, swap, hibernation, removable storage and offline profiles. Full-disk encryption mainly protects powered-off or locked loss; it does not protect an authenticated session, synchronized cloud copy or attacker with keys.",
          "zh": "包括笔记本、台式机和受管移动设备上的企业数据，以及本地缓存、交换区、休眠、可移动存储和离线档案。全盘加密主要防丢失设备在关机/锁定时泄露，不能保护已登录会话、同步云副本或拿到密钥的攻击者。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Enforce platform-native encryption through MDM/endpoint configuration, escrow recovery material separately, bind keys to hardware and strong authentication, and block access when encryption is absent, suspended or recovery state is unhealthy. Define coverage for BYOD using container or application-level controls.",
          "zh": "通过 MDM/终端策略强制平台原生加密，恢复材料另处托管，密钥绑定硬件和强认证；加密缺失、暂停或恢复状态异常时阻断访问。BYOD 用容器或应用级控制另定覆盖。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A device reporting “encrypted” while auto-unlocked with an exposed key has weaker protection. Servers and databases belong under 3.11; removable media under 3.9. Unmanaged BYOD that cannot attest protection should receive browser-only or restricted data access, not an unverified exception.",
          "zh": "设备显示“已加密”但密钥裸露并自动解锁，保护更弱。服务器与数据库归 3.11，可移动介质归 3.9。无法证明保护的非受管 BYOD，只能获得浏览器或受限数据访问，不能给一个不可验证的例外。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Read actual encryption and key-protection state, not installed software. Test a compliant device, encryption suspension, recovery-key use, lost-device lock and a disk removed from the device; measure healthy encrypted eligible devices over all eligible devices, with last check time and exclusions.",
          "zh": "读取真实加密和密钥保护状态，不能只看软件安装。测试合规设备、暂停加密、恢复密钥使用、丢失设备锁定和拆盘读取；覆盖率以最近检查健康的已加密合格设备/全部合格设备计算，单列例外。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "3.6",
          "control": 3,
          "title": {
            "en": "Encrypt Data on End-User Devices",
            "zh": "终端全盘与数据加密"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls3/",
          "snapshot_sha256": "11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09",
          "retrieved_at": "2026-07-30T16:25:28.667Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-013"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-3.7",
      "safeguard_id": "3.7",
      "control": 3,
      "title": {
        "en": "Establish and Maintain a Data Classification Scheme",
        "zh": "分级体系"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Identify",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Define a small, ordered set of classifications tied to business impact and handling, covering confidentiality and any integrity or availability tiers the enterprise needs. Labels must apply consistently to structured, unstructured, derived and aggregated data; one harmless field can become sensitive in combination.",
          "zh": "建立少量、有顺序且直接对应业务影响和处理要求的分类；至少覆盖机密性，并按需要增加完整性/可用性等级。结构化、非结构化、派生与聚合数据要一致适用，单字段无害，组合后也可能敏感。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Publish decision rules, examples, default class, owner and reclassification process, then encode labels in catalogs, repositories, documents and policy engines. Resolve regulatory labels to the enterprise scheme without erasing their distinct obligations; review annually and on material data/use change.",
          "zh": "公布判断规则、示例、默认级别、责任人和重分类流程，在目录、仓库、文档和策略引擎中编码标签；把法规标签映射进体系但保留其独立义务，每年及数据/用途重大变化时复核。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "“Confidential” with no handling consequence is decorative. Automated classifiers have false positives and negatives and require sampling. Public data can still need integrity protection; declassification requires owner evidence, propagation to copies and confirmation that legal or contractual restrictions ended.",
          "zh": "没有处理后果的“机密”只是装饰。自动分类有误报漏报，必须抽样。公开数据仍可能需要完整性保护；降级须有责任人证据、传播到副本，并确认法律/合同限制已结束。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Give independent reviewers representative and ambiguous samples and measure agreement with the owner-approved answer. Trace each class to access, transfer, encryption, retention and disposal controls; seed a mislabelled item and verify detection and correction.",
          "zh": "给独立评审者代表性和模糊样本，测量与责任人批准答案的一致度。把每级追到访问、传输、加密、保留和销毁控制，投放误标对象，验证发现与纠正。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "3.7",
          "control": 3,
          "title": {
            "en": "Establish and Maintain a Data Classification Scheme",
            "zh": "分级体系"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls3/",
          "snapshot_sha256": "11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09",
          "retrieved_at": "2026-07-30T16:25:28.667Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-3.8",
      "safeguard_id": "3.8",
      "control": 3,
      "title": {
        "en": "Document Data Flows",
        "zh": "数据流图"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Identify",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Document where each material data set originates, moves, is transformed, crosses trust or jurisdiction boundaries and terminates, including APIs, queues, batch exports, email, analytics, backups, telemetry, SaaS/providers and AI retrieval/tool paths. Architecture boxes without data identity, purpose and direction are insufficient.",
          "zh": "记录每个重要数据集从哪里产生、向哪里移动、如何转换、跨越哪些信任或司法边界、在哪里终止，覆盖 API、队列、批量导出、邮件、分析、备份、遥测、SaaS/服务商和 AI 检索/工具路径。只有架构方框而无数据身份、目的和方向不够。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Generate flows from design records, service catalogs, gateway/mesh/cloud logs and owner interviews; bind source, destination, protocol, data class, purpose, controller/processor, region, protection and retention. Review annually and trigger change review from new integrations, routes, providers or processing purposes.",
          "zh": "从设计记录、服务目录、网关/服务网格/云日志和责任人访谈生成流向，绑定源、目的、协议、数据级别、用途、控制者/处理者、地区、保护和保留。每年复核，并由新集成、路由、服务商或用途触发变更审查。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Encrypted traffic still has a flow and destination. Serverless callbacks, browser-to-third-party transfers, support exports and vendor subprocessors are commonly missed. A zero observed count may mean telemetry failure; unknown flows are investigated, not excluded to improve coverage.",
          "zh": "加密流量仍然有流向与目的。Serverless 回调、浏览器直连第三方、支持导出和服务商分包最容易遗漏。观测为零也可能是遥测坏了；未知流先调查，不能为提高覆盖率而排除。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Select high-risk flows and trace documentation against observed network/application events in both directions. Add a test integration and verify inventory/change workflow; measure documented material flows over flows found by independent observation, with dormant, emergency and shadow paths called out.",
          "zh": "挑选高风险数据流，从文档到真实网络/应用事件双向追踪；新增一个测试集成验证台账/变更流程。覆盖率用独立观测发现的流为总体，单列休眠、应急和影子路径。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "3.8",
          "control": 3,
          "title": {
            "en": "Document Data Flows",
            "zh": "数据流图"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls3/",
          "snapshot_sha256": "11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09",
          "retrieved_at": "2026-07-30T16:25:28.667Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-3.9",
      "safeguard_id": "3.9",
      "control": 3,
      "title": {
        "en": "Encrypt Data on Removable Media",
        "zh": "可移动介质加密"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The population includes authorized USB storage, external drives, memory cards and other removable media carrying enterprise data, plus endpoints allowed to mount them. Phones used only as managed endpoints follow mobile policy; device transfer modes and virtual media may create equivalent paths.",
          "zh": "总体包括承载企业数据的授权 U 盘、移动硬盘、存储卡等介质，以及允许挂载它们的终端。手机若只作为受管终端，按移动策略处理；设备传输模式与虚拟介质可能形成等效路径。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Default-deny removable storage, then issue managed encrypted media with hardware or software keys, strong authentication, inventory and custody. Configure endpoints to write only through approved encryption, block unencrypted formats and define secure exchange with systems that cannot support the control.",
          "zh": "默认拒绝移动存储，只发放有硬件/软件加密、强认证、台账和保管链的受管介质。终端只允许通过批准加密写入并阻断明文格式；不能支持的系统走安全交换流程。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Installed host encryption leaves individual media writes unverified. OT/service workflows may need broker stations, one-way transfer and malware scanning. Lost keys, shared passwords, exported plaintext and vendor media need incident or exception handling with an expiry.",
          "zh": "主机装了加密软件，不代表每次写入都加密。OT/维修流程可使用中转站、单向传输和恶意软件扫描。丢失密钥、共享口令、明文导出与供应商介质需进入事件或有到期日的例外。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Insert approved encrypted, approved-but-unlocked, and unapproved/plain media into representative systems; verify mount/write decisions, encryption state, logs, key recovery and data readability off-device. Measure enforcing eligible endpoints and encrypted issued media separately.",
          "zh": "把批准加密介质、批准但未解锁介质和未批准明文介质插入代表系统，验证挂载/写入决定、加密状态、日志、密钥恢复和脱机可读性。终端强制覆盖与已发介质加密分别统计。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "3.9",
          "control": 3,
          "title": {
            "en": "Encrypt Data on Removable Media",
            "zh": "可移动介质加密"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls3/",
          "snapshot_sha256": "11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09",
          "retrieved_at": "2026-07-30T16:25:28.667Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-3.10",
      "safeguard_id": "3.10",
      "control": 3,
      "title": {
        "en": "Encrypt Sensitive Data in Transit",
        "zh": "传输中敏感数据加密"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Include sensitive data crossing process, host, network, account, provider and physical trust boundaries through web, API, messaging, database, file transfer, email, remote administration and service-to-service traffic. “Internal network” is not an automatic trusted exemption.",
          "zh": "包括敏感数据通过 Web、API、消息、数据库、文件传输、邮件、远程管理和服务间通信，跨越进程、主机、网络、账号、服务商或物理信任边界的所有路径。“内网”不能自动豁免。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Define approved protocols, versions, cipher/key and certificate trust for each flow; enforce at clients and services, disable downgrade and plaintext listeners, authenticate both ends where risk requires, and manage private keys, renewal and revocation. Application owners own endpoints; platform teams supply guardrails.",
          "zh": "逐条数据流规定协议、版本、算法/密钥和证书信任，在客户端与服务端强制，关闭降级和明文监听；风险需要时做双向认证，管理私钥、续期和撤销。应用负责人管端点，平台团队提供护栏。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "TLS termination changes the boundary: traffic behind the terminator needs a new decision. Encryption does not validate recipient authorization or stop endpoint logging. Legacy devices require an isolated gateway and retirement date; “provider encrypts” needs tenant-specific configuration and evidence.",
          "zh": "TLS 终止会产生新边界，终止器后的链路需重新决策。加密不证明接收方有权，也不能阻止端点记录。旧设备要放到隔离网关并有退役日；“服务商加密”需租户配置和证据。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Probe every representative endpoint and alternate route for plaintext, downgrade, expired/untrusted certificates, hostname failure and mutual-auth bypass. Capture negotiated protection and application authorization; send a canary through expected flows and verify that proxies, queues and providers do not expose a plaintext hop.",
          "zh": "探测各代表端点和替代路由的明文、降级、证书过期/不可信、主机名失败与双向认证绕过；记录协商保护和应用授权。发送金丝雀数据，确认代理、队列和服务商之间没有明文一跳。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "3.10",
          "control": 3,
          "title": {
            "en": "Encrypt Sensitive Data in Transit",
            "zh": "传输中敏感数据加密"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls3/",
          "snapshot_sha256": "11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09",
          "retrieved_at": "2026-07-30T16:25:28.667Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-3.11",
      "safeguard_id": "3.11",
      "control": 3,
      "title": {
        "en": "Encrypt Sensitive Data At Rest",
        "zh": "静态敏感数据加密"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Cover sensitive data in databases, object/block/file stores, application state, snapshots, replicas, search indexes, caches and backups on servers and providers. Storage-layer encryption meets the CIS minimum, while the threat model decides whether provider/admin separation or application-level keys are also required.",
          "zh": "覆盖服务器和服务商上数据库、对象/块/文件存储、应用状态、快照、副本、搜索索引、缓存和备份中的敏感数据。存储层加密达到 CIS 最低要求；威胁模型再决定是否需要隔离服务商/管理员或应用层密钥。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Enable encryption at each storage service, separate key administration from data administration where needed, set rotation/revocation and recovery, restrict plaintext exports, and bind key policy to data classification and tenant/account. Record which layer protects which copy.",
          "zh": "在每种存储启用加密，必要时分离密钥管理员与数据管理员，设置轮换、撤销、恢复，限制明文导出，并把密钥政策绑定数据分级与租户/账号；逐份记录是哪一层保护哪一副本。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "The current CAS inputs and M3/M4/M5 references are internally inconsistent; do not automate them verbatim. Server-side encryption with a provider-owned key protects lost media but may not constrain provider or tenant admins. Hashing, masking and tokenization are different controls and must preserve re-identification boundaries.",
          "zh": "CAS 的输入和 M3/M4/M5 引用互相矛盾，不能照抄自动化。服务端加密配服务商密钥能防介质丢失，却未必约束服务商或租户管理员。哈希、脱敏和 Token 化是不同控制，需保留重新识别边界。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Inspect live storage and key policies, then test authorized read, unauthorized identity, direct-media or snapshot access, key disablement and restore. Measure encrypted in-scope stores over discovered stores and separately report keys controlled by the same administrator.",
          "zh": "检查运行中的存储与密钥策略，测试授权读取、未授权身份、直接介质/快照访问、禁用密钥和恢复；以已发现存储为分母算加密覆盖，另报“数据与密钥由同一管理员控制”的比例。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "3.11",
          "control": 3,
          "title": {
            "en": "Encrypt Sensitive Data At Rest",
            "zh": "静态敏感数据加密"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls3/",
          "snapshot_sha256": "11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09",
          "retrieved_at": "2026-07-30T16:25:28.667Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-014"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-3.12",
      "safeguard_id": "3.12",
      "control": 3,
      "title": {
        "en": "Segment Data Processing and Storage Based on Sensitivity",
        "zh": "按敏感度隔离处理与存储"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The boundary follows data and workloads across network segments, cloud accounts/projects, clusters, databases, analytics and administration. A system inherits the highest sensitivity it can access unless a verified isolation mechanism prevents lower-trust components from crossing the boundary.",
          "zh": "边界随数据与工作负载跨网络区、云账号/项目、集群、数据库、分析和管理面移动。只要能访问更高敏感度数据，系统就继承最高级别，除非经过验证的隔离能阻止低信任组件越界。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Place high-sensitivity workloads in dedicated trust zones with explicit identity, network, storage and management-plane policy; restrict ingress, egress, replication and operator paths. Use architecture and data-flow records to drive placement and change admission, not VLAN names alone.",
          "zh": "把高敏工作负载置于专属信任区，在身份、网络、存储和管理面设显式策略，限制入口、出口、复制和运维路径。资产放置与变更准入由架构/数据流记录驱动，不能只靠 VLAN 名称。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Shared control planes, CI/CD, backup systems, observability, jump hosts and keys can bridge otherwise separate networks. Encryption alone does not create segmentation. Multi-tenant SaaS needs contractual and technical tenant-isolation evidence; an exception states the exact bridge, filters, monitoring and closure date.",
          "zh": "共享控制面、CI/CD、备份、可观测、跳板和密钥会跨过看似分离的网络。加密本身不构成隔离。多租户 SaaS 要有合同和技术租户隔离证据；例外写明准确桥接、过滤、监测和关闭日期。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Attempt access from lower-trust workloads, identities, networks and management planes; verify denial and alerting while approved flows still work. Trace every sensitive-data location to a permitted zone and every permitted zone back to an owner and data purpose.",
          "zh": "从低信任工作负载、身份、网络和管理面尝试访问，验证拒绝和告警，同时批准流仍正常。每个敏感数据位置要能追到允许区，每个允许区要能追到责任人和数据用途。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "3.12",
          "control": 3,
          "title": {
            "en": "Segment Data Processing and Storage Based on Sensitivity",
            "zh": "按敏感度隔离处理与存储"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls3/",
          "snapshot_sha256": "11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09",
          "retrieved_at": "2026-07-30T16:25:28.667Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-3.13",
      "safeguard_id": "3.13",
      "control": 3,
      "title": {
        "en": "Deploy a Data Loss Prevention Solution",
        "zh": "数据防泄漏"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "DLP scope spans endpoints, email, web, cloud storage, SaaS, collaboration, databases and sanctioned transfer paths where sensitive data can be identified or controlled. Coverage claims must state data types, channels, managed/unmanaged devices, encrypted traffic visibility and detect-only versus block mode.",
          "zh": "DLP 范围横跨终端、邮件、Web、云存储、SaaS、协作、数据库和所有能识别或控制敏感数据的批准传输路径。覆盖声明要写明数据类型、渠道、受管/非受管设备、加密流可见性，以及仅检测还是阻断。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Start from the data inventory and highest-consequence exfiltration paths, deploy classifiers and exact-data or fingerprint rules, route incidents to owners, tune with labelled samples and feed confirmed discoveries back to the inventory. Separate policy administration, exception approval and investigation.",
          "zh": "从数据台账与后果最高的外泄路径开始，部署分类器、精确数据或指纹规则，告警路由给责任人，用有标签样本调优，并把确认发现回写台账；分开策略管理、例外批准和调查职责。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "DLP cannot see end-to-end encrypted, unmanaged or unsupported paths and can harm privacy. Blocking may be unsafe for production transfers, so monitor-and-respond can be valid when explicitly bounded. Screenshots, photos, retyping, model prompts and approved-but-malicious insiders require other controls.",
          "zh": "DLP 看不到端到端加密、非受管或不支持路径，也可能侵害隐私。阻断若会伤害生产，可在明示范围内监测并响应。截图、拍照、重打、模型 Prompt 和有权限的恶意内部人需要其他控制。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Use true-positive, benign look-alike, obfuscated, compressed, encrypted and high-volume test data across each declared channel. Measure channel/population coverage, precision on adjudicated alerts, time to disposition and policy bypasses; an installed agent or license count is not successful coverage.",
          "zh": "在每条声明渠道发送真阳性、相似无害、混淆、压缩、加密和大批量测试数据。统计渠道/总体覆盖、经裁决告警精度、处置时间和绕过；Agent 或许可证数量不等于成功覆盖。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "3.13",
          "control": 3,
          "title": {
            "en": "Deploy a Data Loss Prevention Solution",
            "zh": "数据防泄漏"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls3/",
          "snapshot_sha256": "11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09",
          "retrieved_at": "2026-07-30T16:25:28.667Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-3.14",
      "safeguard_id": "3.14",
      "control": 3,
      "title": {
        "en": "Log Sensitive Data Access",
        "zh": "敏感数据访问日志"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Data",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Log reads, queries, exports, modification, deletion and permission/key changes for sensitive data, including human, service, provider-support and administrative paths. Infrastructure access logs alone may not identify the record or data set actually touched.",
          "zh": "记录敏感数据的读取、查询、导出、修改、删除以及权限/密钥变化，覆盖人、服务、服务商支持和管理员路径。只有基础设施访问日志，未必能说明触及了哪个记录或数据集。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Enable native database, storage, application and key audit events; preserve actor, effective identity, action, object/data set, result, time, source, volume and correlation context. Route to protected centralized storage, minimize unnecessary sensitive payloads, and link detections to owners.",
          "zh": "启用数据库、存储、应用和密钥原生日志，保留行为人、有效身份、动作、对象/数据集、结果、时间、来源、数量与关联上下文；集中到受保护存储，少记不必要的敏感载荷，并把检测关联责任人。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Bulk analytics, break-glass, support access, backups and application connection pools can obscure the real actor. Logging every row may be infeasible; statement, object and volume logs can meet the risk need if bounded. A configured logger that cannot survive tampering or is never reviewed supplies evidence but little control.",
          "zh": "批量分析、破窗、支持访问、备份和连接池会遮蔽真实行为人。逐行记录可能不可行，可在明确边界下用语句、对象和数量日志。记录器配置好了但可被篡改或无人复核，只提供薄弱证据。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Perform allowed read/update/delete/export and denied attempts with human and service identities, then trace complete events through collection, parsing, retention and review. Measure enabled, recently emitting in-scope data stores over all discovered stores, plus sampled event completeness and alert outcomes.",
          "zh": "用人和服务身份执行允许的读改删导出以及拒绝尝试，沿采集、解析、保留、复核全链路核验事件。覆盖率用已发现数据存储为分母，要求近期实际发出事件，并抽样字段完整性与告警结果。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "3.14",
          "control": 3,
          "title": {
            "en": "Log Sensitive Data Access",
            "zh": "敏感数据访问日志"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls3/",
          "snapshot_sha256": "11FD754951B6A390A90698DC500F38102544886E1DA073C7830910E2C338BB09",
          "retrieved_at": "2026-07-30T16:25:28.667Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-4.1",
      "safeguard_id": "4.1",
      "control": 4,
      "title": {
        "en": "Establish and Maintain a Secure Configuration Process",
        "zh": "资产与软件安全配置流程"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The process covers each supported asset and software family, version, role and environment, including endpoints, servers, mobile, IoT, operating systems, applications, databases, containers, cloud resources and provider-managed tenant settings. A benchmark name without profile, version and applicability decisions is not a configuration standard.",
          "zh": "覆盖每一种受支持的资产/软件族、版本、角色和环境：终端、服务器、移动、IoT、OS、应用、数据库、容器、云资源以及服务商管理但租户可配的设置。只写“采用某 Benchmark”而无 Profile、版本和适用判断，不是配置标准。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Create risk-based, version-controlled baselines from authoritative hardening guidance; document values, rationale, allowed deviations, deployment method, validation and rollback. Platform owners approve and automate them through images, MDM, configuration management, policy-as-code and CI/CD; review annually and on significant product, threat or architecture change.",
          "zh": "从权威加固指南生成风险化、版本化基线，写明取值、理由、允许偏差、部署、验证与回滚。平台负责人通过镜像、MDM、配置管理、策略即代码和 CI/CD 自动执行；每年及产品、威胁或架构重大变化时更新。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A secure setting can break safety, availability or vendor support, so deviations are exact, owned, compensated, expiring and retested. SaaS/provider settings and ephemeral workloads need API or deployment-time evidence. The CAS ratio measures documentation coverage; live asset enforcement requires a separate check.",
          "zh": "安全设置可能影响安全性、可用性或厂商支持，偏差因此必须精确、具名、有补偿、会到期并复测。SaaS/服务商设置与短命工作负载要靠 API 或部署时证据。CAS 的“有文档软件占比”不能证明真实资产执行了基线。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Build a clean instance from the baseline and test required business paths, then introduce a prohibited setting and verify drift detection and repair. Sample live assets against their exact baseline and report eligible, assessed, compliant, drifted, excepted and unevaluable populations with baseline and scanner versions.",
          "zh": "用基线构建干净实例并跑通业务，再引入一个禁止设置，验证漂移发现与修复。按准确基线抽查实时资产，分别报告符合条件、已评估、合规、漂移、例外和无法评估，并固定基线与扫描器版本。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "4.1",
          "control": 4,
          "title": {
            "en": "Establish and Maintain a Secure Configuration Process",
            "zh": "资产与软件安全配置流程"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls4/",
          "snapshot_sha256": "613D6086318545F0A7BA221AF501DC788ACDB3F79C3370D891E1D6EA2CF1190C",
          "retrieved_at": "2026-07-30T16:25:29.565Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-4.2",
      "safeguard_id": "4.2",
      "control": 4,
      "title": {
        "en": "Establish and Maintain a Secure Configuration Process for Network Infrastructure",
        "zh": "网络基础设施安全配置流程"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Include routers, switches, firewalls, wireless, load balancers, DNS/DHCP, VPN, SD-WAN, cloud networks, service meshes and management controllers across physical and virtual infrastructure. Managed-service responsibility changes who operates a setting, not whether the tenant-specific boundary exists.",
          "zh": "包括路由器、交换机、防火墙、无线、负载均衡、DNS/DHCP、VPN、SD-WAN、云网络、服务网格和管理控制器。托管服务只改变谁操作设置，不会取消租户边界。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Maintain versioned baselines by device role and trust zone covering management plane, authentication, protocols, routing, logging, time, services, backups and control-plane protection. Deploy through reviewed templates or APIs, protect secrets, validate syntax and state, and keep tested rollback and out-of-band recovery.",
          "zh": "按设备角色和信任区维护版本化基线，覆盖管理面、认证、协议、路由、日志、时间、服务、备份和控制面保护。通过评审模板/API 部署，保护秘密，验证语法与有效状态，并保留测试过的回滚和带外恢复。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "High availability pairs, controller-generated state and emergency routing can make text diffs misleading. Provider defaults, inherited policies and overlays require effective-state checks. Legacy equipment gets isolated management and replacement dates; an unreachable device is unevaluated, never compliant.",
          "zh": "HA 对、控制器生成状态与应急路由会让纯文本 Diff 误导。服务商默认、继承策略和 Overlay 要检查最终有效状态。旧设备需隔离管理并设替换日；不可达设备是未评估，绝不能算合规。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Compare running and intended configuration after normalization, sample devices from every role, and inject a harmless drift in a test segment. Verify approval, deployment, detection, rollback and log evidence; measure current successful assessments and exceptions against the authoritative device/control-plane population.",
          "zh": "归一化后比较运行与意图配置，从每种角色抽样，并在测试区注入无害漂移，验证批准、部署、发现、回滚和日志。分母取权威设备/控制面总体，要求本期成功评估；例外单列。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "4.2",
          "control": 4,
          "title": {
            "en": "Establish and Maintain a Secure Configuration Process for Network Infrastructure",
            "zh": "网络基础设施安全配置流程"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls4/",
          "snapshot_sha256": "613D6086318545F0A7BA221AF501DC788ACDB3F79C3370D891E1D6EA2CF1190C",
          "retrieved_at": "2026-07-30T16:25:29.565Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-4.3",
      "safeguard_id": "4.3",
      "control": 4,
      "title": {
        "en": "Configure Automatic Session Locking on Enterprise Assets",
        "zh": "自动会话锁定"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Eligible interactive sessions include desktop, laptop, mobile, virtual desktop, jump host and administrative consoles that can expose enterprise data or authority after inactivity. Service sessions, kiosks and operational displays need an explicit functional decision and remain in the population with their chosen treatment.",
          "zh": "适用会话包括台式机、笔记本、移动设备、VDI、跳板机和可暴露企业数据/权限的管理控制台。服务会话、自助终端和运维看板不能悄悄排除，必须有功能性决定。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Enforce no more than 15 minutes on general-purpose systems and two minutes on mobile through central configuration, with reauthentication on unlock. Choose shorter periods for privileged or exposed contexts, prevent ordinary users from extending them and coordinate with application/session controls where the OS lock leaves remote sessions alive.",
          "zh": "通用系统空闲锁定不超过 15 分钟，移动端不超过 2 分钟，解锁须重新认证；高权限或暴露场景可更短，普通用户不能放宽。若 OS 锁屏未结束远程会话，还要配合应用/会话控制。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A screen saver without authentication fails. Long-running dashboards, clinical stations and shared production consoles may use presence, badge, physical zoning or supervised kiosk controls under an expiring risk decision. Session lock limits walk-up misuse; it does not terminate tokens, network sessions or unattended batch authority.",
          "zh": "只有屏保而无认证即失败。看板、临床站和共用生产控制台可用人在场、工牌、物理分区或受监督 Kiosk 作为有期限补偿。锁屏降低离席滥用，不能撤销 Token、网络会话和批处理权限。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Measure effective live policy and last check for all eligible devices, then leave a session idle beyond the threshold and verify screen lock, protected data, remote/virtual behavior and reauthentication. Test policy tampering and resume from sleep; count unsupported and exception devices separately.",
          "zh": "读取全部合格设备的实时有效策略和最后检查时间，等待超过阈值，验证屏幕、数据、远程/虚拟会话与重新认证；再测试篡改策略和睡眠恢复。不支持与例外设备分列。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "4.3",
          "control": 4,
          "title": {
            "en": "Configure Automatic Session Locking on Enterprise Assets",
            "zh": "自动会话锁定"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls4/",
          "snapshot_sha256": "613D6086318545F0A7BA221AF501DC788ACDB3F79C3370D891E1D6EA2CF1190C",
          "retrieved_at": "2026-07-30T16:25:29.565Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-4.4",
      "safeguard_id": "4.4",
      "control": 4,
      "title": {
        "en": "Implement and Manage a Firewall on Servers",
        "zh": "服务器主机防火墙"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The server population includes physical, virtual, cloud and container hosts plus serverless or platform equivalents where a local or workload policy is available. Network firewalls do not automatically cover east-west, loopback, overlay, host-network and same-subnet paths.",
          "zh": "包括物理、虚拟、云和容器宿主服务器，以及有本地/工作负载策略能力的 Serverless 或平台等效物。网络防火墙不会自动覆盖东西向、Loopback、Overlay、同子网和 Host 网络路径。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Apply default-deny or least-exposure ingress and, where risk supports it, egress rules at host, workload, security-group or virtual-firewall layers. Generate policy from service ownership and flows, centrally manage changes, preserve break-glass access and reconcile listening services to allowed sources and ports.",
          "zh": "在主机、工作负载、安全组或虚拟防火墙层做默认拒绝或最小暴露，按风险控制出站；策略从服务责任和流向生成，集中变更，保留破窗，并把监听服务与允许源/端口对账。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Platform services and clustered control traffic need documented rules, not blanket any-to-any. Host policy absent because a product is unsupported requires compensating segmentation and a retirement plan. Installed software, an empty policy or “running” status is not proof of enforcement.",
          "zh": "平台服务和集群控制流需明确规则，不能一条全放。因不支持而无主机策略，需要补偿分段和退役计划。软件已装、策略为空或状态“运行”都不是强制证据。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "From allowed and disallowed source zones, test required ports, unexpected listeners, IPv4/IPv6, overlay and management paths. Inspect effective rules and enforcement status on every eligible server; verify disabling the agent or adding a local rule alerts and repairs without locking out recovery.",
          "zh": "从允许与不允许源区测试必需端口、意外监听、IPv4/IPv6、Overlay 和管理路径；检查所有合格服务器的有效规则和强制状态，验证停 Agent 或本地加规则能告警并修复，且不会锁死恢复。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "4.4",
          "control": 4,
          "title": {
            "en": "Implement and Manage a Firewall on Servers",
            "zh": "服务器主机防火墙"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls4/",
          "snapshot_sha256": "613D6086318545F0A7BA221AF501DC788ACDB3F79C3370D891E1D6EA2CF1190C",
          "retrieved_at": "2026-07-30T16:25:29.565Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-015"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-4.5",
      "safeguard_id": "4.5",
      "control": 4,
      "title": {
        "en": "Implement and Manage a Firewall on End-User Devices",
        "zh": "终端主机防火墙"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Cover managed desktops, laptops and other end-user devices on corporate, home, public, VPN and disconnected networks, for both IP families and every network profile. The CIS requirement is default-deny inbound except explicitly allowed services and ports.",
          "zh": "覆盖受管台式机、笔记本和其他终端在办公、家庭、公共、VPN 与离线网络上的 IPv4/IPv6 和全部网络 Profile。CIS 要求默认拒绝入站，仅显式允许服务/端口。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Centrally enforce host firewall profiles, block local user override, minimize inbound exceptions by application, source and profile, and keep outbound controls proportional to the threat model. MDM/endpoint owners monitor state and define safe recovery so a bad rule can be rolled back.",
          "zh": "集中强制各 Profile 的主机防火墙，阻止本地用户改写，按应用、来源与 Profile 收窄入站例外；出站控制按威胁模型决定。MDM/终端负责人监控状态并提供安全回滚。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Developer servers, peer collaboration, assistive technology and support tools need narrow time-bound rules. VPN split tunnelling and profile misclassification can select the wrong policy. The CAS operations/measures shift M2/M3/M4 labels, so consumers must map the intended numerator directly instead of executing the text mechanically.",
          "zh": "开发服务、协作、辅助技术和支持工具要有窄且限时规则。VPN 分流与网络 Profile 误判会选错政策。CAS 的操作与度量把 M2/M3/M4 错位，应直接按意图重建分子，不能机械执行。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Probe a representative device from trusted, guest and remote networks over IPv4/IPv6, verify allowed business functions and denied unexpected ports, then disable the firewall or change profile to test detection. Measure effective enforcing configurations over eligible devices, not installed components.",
          "zh": "从可信、访客和远程网络经 IPv4/IPv6 探测代表设备，验证业务通、意外端口拒绝；再停防火墙或切 Profile，检查发现。覆盖率看实时强制配置，不看安装组件。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "4.5",
          "control": 4,
          "title": {
            "en": "Implement and Manage a Firewall on End-User Devices",
            "zh": "终端主机防火墙"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls4/",
          "snapshot_sha256": "613D6086318545F0A7BA221AF501DC788ACDB3F79C3370D891E1D6EA2CF1190C",
          "retrieved_at": "2026-07-30T16:25:29.565Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-016"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-4.6",
      "safeguard_id": "4.6",
      "control": 4,
      "title": {
        "en": "Securely Manage Enterprise Assets and Software",
        "zh": "安全管理资产与软件"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Management scope includes local and remote administration of devices, operating systems, applications, cloud/SaaS, hypervisors, containers and infrastructure-as-code. It covers protocol security, management-plane reachability, administrator identity, change provenance, secrets and session recording where consequence requires it.",
          "zh": "管理范围是通过本地、远程、API 和 IaC 管理设备、OS、应用、云/SaaS、虚拟化与容器；同时覆盖协议、管理面可达性、管理员身份、变更来源、秘密，以及高后果场景的会话记录。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Route administration through dedicated trusted paths using SSH, HTTPS or equivalent authenticated encryption, central identity/MFA, least privilege and version-controlled changes. Disable Telnet/HTTP and direct public management, protect IaC state and keys, separate production administration, and log both API and interactive actions.",
          "zh": "经专用可信路径使用 SSH、HTTPS 或同等认证加密，接入集中身份/MFA 与最小权限；关闭 Telnet/HTTP 和公网上的直接管理，保护 IaC 状态/密钥，分隔生产管理，并记录 API 与交互行为。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Encryption alone does not make an exposed management plane safe. Vendor emergency channels, console ports, support tunnels and cloud root accounts require explicit custody and monitoring. Operationally essential insecure protocols stay inside isolated gateways with expiry and migration plans.",
          "zh": "加密不能让公开暴露的管理面自动安全。厂商应急通道、Console、支持隧道和云 Root 需明确保管与监测。确属运维必需的不安全协议只能留在隔离网关内，并有迁移期限。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Attempt management from an unauthorized network and identity, try insecure protocol and expired credential paths, then verify denial and alerting. Trace a sampled change from approval or commit through deployment, effective state and rollback; enumerate unmanaged interfaces and locally changed assets.",
          "zh": "从未授权网络和身份尝试管理，再测试不安全协议和过期凭据，验证拒绝/告警。从批准或提交追一笔变更到部署、有效状态和回滚，枚举未管理接口与本地变更资产。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "4.6",
          "control": 4,
          "title": {
            "en": "Securely Manage Enterprise Assets and Software",
            "zh": "安全管理资产与软件"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls4/",
          "snapshot_sha256": "613D6086318545F0A7BA221AF501DC788ACDB3F79C3370D891E1D6EA2CF1190C",
          "retrieved_at": "2026-07-30T16:25:29.565Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-4.7",
      "safeguard_id": "4.7",
      "control": 4,
      "title": {
        "en": "Manage Default Accounts on Enterprise Assets and Software",
        "zh": "默认账户"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Include factory, built-in, sample, guest, root, administrator, maintenance, cloud break-glass and vendor-support accounts across assets and software. Renaming an account does not remove its known identifier, privileges, recovery path or default credential.",
          "zh": "覆盖设备与软件里的出厂、内置、示例、Guest、Root、Administrator、维护、云破窗和厂商支持账户。改名不会改变已知 SID/权限、恢复路径或默认凭据。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Disable or render default accounts unusable; where impossible, rotate to unique managed secrets, restrict sources and roles, monitor use and assign an accountable custodian. Build the treatment into provisioning and verify upgrades or factory resets do not restore defaults.",
          "zh": "能禁则禁或使其不可用；不能禁则换为唯一受管秘密，限制来源/角色，监测使用并指定保管人。把处置写进自动预配，并验证升级和恢复出厂不会复活默认账户。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "The CAS formula lacks parentheses and can overstate the result. Shared vendor credentials, hidden support accounts and cloud-provider access need contract and technical controls. A default account required for recovery can remain enabled only with vaulted credentials, MFA where supported, alerting, periodic test and strict use conditions.",
          "zh": "CAS 公式缺括号，会高估结果。共享厂商凭据、隐藏支持账户和云服务商访问需要合同与技术控制。恢复必需账户可启用，但须密钥库、可支持时 MFA、告警、周期测试和严格使用条件。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Attempt authentication with published defaults and enumerate enabled built-in identities on representative systems. Test installation, upgrade and reset; reconcile every unavoidable enabled account to a unique secret, restriction and owner. The correct ratio is unusable-or-secured default accounts over identified defaults.",
          "zh": "在代表系统用公开默认凭据尝试登录并枚举已启用内置身份，测试安装、升级和重置；每个无法禁用的账户都要对到唯一秘密、限制和责任人。正确指标是“不可用或已安全处置的默认账户/已发现默认账户”。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "4.7",
          "control": 4,
          "title": {
            "en": "Manage Default Accounts on Enterprise Assets and Software",
            "zh": "默认账户"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls4/",
          "snapshot_sha256": "613D6086318545F0A7BA221AF501DC788ACDB3F79C3370D891E1D6EA2CF1190C",
          "retrieved_at": "2026-07-30T16:25:29.565Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-017"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-4.8",
      "safeguard_id": "4.8",
      "control": 4,
      "title": {
        "en": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software",
        "zh": "不必要服务与功能"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The population includes OS daemons, listeners, application modules, cloud features, management APIs, packages, browser services and container sidecars that are installed or enabled. “Authorized somewhere” does not make a service necessary on every role or reachable from every zone.",
          "zh": "范围包括 OS Daemon、监听器、应用模块、云功能、管理 API、包、浏览器服务和容器 Sidecar 中已安装或启用的功能。“在某处获批”不等于每种角色都需要，也不等于应从每个网段可达。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Define required services per asset role in the secure baseline, remove packages when practical, otherwise disable and block them, and prevent automatic re-enablement. Tie exceptions to a business dependency and observe actual listening sockets, processes and cloud/API configuration.",
          "zh": "按资产角色在安全基线中列必需服务，能卸载就移除，否则禁用并阻断，防止自动重启；例外绑定业务依赖，并观察真实监听端口、进程和云/API 配置。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Socket activation, scheduled tasks, containers and on-demand cloud features may be dormant during a snapshot. Disabling without removing can still leave exploitable code, while removal may break patching or support. Legacy dependencies need isolation and an exit milestone; authorized-but-misconfigured services remain failures under other safeguards.",
          "zh": "Socket 激活、计划任务、容器与按需云功能在快照时可能休眠。只禁不卸仍保留可利用代码，卸载又可能破坏补丁/支持。旧依赖要隔离并设退出里程碑；“必要但错误配置”的服务由其他 Safeguard 判失败。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Compare live services and ports to the role baseline, disable a benign test service and verify persistence after restart/update, then start an unapproved listener to test detection and remediation. Report unnecessary running, installed-disabled and unassessed separately.",
          "zh": "把实时服务与角色基线对比，禁用无害测试服务并验证重启/更新后仍禁用；再启动未批准监听测试发现和修复。未必需且运行、已安装但禁用、未评估分别报告。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "4.8",
          "control": 4,
          "title": {
            "en": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software",
            "zh": "不必要服务与功能"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls4/",
          "snapshot_sha256": "613D6086318545F0A7BA221AF501DC788ACDB3F79C3370D891E1D6EA2CF1190C",
          "retrieved_at": "2026-07-30T16:25:29.565Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-4.9",
      "safeguard_id": "4.9",
      "control": 4,
      "title": {
        "en": "Configure Trusted DNS Servers on Enterprise Assets",
        "zh": "可信 DNS 解析器"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Cover DNS settings and effective resolution paths on endpoints, servers, network devices, VPNs, mobile, cloud networks, containers and applications using embedded or encrypted DNS. The trusted set must specify resolver identity, purpose, policy and failover, not merely an IP address.",
          "zh": "覆盖终端、服务器、网络设备、VPN、移动、云网络、容器以及自带/加密 DNS 的应用之真实解析路径。可信集合要写明解析器身份、用途、政策和故障转移，不能只留 IP。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Enforce enterprise or explicitly approved resolvers through DHCP/RA, device policy, VPN, cloud and application configuration; authenticate encrypted DNS where used, control bypass, protect resolver administration and monitor fallback. Separate internal namespaces, public recursion and provider dependencies.",
          "zh": "通过 DHCP/RA、设备策略、VPN、云与应用配置强制企业或明确批准的解析器；使用加密 DNS 时认证对端，控制绕过，保护解析器管理并监控回退。内网命名、公共递归和服务商依赖分开。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Captive portals, roaming clients, split DNS, IPv6 RDNSS and application-level DoH can bypass endpoint settings. A reputable external resolver may still violate data or jurisdiction requirements. Resolver availability failover must not silently fall back to an untrusted path.",
          "zh": "Captive Portal、漫游、分区 DNS、IPv6 RDNSS 和应用 DoH 会绕开终端设置。知名公共解析器也可能不符合数据/地域要求。可用性回退不能悄悄落到不可信路径。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Resolve test names through normal and failure paths and confirm the actual resolver, policy response, logging and DNSSEC behavior where required. Attempt a rogue resolver, hard-coded public DNS and browser DoH; measure assets with verified effective paths over eligible assets.",
          "zh": "在正常与故障路径解析测试域名，确认实际解析器、策略结果、日志以及需要时 DNSSEC；再尝试 Rogue 解析器、硬编码公共 DNS 和浏览器 DoH。覆盖率以验证过的有效路径/合格资产计算。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "4.9",
          "control": 4,
          "title": {
            "en": "Configure Trusted DNS Servers on Enterprise Assets",
            "zh": "可信 DNS 解析器"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls4/",
          "snapshot_sha256": "613D6086318545F0A7BA221AF501DC788ACDB3F79C3370D891E1D6EA2CF1190C",
          "retrieved_at": "2026-07-30T16:25:29.565Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-4.10",
      "safeguard_id": "4.10",
      "control": 4,
      "title": {
        "en": "Enforce Automatic Device Lockout on Portable End-User Devices",
        "zh": "便携设备失败认证锁定"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Eligible devices are laptops, tablets and smartphones with local authentication and enterprise data or authority. CIS caps local failed attempts at 20 for laptops and 10 for phones/tablets; remote identity lockout and online rate limiting are related but distinct populations.",
          "zh": "适用设备是带本地认证且承载企业数据/权限的笔记本、平板和手机。CIS 上限是笔记本 20 次、手机/平板 10 次本地失败；远程身份锁定和在线限速属于相邻但不同总体。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Enforce thresholds through MDM/endpoint policy with escalating delay, lock or secure wipe appropriate to data and recovery risk. Protect recovery credentials, prevent user override and align biometric/PIN fallback, offline attempts and hardware-backed limits with the declared policy.",
          "zh": "通过 MDM/终端策略设置逐步延迟、锁定或按数据/恢复风险决定的安全擦除；保护恢复凭据，阻止用户放宽，并让生物/PIN 回退、离线尝试和硬件限制与政策一致。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Aggressive wipe can cause denial of service or destroy unsynchronized evidence; choose lock versus wipe deliberately. Devices without support require full encryption, restricted data and replacement. Help-desk reset and boot/recovery modes must not create an unmonitored bypass.",
          "zh": "过激擦除可造成拒绝服务或毁掉未同步证据，应明确选择锁还是擦。不支持设备需全盘加密、限制数据并替换。Helpdesk 重置和启动/恢复模式不能成为无监控绕过。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "On test devices, exceed the threshold using local, biometric-fallback and offline paths, verify lock state, data preservation or wipe, alerting and approved recovery. Inspect effective policy and last attestation for all eligible devices; assigned configuration profiles are supporting metadata.",
          "zh": "在测试设备经本地、生物回退和离线路径超过阈值，验证锁定、保留/擦除数据、告警和获批恢复；读取真实生效策略与最近证明，不看 Profile 是否“已分配”。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "4.10",
          "control": 4,
          "title": {
            "en": "Enforce Automatic Device Lockout on Portable End-User Devices",
            "zh": "便携设备失败认证锁定"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls4/",
          "snapshot_sha256": "613D6086318545F0A7BA221AF501DC788ACDB3F79C3370D891E1D6EA2CF1190C",
          "retrieved_at": "2026-07-30T16:25:29.565Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-4.11",
      "safeguard_id": "4.11",
      "control": 4,
      "title": {
        "en": "Enforce Remote Wipe Capability on Portable End-User Devices",
        "zh": "远程擦除"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Scope enterprise-owned portable devices and the enterprise workspace/data on supported personally owned devices. Remote wipe depends on enrolment, connectivity, identity and provider availability; it is a response capability, not assurance that every lost offline device is erased.",
          "zh": "范围是企业所有便携设备，以及受支持个人设备里的企业工作区/数据。远程擦除依赖已注册、联网、身份和服务商可用性；它是响应能力，不是“离线丢失设备必已清空”的保证。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Enroll devices before access, maintain MDM authority and last contact, separate full-device from selective wipe, require incident authorization and preserve a chain of actions. Pair with encryption, local lock, revocation of tokens/keys and recovery or legal-hold decisions.",
          "zh": "在授予访问前完成 MDM 注册，维护管理权和最后在线时间，区分全机与选择性擦除，要求事件授权并保留操作链；同时撤销 Token/密钥，配合加密、本地锁和取证/法务决定。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Powered-off, reset, jailbroken, unenrolled and permanently offline devices may never receive the command. BYOD usually permits selective enterprise wipe only. Wiping can conflict with evidence preservation and worker-owned data, so incident, legal and privacy owners define the decision boundary in advance.",
          "zh": "关机、重置、越狱、未注册或永久离线设备可能永收不到命令。BYOD 通常只能选择性擦除。擦除会与取证和员工私有数据冲突，事件、法务与隐私负责人须预先定义决策边界。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Use a sacrificial enrolled device to test command authorization, delivery, offline queueing, workspace/full wipe result, token revocation and audit receipt. Report capable/enrolled/recently reachable/tested populations separately; a button displayed in the console is not a completed wipe.",
          "zh": "用可牺牲受管设备测试命令授权、投递、离线排队、工作区/全机结果、Token 撤销和回执。分别报告支持、已注册、近期在线和已实测总体；控制台有按钮不等于擦除完成。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "4.11",
          "control": 4,
          "title": {
            "en": "Enforce Remote Wipe Capability on Portable End-User Devices",
            "zh": "远程擦除"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls4/",
          "snapshot_sha256": "613D6086318545F0A7BA221AF501DC788ACDB3F79C3370D891E1D6EA2CF1190C",
          "retrieved_at": "2026-07-30T16:25:29.565Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-4.12",
      "safeguard_id": "4.12",
      "control": 4,
      "title": {
        "en": "Separate Enterprise Workspaces on Mobile End-User Devices",
        "zh": "移动端企业工作区隔离"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The boundary separates enterprise applications, identities, data, clipboard, storage, backup and network paths from personal apps and accounts on supported mobile devices. A work profile icon leaves exports, notifications, screenshots, accessibility services and cloud-backup separation unverified.",
          "zh": "边界要把移动端企业应用、身份、数据、剪贴板、存储、备份和网络路径与个人应用/账户分开。看到“工作资料”图标，不代表导出、通知、截图、辅助服务或云备份都隔离。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Use managed work profiles or containers, managed app configuration, per-app VPN and data-transfer policies; block unmanaged destinations, personal backups and unauthorized account mixing. Define corporate-owned, COPE and BYOD profiles separately and make access conditional on attested workspace state.",
          "zh": "用受管工作 Profile/容器、受管应用配置、Per-app VPN 与数据传输策略，禁止去未管理目的、个人备份和账户混用；企业所有、COPE 与 BYOD 分别制定 Profile，访问取决于经证明的工作区状态。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Platform capabilities differ by OS version and ownership model. Some leakage paths cannot be fully blocked and require data minimization or browser-only access. The CAS metric M5 / M2 measures configured workspace coverage among identified mobile devices; it does not exercise clipboard, sharing, backup, notification, screenshot, or unsupported-device paths.",
          "zh": "各 OS 版本与所有权模式能力不同，有些泄漏路径无法完全阻断，需数据最小化或仅浏览器访问。CAS 的 M5 / M2 衡量已识别移动设备中的工作区配置覆盖率，没有测试剪贴板、分享、备份、通知、截图或不支持设备等路径。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Move test data through copy/paste, share sheets, open-in, screenshots, notifications, backups, keyboards, accessibility and personal cloud applications; verify intended allow/deny behavior and selective wipe. Measure eligible devices with healthy effective policy, not just an MDM agent.",
          "zh": "用测试数据遍历复制粘贴、分享、Open-in、截图、通知、备份、键盘、辅助功能和个人云应用，验证预期准入/拒绝与选择性擦除。覆盖率看健康的有效策略，不看 MDM Agent。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "4.12",
          "control": 4,
          "title": {
            "en": "Separate Enterprise Workspaces on Mobile End-User Devices",
            "zh": "移动端企业工作区隔离"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls4/",
          "snapshot_sha256": "613D6086318545F0A7BA221AF501DC788ACDB3F79C3370D891E1D6EA2CF1190C",
          "retrieved_at": "2026-07-30T16:25:29.565Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-018"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-5.1",
      "safeguard_id": "5.1",
      "control": 5,
      "title": {
        "en": "Establish and Maintain an Inventory of Accounts",
        "zh": "账户总账"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Identify",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Include all human, administrator and service accounts in directories, local systems, applications, databases, cloud/SaaS tenants, CI/CD, devices and provider portals, whether interactive, federated, dormant, disabled or emergency. Alias and federation records must resolve to the effective person or workload without hiding local bypass accounts.",
          "zh": "包括目录、本地系统、应用、数据库、云/SaaS、CI/CD、设备与服务商门户中的人、管理员和服务账户，无论交互式、联邦、休眠、禁用还是应急。别名和联邦记录要能还原到实际人或工作负载，不能遮住本地旁路账户。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Reconcile authoritative HR/vendor/workload sources with every authentication system at least quarterly and on lifecycle events. Record immutable account ID, type, owner/person, department or system, purpose, privilege, source, creation/start/stop, status and last review; preserve disabled records as audit evidence.",
          "zh": "至少每季度并在生命周期事件上，把 HR/供应商/工作负载权威源与所有认证系统对账。保存不可变账户 ID、类型、人员/责任人、部门/系统、用途、权限、来源、起止、状态和复核；禁用记录保留供审计。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "The current CAS formulas divide complete accounts by two and label unauthorized accounts as “accuracy,” producing invalid results. Shared, orphaned, guest, provider and emergency identities need owners and end dates. An account absent from the central directory is not out of scope when it can authenticate.",
          "zh": "CAS 把完整账户数除以 2，并把未授权账户率标成“准确度”，公式无效。共享、孤儿、Guest、服务商和应急身份都需责任人和结束日。只要仍能认证，没进中央目录也在范围。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Enumerate accounts independently from identity systems and compare both directions to the register. Create, transfer and terminate test identities, including a local and federated account, and verify authorization, metadata, disablement and audit preservation within SLOs.",
          "zh": "独立从身份系统枚举账户，与台账双向比较。创建、调岗、离职测试身份，覆盖本地和联邦账户，验证授权、字段、禁用和审计保留在 SLO 内完成。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "5.1",
          "control": 5,
          "title": {
            "en": "Establish and Maintain an Inventory of Accounts",
            "zh": "账户总账"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls5/",
          "snapshot_sha256": "067CD9797658BCF1080DAC4A01672E8CD9A550F6933CD3F3219369737E28A28A",
          "retrieved_at": "2026-07-30T16:25:30.015Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-019",
          "CAS-2026-07-31-020"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-5.2",
      "safeguard_id": "5.2",
      "control": 5,
      "title": {
        "en": "Use Unique Passwords",
        "zh": "唯一口令"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Every password-bearing account must use a secret not reused by another enterprise or personal account; cover users, local admins, devices, applications and break-glass identities. CIS gives length floors of eight characters with MFA and 14 without, while stronger modern policy should also screen compromised values and avoid predictable rotations.",
          "zh": "所有使用口令的账户都要与企业内其他账户及个人账户不复用，覆盖用户、本地管理员、设备、应用和破窗身份。CIS 给出有 MFA 至少 8 位、无 MFA 至少 14 位；更强实践还要阻止已泄露口令和可预测轮换。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Use an identity platform/password manager to generate and store unique secrets, block known-compromised and default passwords, rate-limit guessing, and migrate service accounts to managed keys or workload identity. Protect reset and recovery paths as strongly as sign-in; never collect plaintext for compliance.",
          "zh": "用身份平台/密码管理器生成、存储唯一秘密，拦截已泄露和默认口令，限制猜测，并把服务账户迁移到受管密钥或工作负载身份。重置和恢复路径需与登录同强度；不得收集明文做合规检查。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Uniqueness across systems cannot be proven by reversible comparison without creating risk; enforce generation and monitor exposure instead. MFA does not make eight-character shared passwords acceptable. Legacy maximum lengths, hard-coded devices and emergency accounts require vaulted random secrets, access monitoring and replacement plans.",
          "zh": "不能为了证明跨系统唯一而做可逆比对，那会制造泄露风险；应通过生成策略和暴露监测控制。MFA 不能让 8 位共享口令合理。旧系统长度上限、硬编码设备和应急账户需高熵随机秘密、密钥库、监测和替换计划。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Test policy at creation, change, reset and imported-account paths with short, known-breached and reused canary passwords where safe. Review effective enforcement and credential-compromise events, not a policy document alone; verify help-desk and legacy protocols cannot bypass length or MFA assumptions.",
          "zh": "在创建、修改、重置与导入路径安全测试短、已泄露和重复金丝雀口令，检查真实强制而非文档；确认 Helpdesk 与旧协议不能绕过长度或 MFA 前提。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "5.2",
          "control": 5,
          "title": {
            "en": "Use Unique Passwords",
            "zh": "唯一口令"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls5/",
          "snapshot_sha256": "067CD9797658BCF1080DAC4A01672E8CD9A550F6933CD3F3219369737E28A28A",
          "retrieved_at": "2026-07-30T16:25:30.015Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-5.3",
      "safeguard_id": "5.3",
      "control": 5,
      "title": {
        "en": "Disable Dormant Accounts",
        "zh": "休眠账户"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The population includes enabled human, administrative, guest, local, cloud, SaaS and service identities whose last meaningful activity can be determined. CIS calls for disablement or deletion after 45 inactive days where supported, but planned leave, emergency and non-interactive schedules need explicit semantics.",
          "zh": "包括启用的人、管理员、Guest、本地、云、SaaS 和服务身份，只要能可靠定义最后“有意义活动”。CIS 要求支持时 45 天后禁用/删除；计划休假、应急和非交互周期需另定语义。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Define activity per account type, calculate dormancy from reliable sign-in/use events, notify owners, disable before deletion and preserve audit links. Run at least daily or frequently enough to meet 45 days; excluded emergency/service identities receive use monitoring and scheduled owner recertification.",
          "zh": "按账户类型定义活动，使用可信登录/使用事件算休眠，通知责任人，先禁用后删除并保留审计关联。执行频率须足以满足 45 天；被排除的应急/服务身份需使用监测与定期责任人复核。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A password change, background token refresh or failed login may falsely appear active; an account can also remain dangerous while never signing in. Maternity/medical leave needs suspension and reactivation workflow. Service accounts belong to 5.5 lifecycle even when no interactive “last login” exists.",
          "zh": "改口令、后台刷新 Token 或失败登录可能假装“活跃”，账户即使从未登录也可能危险。产假/病假需要暂停与复开流程。没有交互式“最后登录”的服务账户按 5.5 生命周期治理。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Create a canary account, advance or simulate inactivity, and verify notification, disablement, session/token revocation and blocked sign-in. Sample last-activity accuracy across federated and local systems; measure enabled dormant accounts over all dormant accounts, with unknown activity separated.",
          "zh": "创建金丝雀账户，推进或模拟无活动，验证通知、禁用、会话/Token 撤销和登录阻断。从联邦与本地系统抽样核对最后活动；指标是仍启用的休眠账户/全部休眠账户，未知活动单列。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "5.3",
          "control": 5,
          "title": {
            "en": "Disable Dormant Accounts",
            "zh": "休眠账户"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls5/",
          "snapshot_sha256": "067CD9797658BCF1080DAC4A01672E8CD9A550F6933CD3F3219369737E28A28A",
          "retrieved_at": "2026-07-30T16:25:30.015Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-5.4",
      "safeguard_id": "5.4",
      "control": 5,
      "title": {
        "en": "Restrict Administrator Privileges to Dedicated Administrator Accounts",
        "zh": "专用管理员账户"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Cover every human with elevated authority across endpoint, server, network, cloud, SaaS, database, CI/CD and security tooling. The same person may hold user and admin identities, but ordinary browsing, email and productivity activity must occur under the non-privileged identity.",
          "zh": "覆盖终端、服务器、网络、云、SaaS、数据库、CI/CD 和安全工具上的每个人工高权限路径。同一人可有用户与管理员身份，但浏览、邮件和办公必须使用普通身份。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Issue named dedicated admin accounts, require strong MFA and privileged workstations or paths, remove elevation from daily accounts, and use just-in-time or task-scoped privilege where possible. Separate tiers so compromise of one admin context does not grant every layer; log elevation and break-glass use.",
          "zh": "发放实名专用管理员账户，要求强 MFA 和特权工作站/路径，从日常账户移除提权；尽可能使用 JIT/任务级权限。区分管理层级，避免一个上下文拿下全栈，记录提权与破窗。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A dedicated username used on the same contaminated workstation offers limited separation. Local sudo, cloud role assumption and application superuser paths must be included. Non-human privileges belong to service-account governance; emergency accounts remain isolated, vaulted, tested and monitored, with routine use prohibited.",
          "zh": "在同一已污染日常设备里换个用户名，隔离很弱。本地 sudo、云角色承担和应用 Superuser 都要算。非人权限归服务账户治理；应急账户隔离、入库、测试和监测，不能日常使用。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Attempt ordinary email/web access from an admin identity, administrative action from the daily identity, and cross-tier access; verify policy and alerts. Enumerate effective privilege independently from account labels and reconcile every privileged identity to an authorized administrator and non-privileged working account.",
          "zh": "从管理员身份尝试普通邮件/Web，从日常身份尝试管理，并测试跨层访问；验证策略和告警。独立枚举有效权限，不信账户名称，把每个高权身份对到获批管理员和其普通账户。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "5.4",
          "control": 5,
          "title": {
            "en": "Restrict Administrator Privileges to Dedicated Administrator Accounts",
            "zh": "专用管理员账户"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls5/",
          "snapshot_sha256": "067CD9797658BCF1080DAC4A01672E8CD9A550F6933CD3F3219369737E28A28A",
          "retrieved_at": "2026-07-30T16:25:30.015Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-5.5",
      "safeguard_id": "5.5",
      "control": 5,
      "title": {
        "en": "Establish and Maintain an Inventory of Service Accounts",
        "zh": "服务账户总账"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Identify",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Include non-human identities used by services, workloads, jobs, devices, integrations, bots, RPA, APIs and CI/CD across directories, clouds, SaaS and local systems, including certificates, API keys and federated workload roles. One shared “service account” for many workloads destroys ownership and revocation boundaries.",
          "zh": "包括服务、工作负载、Job、设备、集成、Bot、RPA、API 与 CI/CD 在目录、云、SaaS 和本地使用的非人身份，包括证书、API Key 与联邦角色。多个工作负载共用一个账户会摧毁责任和撤销边界。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Record owner/team, workload and environment, purpose, privilege, authentication system, credential type/location, creation, rotation/expiry, dependencies and quarterly review. Prefer short-lived workload identity and automatic rotation; bind issuance to deployed workload and decommission with the service.",
          "zh": "记录责任团队、工作负载/环境、用途、权限、认证系统、凭据类型/位置、创建、轮换/到期、依赖和季度复核；优先短期工作负载身份和自动轮换，发放绑定部署并随服务退役。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "The current CAS repeats the invalid inventory formulas from 5.1 and even tests three required fields against four. Accounts with no interactive login still need observed-use evidence. Vendor integrations, shared API tokens and orphaned CI variables require contract/source mapping, scoped privileges and expiry.",
          "zh": "CAS 重复 5.1 的无效公式，且三项必需字段却按四项算。无交互登录仍需实际使用证据。厂商集成、共享 API Token 和遗留 CI 变量需映射合同/来源、收窄权限并到期。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Enumerate non-human identities and credentials from each authentication/secret system, compare to deployed workloads and owners, and rotate/revoke a canary without outage. Test that an old secret fails and that use from the wrong workload or environment alerts.",
          "zh": "从每个认证/秘密系统枚举非人身份和凭据，与部署工作负载/责任人对账；轮换或撤销金丝雀，确认旧秘密失效，错误工作负载/环境使用会告警。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "5.5",
          "control": 5,
          "title": {
            "en": "Establish and Maintain an Inventory of Service Accounts",
            "zh": "服务账户总账"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls5/",
          "snapshot_sha256": "067CD9797658BCF1080DAC4A01672E8CD9A550F6933CD3F3219369737E28A28A",
          "retrieved_at": "2026-07-30T16:25:30.015Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-021"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-5.6",
      "safeguard_id": "5.6",
      "control": 5,
      "title": {
        "en": "Centralize Account Management",
        "zh": "集中账户管理"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Centralization applies to identities that supported systems can delegate to a directory or identity provider, across workforce, cloud and SaaS. It does not mean one failure domain for every trust tier, nor does an SSO tile prove local accounts and recovery paths are controlled.",
          "zh": "集中化适用于能委托目录/IdP 的 workforce、云和 SaaS 身份；不意味着所有信任层只有一个故障域，也不能以 SSO 磁贴证明本地账户和恢复路径受控。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Select authoritative identity services, federate applications, automate lifecycle and group/role provisioning, restrict local account creation, and maintain resilient break-glass access. Separate workforce, privileged, customer and workload identity where their assurance, availability or privacy requirements differ.",
          "zh": "选定权威身份服务，联邦应用，自动化生命周期与组/角色预配，限制本地账户创建，并维护弹性破窗。若 workforce、特权、客户和工作负载的保证、可用或隐私不同，应分域管理。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Legacy, OT and isolated systems may need local identities with compensating vaulting and reconciliation. Centralization can amplify compromise and outage, so admin separation, conditional access, logs and tested continuity are required. Multiple necessary identity domains are valid when their boundary is deliberate and governed.",
          "zh": "旧系统、OT 和隔离环境可保留本地身份，但要密钥库和对账。集中化会放大入侵与停机，必须分开管理、条件访问、日志和连续性。多个必要身份域可以合规，前提是边界有意且受治理。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Inventory every authentication point, test central disablement and role change through representative applications, and try a local/login recovery bypass. Measure eligible applications with enforced federation and lifecycle, plus remaining local accounts and unintegrated systems; test identity-provider outage and recovery.",
          "zh": "清点所有认证点，在代表应用测试中央禁用/调岗，并尝试本地登录和恢复旁路；指标包括强制联邦且生命周期可控的合格应用、残留本地账户和未集成系统，同时演练 IdP 故障与恢复。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "5.6",
          "control": 5,
          "title": {
            "en": "Centralize Account Management",
            "zh": "集中账户管理"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls5/",
          "snapshot_sha256": "067CD9797658BCF1080DAC4A01672E8CD9A550F6933CD3F3219369737E28A28A",
          "retrieved_at": "2026-07-30T16:25:30.015Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-6.1",
      "safeguard_id": "6.1",
      "control": 6,
      "title": {
        "en": "Establish an Access Granting Process",
        "zh": "访问授予流程"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The process covers employees, contractors, guests, partners, service identities and administrators gaining access through new hire, new workload, role or project change and emergency need. It must reach every authoritative system, including local and provider-managed privileges outside central provisioning.",
          "zh": "覆盖员工、承包商、Guest、伙伴、服务身份和管理员在入职、新工作负载、调岗/项目变化和应急时获得访问，且要到达所有权威系统，包括中央预配之外的本地和服务商权限。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Require identified requester, owner/manager approval, business purpose, role or entitlement, start/end time, segregation-of-duties check and target system; automate from authoritative events and make privileged or sensitive access expire by default. Preserve who approved and the exact effective entitlement.",
          "zh": "要求具名申请人、所有者/经理批准、业务目的、角色/权限、起止、职责冲突检查和目标系统；由权威事件自动化，高权或敏感访问默认到期。保留谁批准与最终有效权限。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A completed ticket is not a grant receipt, and group membership may yield hidden nested privilege. Pre-authorized birthright access still needs documented role logic. Service-provider support, shared links and data exports are access paths; emergency grants are logged, time-bounded and reviewed after use.",
          "zh": "工单完成不等于授权送达，组嵌套可能带来隐藏权限。预批准 Birthright 权限也要有角色逻辑。服务商支持、共享链接和数据导出都是访问路径；应急授权需日志、限时并事后复核。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Run canary new-hire, transfer, temporary and emergency requests, then compare approved access with effective accounts, groups, roles, keys and sessions at the promised time. Sample denials and rejected conflicts as well as successful grants; track late, excess and manually bypassed access.",
          "zh": "执行入职、调岗、临时和应急金丝雀请求，把批准访问与 SLO 时间点的真实账户、组、角色、密钥和会话比较；同时抽样拒绝与冲突请求，统计迟发、超权和手工旁路。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "6.1",
          "control": 6,
          "title": {
            "en": "Establish an Access Granting Process",
            "zh": "访问授予流程"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls6/",
          "snapshot_sha256": "F05309C876FA1A941F5B41071EE4764DAA9848B4EB967755B390547FE1F078C5",
          "retrieved_at": "2026-07-30T16:25:30.470Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-6.2",
      "safeguard_id": "6.2",
      "control": 6,
      "title": {
        "en": "Establish an Access Revoking Process",
        "zh": "访问撤销流程"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Scope termination, contract end, role/project change, rights removal, compromise and emergency containment for accounts, groups, roles, sessions, tokens, keys, devices, sharing links and physical/remote paths. Disabling one directory account may leave active SaaS sessions or local credentials.",
          "zh": "范围是离职、合同结束、调岗/项目变化、权利取消、账户受损和应急遏制，覆盖账户、组、角色、会话、Token、密钥、设备、分享链接与物理/远程路径。只禁一个目录账户，可能仍留 SaaS 会话和本地凭据。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Trigger immediate termination disablement and risk-based revocation SLOs, propagate to all authentication and authorization systems, revoke sessions/keys, recover assets and transfer ownership. Preserve the identity record for audit while removing effective access; automate reconciliation and escalate failures.",
          "zh": "离职立即禁用，按风险设撤权 SLO，传播到全部认证/授权系统，撤销会话/密钥、收回资产并转移所有权。保留身份记录供审计但清空有效权限；自动对账，失败升级。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Legal hold preserves data and logs, not access. Offline devices, provider delays and immutable credentials require network denial or key rotation. Shared accounts make individual revocation impossible and are a design defect; emergency access opened during an incident must have an automatic expiry and retrospective review.",
          "zh": "诉讼保全保存数据/日志，不保存访问。离线设备、服务商延迟和不可变凭据需网络阻断或换钥。共享账户无法个人撤权，本身就是设计缺陷；事件中开放的应急访问须自动到期和事后审查。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Simulate termination and role change for federated, local, mobile, cloud and service access; verify sign-in, existing sessions, API tokens, group inheritance and recovery paths all fail or change on time. Measure effective closure across systems, not HR-ticket completion.",
          "zh": "模拟联邦、本地、移动、云和服务访问的离职/调岗，验证登录、存量会话、API Token、组继承和恢复路径按时失效或改变。指标看系统实际关闭，不看 HR 工单结束。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "6.2",
          "control": 6,
          "title": {
            "en": "Establish an Access Revoking Process",
            "zh": "访问撤销流程"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls6/",
          "snapshot_sha256": "F05309C876FA1A941F5B41071EE4764DAA9848B4EB967755B390547FE1F078C5",
          "retrieved_at": "2026-07-30T16:25:30.470Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-022"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-6.3",
      "safeguard_id": "6.3",
      "control": 6,
      "title": {
        "en": "Require MFA for Externally-Exposed Applications",
        "zh": "外网应用多因素认证"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Include every enterprise or third-party application reachable from the Internet and every human account path, including native login, SSO, API or app passwords, password reset, support/admin portals and legacy protocols. Network location or obscurity is not a factor by itself.",
          "zh": "包括所有外网可达的企业/第三方应用及其人工账户路径：原生登录、SSO、API/App Password、重置、支持/管理门户和旧协议。网络位置和隐蔽性不能豁免。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Enforce phishing-resistant MFA where feasible through the application or IdP, disable bypass protocols, bind enrollment and recovery to strong identity proofing, and require step-up for sensitive actions. Inventory exceptions by application/account and make external exposure conditional on MFA readiness.",
          "zh": "在应用或 IdP 强制 MFA，能用则优先抗钓鱼因素，关闭绕过协议，强身份核验注册/恢复，敏感操作 Step-up；按应用/账户管理例外，外网暴露取决于 MFA 准备度。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "“Where supported” requires a replacement, gateway or risk-accepted isolation plan, not indefinite password-only access. Service-to-service APIs use strong workload authentication; human MFA applies to human interactions. SMS may satisfy a minimum but high-value and admin access needs stronger factors resistant to phishing and SIM takeover.",
          "zh": "“支持时”意味着替换、网关或有期限的隔离计划，不是永久口令登录。服务到服务 API 用强工作负载认证而非人工 MFA。短信可达最低要求，但高价值/管理访问应选抗钓鱼和 SIM 劫持的强因素。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Test valid MFA, password-only, legacy protocol, recovery, remembered-device, new-device and federated fallback paths for ordinary and privileged users. Measure accounts for which every interactive path enforces MFA, then monitor enrollment, bypass and failed challenge events.",
          "zh": "对普通和高权用户测试有效 MFA、仅口令、旧协议、恢复、记住设备、新设备和联邦回退。覆盖率只计算每条交互路径都强制 MFA 的账户，并监测注册、绕过与失败挑战。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "6.3",
          "control": 6,
          "title": {
            "en": "Require MFA for Externally-Exposed Applications",
            "zh": "外网应用多因素认证"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls6/",
          "snapshot_sha256": "F05309C876FA1A941F5B41071EE4764DAA9848B4EB967755B390547FE1F078C5",
          "retrieved_at": "2026-07-30T16:25:30.470Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-6.4",
      "safeguard_id": "6.4",
      "control": 6,
      "title": {
        "en": "Require MFA for Remote Network Access",
        "zh": "远程网络访问多因素认证"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The population is every human remote path into enterprise networks or equivalent private resources: VPN, ZTNA, VDI gateways, remote desktop, dial-up/management tunnels and vendor access. An externally exposed application covered by 6.3 does not automatically constitute network access.",
          "zh": "总体是所有人工远程进入企业网络或等效私有资源的路径：VPN、ZTNA、VDI 网关、远程桌面、拨号/管理隧道和厂商访问。6.3 的外网应用不自动等于网络接入。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Require MFA before network or resource access, bind the session to device and user context where appropriate, centrally authorize destinations and expire idle/maximum sessions. Separate vendor and administrator paths, disable split or fallback protocols that bypass the control, and log posture and factor decisions.",
          "zh": "网络或资源访问前强制 MFA，按需绑定设备/用户上下文，集中授权目的地并限制空闲/最长会话；分离厂商和管理员路径，关闭可绕过的分流/备用协议，记录姿态与因素决定。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Always-on device tunnels may authenticate machines before users and need a second user gate for sensitive resources. Offline recovery, provider outage and emergency access use bounded break-glass. MFA does not repair an over-broad VPN that places a user on every segment.",
          "zh": "Always-on 设备隧道可先认证机器，但敏感资源仍需用户关口。离线恢复、服务商故障和应急用有界破窗。MFA 修不好一条把用户放进所有网段的宽 VPN。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Attempt connection with password only, stolen/expired token, unenrolled device, alternate VPN protocol and existing session after account disablement. Verify denial, destination scope, logs and session revocation; enumerate gateways and accounts independently.",
          "zh": "用仅口令、被盗/过期 Token、未注册设备、替代 VPN 协议，以及账户禁用后的现有会话连接，验证拒绝、目的范围、日志和会话撤销；独立枚举网关与账户。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "6.4",
          "control": 6,
          "title": {
            "en": "Require MFA for Remote Network Access",
            "zh": "远程网络访问多因素认证"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls6/",
          "snapshot_sha256": "F05309C876FA1A941F5B41071EE4764DAA9848B4EB967755B390547FE1F078C5",
          "retrieved_at": "2026-07-30T16:25:30.470Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-6.5",
      "safeguard_id": "6.5",
      "control": 6,
      "title": {
        "en": "Require MFA for Administrative Access",
        "zh": "管理访问多因素认证"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Cover every human administrative path to assets and software, on-premises or provider-hosted: console, SSH/RDP, cloud control plane, SaaS admin, database, hypervisor, CI/CD and security tools. Local console and recovery interfaces remain in scope where supported.",
          "zh": "覆盖所有人工管理路径：Console、SSH/RDP、云控制面、SaaS 管理、数据库、虚拟化、CI/CD、安全工具以及服务商托管系统；支持的本地 Console 和恢复接口也在范围。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Require strong MFA at the authoritative elevation or administrative session, prefer phishing-resistant factors, separate admin identities, protect enrollment/recovery, and eliminate protocols that accept only passwords. Use privileged access workflows and short-lived credentials for high consequence systems.",
          "zh": "在权威提权或管理会话强制 MFA，优先抗钓鱼因素，分离管理身份，保护注册/恢复并淘汰仅口令协议。高后果系统使用 PAM 与短期凭据。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Workload/service administration uses scoped machine credentials, not human MFA. Some offline consoles cannot support MFA and require physical control, dual custody, vaulted credentials and migration. A bastion with MFA does not pass if the target still accepts a direct password path.",
          "zh": "工作负载管理用范围化机器凭据，不用人工 MFA。有些离线 Console 不支持，需要物理控制、双人保管、密钥库和迁移。跳板机有 MFA 但目标仍接受直连口令，不能通过。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Test direct, federated, command-line, API-assisted, local/recovery and vendor-support paths with and without the second factor; verify a disabled factor or user kills active privilege. Reconcile effective administrative accounts to MFA policy and recent authentication evidence.",
          "zh": "通过直连、联邦、命令行、API 辅助、本地/恢复和厂商支持路径，在有无第二因素情况下测试；禁用因素/用户后高权会话应失效。把有效管理员账户与 MFA 策略和近期认证证据对账。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "6.5",
          "control": 6,
          "title": {
            "en": "Require MFA for Administrative Access",
            "zh": "管理访问多因素认证"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls6/",
          "snapshot_sha256": "F05309C876FA1A941F5B41071EE4764DAA9848B4EB967755B390547FE1F078C5",
          "retrieved_at": "2026-07-30T16:25:30.470Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-6.6",
      "safeguard_id": "6.6",
      "control": 6,
      "title": {
        "en": "Establish and Maintain an Inventory of Authentication and Authorization Systems",
        "zh": "认证与授权系统总账"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Identify",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Include directories, IdPs, MFA, PKI, PAM, SSO brokers, authorization engines, cloud IAM, local account stores, secrets managers and external providers that issue identities, credentials or decisions. Map trust, federation and recovery relationships; listing product names alone hides the real authority chain.",
          "zh": "包括目录、IdP、MFA、PKI、PAM、SSO Broker、授权引擎、云 IAM、本地账户库、秘密管理器和外部身份商；凡能发身份、凭据或决定都在范围。要画出信任、联邦与恢复关系，产品名列表不够。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Record owner, purpose, tenants/regions, assurance methods, upstream/downstream trusts, admin and break-glass paths, data, availability/recovery, supported lifecycle and last review. Reconcile software, cloud/SaaS and architecture inventories at least annually and on any trust or provider change.",
          "zh": "记录责任人、用途、租户/地区、保证方式、上下游信任、管理/破窗路径、数据、可用/恢复、支持生命周期与复核日；至少每年及信任/服务商变化时与软件、云/SaaS、架构台账对账。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "The CAS denominator uses current inventory and omits authorized systems missing from that inventory, which can inflate the score. Embedded application stores, social login, customer identity and provider recovery channels remain in scope. An unused configured trust is still an attack path until removed.",
          "zh": "CAS 用“当前台账系统数”作分母，漏记系统反而会提高分数。嵌入式应用账户库、社交登录、客户身份和服务商恢复通道仍在范围。未使用但已配置的信任，移除前仍是攻击面。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Trace representative sign-in and authorization decisions end to end, then disable a link or test tenant to verify known dependencies and fail behavior. Compare live federation metadata, applications, certificate issuers and secret systems to the inventory; measure authorized systems over independently discovered authorities.",
          "zh": "端到端追踪代表登录和授权，再停一个测试信任链，验证依赖和故障模式；把实时联邦 Metadata、应用、证书签发者和秘密系统与台账比较，分母取独立发现的全部权威系统。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "6.6",
          "control": 6,
          "title": {
            "en": "Establish and Maintain an Inventory of Authentication and Authorization Systems",
            "zh": "认证与授权系统总账"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls6/",
          "snapshot_sha256": "F05309C876FA1A941F5B41071EE4764DAA9848B4EB967755B390547FE1F078C5",
          "retrieved_at": "2026-07-30T16:25:30.470Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-6.7",
      "safeguard_id": "6.7",
      "control": 6,
      "title": {
        "en": "Centralize Access Control",
        "zh": "集中访问控制"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The safeguard centralizes authorization where assets and software support a directory or SSO, while preserving resource-level enforcement. Authentication centralization alone does not ensure groups, roles, data scopes and tenant policies produce a least-privilege decision.",
          "zh": "集中化适用于支持目录或 SSO 的资产与软件，同时仍要在资源层执法。认证集中不代表组、角色、数据范围和租户策略能给出最小权限决定。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Use central groups, roles, policy engines or identity-aware proxies to drive access; automate provisioning/deprovisioning, restrict local grants and reconcile effective permissions. Define which decisions remain at the application and how central identity, attributes and resource policy combine.",
          "zh": "用中央组、角色、策略引擎或身份代理驱动访问，自动预配/撤销，限制本地授权并对账有效权限；明确哪些决定留在应用，以及中央身份、属性和资源策略如何组合。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "An IdP outage or compromise becomes systemic, requiring separated administration, resilient break-glass and tested recovery. Offline, OT and legacy systems may retain local authorization under compensating review. SSO convenience without centralized revocation or resource policy does not satisfy the intent.",
          "zh": "IdP 故障或失陷会系统性扩散，需要分权管理、弹性破窗和恢复。离线、OT、旧系统可在补偿审查下本地授权。只有 SSO 便利、没有集中撤销和资源策略，不满足本意。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Change a central role and verify access changes across representative systems, then attempt a local account, direct object permission and stale token bypass. Measure eligible systems with enforced central decision and lifecycle, plus orphan local grants and policy drift.",
          "zh": "改变中央角色，验证代表系统访问同步变化；再尝试本地账户、直接对象权限和旧 Token 绕过。覆盖率看强制中央决策与生命周期的合格系统，并另列孤儿本地授权和策略漂移。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "6.7",
          "control": 6,
          "title": {
            "en": "Centralize Access Control",
            "zh": "集中访问控制"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls6/",
          "snapshot_sha256": "F05309C876FA1A941F5B41071EE4764DAA9848B4EB967755B390547FE1F078C5",
          "retrieved_at": "2026-07-30T16:25:30.470Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-6.8",
      "safeguard_id": "6.8",
      "control": 6,
      "title": {
        "en": "Define and Maintain Role-Based Access Control",
        "zh": "基于角色的访问控制"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Users",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The role model covers human job functions and, where useful, workload functions across enterprise assets and data. Roles must express necessary rights and constraints; copying current entitlements into hundreds of one-person roles only hides privilege accumulation.",
          "zh": "角色模型覆盖人工岗位，也可覆盖工作负载职能；角色必须表达必要权利与约束。把现状权限复制成数百个“一人一角色”，只会遮住权限累积。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Define business-owned roles, permissions, eligibility, approval, segregation conflicts and lifecycle; separate base, elevated and temporary access. Map accounts to roles, control direct exceptions, perform at least annual effective-access review and redesign roles when organization or systems change.",
          "zh": "由业务定义角色、权限、资格、批准、职责冲突和生命周期，分开基础、提升与临时访问；账户映射角色，控制直接例外，至少每年审查有效权限，组织或系统变化时重构。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "RBAC alone handles context, attributes and object ownership poorly, so ABAC or relationship controls may supplement it under the same governance. Emergency and project-specific grants need expiry. Dormant roles, excessive birthright access and rubber-stamp recertification are failures even with 100% role assignment.",
          "zh": "RBAC 不擅长上下文、属性和对象关系，可由 ABAC/关系控制补充，但归同一治理。应急与项目授权要到期。休眠角色、过宽 Birthright 和走过场复核，即使 100% 分配角色仍失败。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Test representative tasks for allowed and disallowed roles, inspect nested groups and direct grants, and verify role change removes old access. Reviewers see effective permissions and recent use, not just role names; record approval, removals and unresolved toxic combinations.",
          "zh": "用允许/不允许角色执行代表任务，检查嵌套组和直接授权，并验证调岗移除旧权。评审人看到实际权限和近期使用，而非角色名；记录批准、移除和未解 Toxic Combination。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "6.8",
          "control": 6,
          "title": {
            "en": "Define and Maintain Role-Based Access Control",
            "zh": "基于角色的访问控制"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls6/",
          "snapshot_sha256": "F05309C876FA1A941F5B41071EE4764DAA9848B4EB967755B390547FE1F078C5",
          "retrieved_at": "2026-07-30T16:25:30.470Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-7.1",
      "safeguard_id": "7.1",
      "control": 7,
      "title": {
        "en": "Establish and Maintain a Vulnerability Management Process",
        "zh": "漏洞管理流程"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The process covers vulnerabilities and material misconfigurations across inventoried assets, software, firmware, cloud/SaaS, containers, applications and dependencies from discovery through ownership, prioritization, treatment, verification and closure. It states which populations or finding types each source cannot assess.",
          "zh": "覆盖台账内资产、软件、固件、云/SaaS、容器、应用和依赖中的漏洞与重要错误配置，从发现一直到认领、排序、处置、验证、关闭；同时写明各数据源看不到哪些总体或缺陷类型。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Define accountable owners, approved scanners and intelligence, authenticated/unauthenticated methods, cadence, severity and exposure inputs, ticketing, exception, disclosure, emergency action and metrics. Review annually and whenever architecture, threat, tooling or business risk changes; keep credentials and scanning safety under control.",
          "zh": "定义责任人、批准扫描器/情报、有/无凭据方法、周期、严重度与暴露输入、工单、例外、披露、应急和指标。每年及架构、威胁、工具、业务风险变化时更新，并控制扫描凭据和生产安全。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A CVE count is not risk, and absence of a scanner result is not absence of vulnerability. SaaS/provider findings, unsupported OT, source code and cloud configuration need distinct evidence. Penetration tests and incidents feed the same process without being reduced to routine scanner tickets.",
          "zh": "CVE 数量不等于风险，扫描没结果不等于没漏洞。SaaS/服务商、不能扫的 OT、源代码和云配置需要不同证据。渗透测试和事件也进入同一流程，但不能被压成普通扫描工单。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Walk one finding from source identity and affected asset through triage, owner, due date, remediation, rescan and closure, plus one false positive and one accepted risk. Inspect stale queues, missing assets, scanner failures and reopened findings; document how source and asset identities are deduplicated.",
          "zh": "把一个发现从来源身份、受影响资产一路追到分诊、责任人、到期、修复、复扫和关闭，再追一个误报和一个风险接受；检查陈旧队列、漏资产、扫描失败和重开，并说明怎样合并来源/资产身份。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "7.1",
          "control": 7,
          "title": {
            "en": "Establish and Maintain a Vulnerability Management Process",
            "zh": "漏洞管理流程"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls7/",
          "snapshot_sha256": "BA2036413BBF89630CCF02B4B304353CB97FCCEB11F22AD1F95FB6408A06830B",
          "retrieved_at": "2026-07-30T16:25:31.916Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-7.2",
      "safeguard_id": "7.2",
      "control": 7,
      "title": {
        "en": "Establish and Maintain a Remediation Process",
        "zh": "风险化修复流程"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The remediation strategy covers patches, upgrades, configuration changes, compensating controls, removal, isolation and accepted risk for every finding source. Priority depends on exploitability, exposure, privilege path, asset/data consequence, control coverage and active exploitation, not a severity score alone.",
          "zh": "修复策略覆盖补丁、升级、配置、补偿、移除、隔离和风险接受，适用于全部发现来源。优先级结合可利用性、暴露、权限链、资产/数据后果、现有控制和活跃利用，不能只看一个分数。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Set treatment and verification SLOs by risk, establish emergency lanes, dependency and outage handling, change ownership, exception expiry and executive escalation. Review the queue and strategy at least monthly, while urgent exploited or Internet-facing conditions trigger action immediately.",
          "zh": "按风险设处置与验证 SLO、应急车道、依赖/停机处理、变更责任、例外到期和高层升级。至少每月复核全队列；正在利用或公网高危条件须立即行动。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "An exception is an owned treatment with evidence, compensating controls, expiry and re-evaluation, not “business accepted.” Vendor patch absence does not stop isolation or exposure reduction. Mean closure time can hide an old dangerous tail, so publish risk-age distributions and overdue high-consequence items.",
          "zh": "例外是有证据、有补偿、有到期和复评的具名处置，不是“业务接受”四个字。厂商无补丁仍可隔离/降暴露。平均关闭时间会遮住危险长尾，应公布风险年龄分布和逾期高后果项。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Use historical findings to compare discovery-to-triage, ownership, treatment, verification and overdue times by risk and asset class. Tabletop a critical actively exploited flaw and a low-score privilege-chain flaw; verify prioritization, maintenance-window decisions and temporary containment.",
          "zh": "用历史发现拆解发现到分诊、认领、处置、验证和逾期的时间，按风险/资产类别看分布。桌演一个活跃利用高危和一个低分但可串链提权的问题，验证排序、维护窗口与临时遏制。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "7.2",
          "control": 7,
          "title": {
            "en": "Establish and Maintain a Remediation Process",
            "zh": "风险化修复流程"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls7/",
          "snapshot_sha256": "BA2036413BBF89630CCF02B4B304353CB97FCCEB11F22AD1F95FB6408A06830B",
          "retrieved_at": "2026-07-30T16:25:31.916Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-7.3",
      "safeguard_id": "7.3",
      "control": 7,
      "title": {
        "en": "Perform Automated Operating System Patch Management",
        "zh": "操作系统自动补丁"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Include every OS and firmware-like platform layer that the enterprise operates on endpoints, servers, cloud images, hypervisors and appliances where automated updating is supported. Golden images do not cover long-lived instances, and rebuilt ephemeral workloads must prove the deployed image is current.",
          "zh": "包括企业运营的终端、服务器、云镜像、虚拟化和设备中可自动更新的 OS/固件层。金镜像不覆盖长期实例；重建型工作负载也要证明部署镜像是当前版本。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Use centrally governed rings, tested repositories and maintenance windows to deploy at least monthly, with faster emergency release, health checks and rollback. Link asset/version/support inventory to update policy; replace or isolate systems outside automation and prevent unmanaged sources or deferred restarts from becoming permanent.",
          "zh": "用中央管理的分批、可信仓库和维护窗至少每月部署，紧急风险更快，并有健康检查/回滚。把资产、版本、支持状态关联策略；自动化外的系统要替换或隔离，禁止更新延迟/待重启永久化。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Counting an out-of-date OS with an exception as “up to date,” as CAS effectiveness does, merges risk acceptance with remediation. Appliances, immutable images, offline and safety systems need alternative workflows. Latest is not automatically safe: hold a bad update only through a documented, monitored release decision.",
          "zh": "CAS 把“有例外的过期 OS”算作更新有效，把风险接受与修复混为一谈。设备、不可变镜像、离线和安全系统需另流程。最新版也可能有严重缺陷，暂缓必须有证据、监测和截止日。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Deploy a signed test update through pilot and broad rings, verify install, reboot or activation, application health, rollback and inventory state. Measure assets actually at an approved current level within SLO, automation freshness, failure and pending-restart populations; sample vendor version claims.",
          "zh": "经试点和广泛分批部署签名测试更新，验证安装、重启/激活、应用健康和回滚。指标看 SLO 内达到批准当前版本的真实资产，另报自动化新鲜度、失败与待重启，并抽验厂商版本判断。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "7.3",
          "control": 7,
          "title": {
            "en": "Perform Automated Operating System Patch Management",
            "zh": "操作系统自动补丁"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls7/",
          "snapshot_sha256": "BA2036413BBF89630CCF02B4B304353CB97FCCEB11F22AD1F95FB6408A06830B",
          "retrieved_at": "2026-07-30T16:25:31.916Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-7.4",
      "safeguard_id": "7.4",
      "control": 7,
      "title": {
        "en": "Perform Automated Application Patch Management",
        "zh": "应用自动补丁"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The population includes managed desktop/server applications, browsers, runtimes, agents, databases, plugins and packaged services; libraries and internally developed application components also require Control 16 pipelines. Portable, user-installed, container and SaaS components may evade endpoint patch tools.",
          "zh": "总体包括受管桌面/服务器应用、浏览器、Runtime、Agent、数据库、插件和打包服务；库与自研组件还要走 Control 16。便携、用户安装、容器和 SaaS 组件可能躲过终端补丁工具。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Use vendor or trusted repositories, packaging and deployment rings to update at least monthly and faster for exploited risk. Map each deployed application/version to its update channel, owner and restart or migration requirement; block unsupported versions and reconcile failures to software inventory.",
          "zh": "使用厂商/可信仓库与分批部署，至少每月更新，活跃利用时更快。每个部署版本映射更新渠道、责任人和重启/迁移要求；阻断不受支持版本，并把失败回写软件台账。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "An application can report the new package while an old vulnerable process or plugin still runs. Auto-update disabled for compatibility needs a bounded manual lane. SaaS “automatically updated” still requires provider release, tenant-setting and residual-risk evidence.",
          "zh": "包显示更新后，旧易受害进程或插件仍可能运行。因兼容关闭自动更新需限时手工车道。SaaS“自动更新”仍要服务商发布、租户配置和剩余风险证据。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Push a test update and verify package authenticity, version, service health, rollback and restart across representative platforms. Measure deployment instances current within risk SLO, not product names or patch-tool configuration; inspect portable and dormant installations as negative controls.",
          "zh": "推送测试更新，验证包真实性、版本、服务健康、回滚和各平台重启；覆盖率按 SLO 内已更新的部署实例算，不能按产品名或工具配置算，并以便携/休眠安装作负控。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "7.4",
          "control": 7,
          "title": {
            "en": "Perform Automated Application Patch Management",
            "zh": "应用自动补丁"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls7/",
          "snapshot_sha256": "BA2036413BBF89630CCF02B4B304353CB97FCCEB11F22AD1F95FB6408A06830B",
          "retrieved_at": "2026-07-30T16:25:31.916Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-023"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-7.5",
      "safeguard_id": "7.5",
      "control": 7,
      "title": {
        "en": "Perform Automated Vulnerability Scans of Internal Enterprise Assets",
        "zh": "内部资产自动漏洞扫描"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Identify",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Scope all internal enterprise assets and reachable services across campuses, remote networks, data centers, cloud accounts, containers and management planes, with both authenticated and unauthenticated perspectives at least quarterly. Asset eligibility, credentialed depth and safety constraints must be declared.",
          "zh": "覆盖园区、远程网、数据中心、云账号、容器和管理面的内部资产与服务，至少季度做有凭据和无凭据两种视角；声明资产适用性、凭据深度和安全限制。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Schedule scanners from representative zones, use least-privilege protected credentials, monitor job/engine/feed health, tune fragile assets and normalize findings to asset/software identities. Add cloud, container, agent and configuration assessment where network scanning cannot see the control surface.",
          "zh": "从代表网段调度扫描器，保护最小权限凭据，监测任务/引擎/Feed 健康，对脆弱资产调优，并把发现归一到资产/软件身份。网络扫描看不到的面用云、容器、Agent 和配置评估补足。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A scanner installed or scheduled is not coverage when routing, credentials or exclusions prevent completion. Short-lived workloads need image/deployment scanning. OT may require passive/vendor-approved assessment, but every exclusion states alternative evidence, isolation and review; duplicate findings across addresses are not extra risk.",
          "zh": "装了或排了扫描器不等于覆盖，路由、凭据、排除会使任务失效。短命工作负载应扫镜像/部署。OT 可用被动/厂商批准方法，但每个排除都写替代证据、隔离和复核；同一资产多 IP 不等于多个风险。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Seed a safe known-vulnerable fixture and a missing credential, then verify discovery, authenticated evidence, failure alert and ticket flow. Measure assets successfully assessed within cadence, authenticated depth and unreachable/unevaluable populations separately; sample results against live versions.",
          "zh": "放置安全的已知漏洞 Fixture 和一个失效凭据，验证发现、有凭据证据、失败告警和工单。分别统计周期内成功评估、认证深度、不可达和无法评估总体，并抽样比对运行版本。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "7.5",
          "control": 7,
          "title": {
            "en": "Perform Automated Vulnerability Scans of Internal Enterprise Assets",
            "zh": "内部资产自动漏洞扫描"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls7/",
          "snapshot_sha256": "BA2036413BBF89630CCF02B4B304353CB97FCCEB11F22AD1F95FB6408A06830B",
          "retrieved_at": "2026-07-30T16:25:31.916Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-7.6",
      "safeguard_id": "7.6",
      "control": 7,
      "title": {
        "en": "Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets",
        "zh": "外网资产自动漏洞扫描"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Identify",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The denominator is every Internet-reachable domain, IP, service, cloud endpoint, application gateway, API and provider-hosted tenant the enterprise owns or authorizes, including shadow and transient exposure. Scan from outside the trust boundary at least monthly and after material exposure change.",
          "zh": "分母是企业拥有或授权的所有公网域名、IP、服务、云端点、应用网关、API 和服务商托管租户，包括影子与短命暴露。至少月扫，并在暴露重大变化后立即扫。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Continuously reconcile DNS, certificates, cloud inventory, routing and external attack-surface discovery, then run safe authenticated or unauthenticated tests appropriate to each service. Verify scanner source authorization, rate and destructive-test limits; route findings to the real service owner.",
          "zh": "持续对账 DNS、证书、云台账、路由和外部攻击面发现，再按服务执行安全的有/无凭据测试；确认扫描源授权、速率和禁止破坏项，发现路由到真实服务责任人。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "CDNs, WAFs and load balancers can hide vulnerable origins while scans only assess the edge. Third-party hosting needs written authorization and provider evidence. A monthly cadence is a floor; newly exposed or actively exploited systems need immediate testing and containment.",
          "zh": "CDN/WAF/负载均衡会遮住脆弱 Origin，扫描可能只看边缘。第三方托管需书面授权与服务商证据。月度只是底线，新暴露或活跃利用要立即测试和遏制。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Publish a benign exposed test service and vulnerable fixture, confirm discovery and scan, then remove them and verify disappearance only after inventory closure. Test IPv6, alternate ports, direct origins, forgotten subdomains and provider front doors; measure completed eligible endpoints and unknown exposures.",
          "zh": "发布无害测试服务和漏洞 Fixture，确认发现与扫描，移除后只有台账结案才算消失；测试 IPv6、替代端口、直连 Origin、遗忘子域和服务商前门，指标看完成的合格端点与未知暴露。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "7.6",
          "control": 7,
          "title": {
            "en": "Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets",
            "zh": "外网资产自动漏洞扫描"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls7/",
          "snapshot_sha256": "BA2036413BBF89630CCF02B4B304353CB97FCCEB11F22AD1F95FB6408A06830B",
          "retrieved_at": "2026-07-30T16:25:31.916Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-7.7",
      "safeguard_id": "7.7",
      "control": 7,
      "title": {
        "en": "Remediate Detected Vulnerabilities",
        "zh": "漏洞修复与闭环"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Respond",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The population is every accepted finding-instance tied to an asset, component, configuration and evidence source, including duplicates consolidated without losing affected scope. Closure can be fixed, removed, mitigated or time-bounded accepted risk, each with different proof.",
          "zh": "总体是关联到资产、组件、配置和证据源的每个发现实例；去重不能丢失受影响范围。关闭状态可为已修、已移除、已缓解或限时接受，每种证明不同。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Route by the risk-based process, apply patch, upgrade, configuration, isolation, or removal, preserve change and exception records, and require independent verification at least monthly or faster. Reopen when the asset, vulnerable version or exposure returns; feed systemic causes into configuration and development controls.",
          "zh": "按风险流程路由，补丁/升级/改配置/隔离/移除，保留变更和例外，并至少每月或更快独立验证；资产、易受害版本或暴露再现时重开，系统性根因回馈配置与开发控制。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "The CAS assumes a finding absent from the next scan was remediated; asset disappearance, credential loss, scope change or scanner failure can create the same result. False positives require technical evidence and expiry. Ticket closure, package installation or vendor statement alone is not remediation.",
          "zh": "CAS 假设下次扫描没出现就是已修，但资产消失、凭据丢失、范围变化和扫描失败都能造成同样结果。误报需技术证据并到期。关闭工单、安装软件包或厂商声明本身都不能证明风险已经消除。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Reproduce or rescan the exact affected path after treatment and pair it with a positive control proving the scanner/test still works. Check running version, exploit condition and compensating control; report verified closures, failed fixes, reopened and overdue findings by risk.",
          "zh": "处理后重现或重扫准确路径，同时用正控证明扫描/测试仍工作；核对运行版本、利用条件和补偿控制，分别报告验证关闭、修复失败、重开和按风险逾期。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "7.7",
          "control": 7,
          "title": {
            "en": "Remediate Detected Vulnerabilities",
            "zh": "漏洞修复与闭环"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls7/",
          "snapshot_sha256": "BA2036413BBF89630CCF02B4B304353CB97FCCEB11F22AD1F95FB6408A06830B",
          "retrieved_at": "2026-07-30T16:25:31.916Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-024"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-8.1",
      "safeguard_id": "8.1",
      "control": 8,
      "title": {
        "en": "Establish and Maintain an Audit Log Management Process",
        "zh": "审计日志管理流程"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The process covers security-relevant logs from assets, identity, applications, data, cloud/SaaS, network, development and providers through generation, transport, normalization, protection, use, retention and disposal. It distinguishes forensic, detection, operational and legal purposes instead of “log everything.”",
          "zh": "覆盖资产、身份、应用、数据、云/SaaS、网络、开发和服务商日志从产生、传输、归一、保护、使用、保留到销毁的全链路；区分取证、检测、运维和法律用途，不主张“全部都记”。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Define mandatory events/fields by source, owner, collection path, time, access, integrity, capacity, retention, privacy, review/detection use and failure response. Tie each source to asset/data inventories and a consumer; review annually and after architecture, threat, regulatory or provider change.",
          "zh": "按来源定义必需事件/字段、责任人、采集路径、时间、访问、完整性、容量、保留、隐私、复核/检测用途和故障处理；关联资产/数据台账和消费者，每年及架构、威胁、法规、服务商变化时更新。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Document completeness is the CAS focus; useful log arrival requires a separate observation. High-volume logs can crowd out critical events; privacy and cross-border rules constrain content. Sources with no detection, investigation or compliance consumer need an explicit reason or should not consume indefinite storage.",
          "zh": "文档完整度（CAS 重点）不能证明日志有用或到达。大流量源可能挤掉关键事件，隐私与跨境限制内容。没有检测、调查或合规消费者的来源，要么说明理由，要么不该无限占存储。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Select representative incident questions and prove the required events can answer actor, action, object, time, source and result within retention. Trace a canary event end to end, then stop a source to verify health alert and recovery; review fields for unnecessary secrets or personal data.",
          "zh": "选代表事件问题，证明日志能在保留期内回答谁、何时、从哪里对什么做了什么、结果如何。全链路追踪金丝雀事件，再停一个源验证健康告警/恢复；检查字段是否多记秘密或个人数据。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "8.1",
          "control": 8,
          "title": {
            "en": "Establish and Maintain an Audit Log Management Process",
            "zh": "审计日志管理流程"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls8/",
          "snapshot_sha256": "BB5C01E764D3A2C232D06D1F839F90311343D93E4A858CB123E6D9911B5A4DC4",
          "retrieved_at": "2026-07-30T16:25:43.952Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-8.2",
      "safeguard_id": "8.2",
      "control": 8,
      "title": {
        "en": "Collect Audit Logs",
        "zh": "日志采集"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Include every in-scope asset and control plane capable of security-relevant logging, with event sets defined by 8.1. “Enabled locally” is distinct from successfully collected, parsed and available at the destination.",
          "zh": "包括所有能产生安全相关事件的在管资产和控制面，事件集由 8.1 规定。“本地启用”与“成功采集、解析并可在目的地使用”是不同状态。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Configure source generation and reliable forwarding, buffer outages, authenticate transport, protect credentials and monitor heartbeat, lag, parse and drop. Use images/policy-as-code for ephemeral workloads and provider APIs for managed services; assign source and pipeline owners.",
          "zh": "配置源端产生与可靠转发，故障时缓冲，认证传输，保护凭据并监测心跳、延迟、解析和丢弃；短命工作负载用镜像/策略即代码，托管服务用服务商 API，并分别指定源和管道责任人。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Devices may be online but legitimately quiet, so use synthetic heartbeats or configuration plus expected-event tests. Network loss, rate limits and license caps can silently discard data. Local logs erased before forwarding, cloned host IDs and auto-scaled instances require buffering and durable identity.",
          "zh": "设备在线却业务安静时，用合成心跳或配置加预期事件验证。网络丢包、API 限流、许可证上限会静默丢数据。源端日志转发前被擦、克隆主机 ID 和自动扩容实例需缓冲与持久身份。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Generate an allowed and denied canary event on each source class and trace raw and normalized forms to the destination with correct identity/time. Measure sources recently delivering required events over the independent eligible inventory, plus silent, partial, delayed and parse-failed sources.",
          "zh": "在每类源生成允许与拒绝金丝雀事件，追踪原始/归一形式和正确身份/时间；覆盖率以独立合格台账为分母，要求近期送达必需事件，另列静默、部分、延迟与解析失败。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "8.2",
          "control": 8,
          "title": {
            "en": "Collect Audit Logs",
            "zh": "日志采集"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls8/",
          "snapshot_sha256": "BB5C01E764D3A2C232D06D1F839F90311343D93E4A858CB123E6D9911B5A4DC4",
          "retrieved_at": "2026-07-30T16:25:43.952Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-8.3",
      "safeguard_id": "8.3",
      "control": 8,
      "title": {
        "en": "Ensure Adequate Audit Log Storage",
        "zh": "日志存储容量"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Capacity covers local buffers, collectors, queues, hot search, archive and restore paths needed to meet the log process under normal peaks and incident bursts. A retention setting is meaningless if ingestion caps, rotation or provider quotas delete events earlier.",
          "zh": "容量覆盖为满足流程所需的本地缓冲、收集器、队列、热查询、归档和恢复路径，既考虑正常峰值也考虑事件爆发。若采集上限、轮转或服务商配额提前删事件，保留设置毫无意义。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Model volume by source and peak, reserve headroom, set priority and backpressure, alert on saturation/lag/drop, and budget immutable or protected tiers. Test expansion and degradation so critical security events survive a noisy source; align physical retention and accessible search windows.",
          "zh": "按来源/峰值建模，留余量，设优先级和背压，对饱和、积压、丢弃告警，并为不可变/受保护层预算。演练扩容和降级，确保噪声源不能挤掉关键事件；物理保留与可检索窗口一致。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Compression and sampling affect evidentiary detail; define which events may be sampled. Unlimited cloud storage can still hit query, cost or API limits. The CAS assumption that correct configuration implies adequate rotation/capacity skips operating effectiveness and must be supplemented by observed loss and restore tests.",
          "zh": "压缩与采样会改变证据细节，必须说明哪些可采样。“无限”云存储仍有查询、成本和 API 瓶颈。CAS 假设配置正确就等于容量足够，跳过运行有效性，必须补充真实丢失与恢复试验。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Replay a controlled burst and collector outage, then verify buffering, no critical-event loss, recovery order and actual oldest searchable/restorable timestamp. Track ingest versus accepted versus stored counts, capacity runway and early-deletion events by source and tier.",
          "zh": "回放受控流量突发并中断收集器，验证缓冲、关键事件不丢、恢复顺序和实际最老可查/可恢复时间。跟踪源发送、管道接收、实际存储三种计数、容量剩余天数和提前删除。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "8.3",
          "control": 8,
          "title": {
            "en": "Ensure Adequate Audit Log Storage",
            "zh": "日志存储容量"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls8/",
          "snapshot_sha256": "BB5C01E764D3A2C232D06D1F839F90311343D93E4A858CB123E6D9911B5A4DC4",
          "retrieved_at": "2026-07-30T16:25:43.952Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-8.4",
      "safeguard_id": "8.4",
      "control": 8,
      "title": {
        "en": "Standardize Time Synchronization",
        "zh": "时间同步"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Eligible logging and security assets should use at least two approved synchronized sources where supported, with a trusted hierarchy, authenticated time where risk warrants it and a defined tolerance. Containers may inherit host time; SaaS may expose only provider timestamps and must state that boundary.",
          "zh": "支持时，产生日志和安全事件的资产至少使用两个批准且同步的时间源，建立可信层级；高风险处需认证时间与误差阈值。容器可继承宿主，SaaS 可能只能接受服务商时间，要明示边界。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Configure redundant sources centrally, prevent ordinary changes, monitor offset, source health and stratum, preserve time zone/UTC semantics, and define behavior during loss or malicious shifts. Critical systems can use internal relays tied to independent authoritative sources.",
          "zh": "集中配置冗余来源，阻止普通人改时，监控偏移、源健康和层级，统一 UTC/时区语义，并定义时间源丢失或恶意跳变时的行为。关键系统可用内部 Relay 上联独立权威源。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Two configured sources are not independent if they share an upstream. Virtualization pauses, offline devices, leap events and application-local clocks can drift. The official current Navigator/core guide classifies 8.4 as Data while CAS says Network; scope from the safeguard intent because the metadata labels conflict.",
          "zh": "两个配置源若共用同一上游就不独立。虚拟化暂停、离线设备、闰秒和应用自带时钟会漂移。Navigator/核心指南把 8.4 归 Data，CAS 归 Network，应按 Safeguard 本意定范围，不能跟元数据缩窄。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Measure actual offset and selected source, not only configuration. Fail one source, introduce a safe offset in a lab and verify failover, alerting and correction without corrupting transactions; correlate one canary event across endpoint, network, identity and application logs.",
          "zh": "测量实际偏移和当前选源，不只看配置。实验室停一个源并安全引入偏移，验证切换、告警和纠正不破坏交易；用金丝雀事件关联终端、网络、身份和应用时间。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "8.4",
          "control": 8,
          "title": {
            "en": "Standardize Time Synchronization",
            "zh": "时间同步"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls8/",
          "snapshot_sha256": "BB5C01E764D3A2C232D06D1F839F90311343D93E4A858CB123E6D9911B5A4DC4",
          "retrieved_at": "2026-07-30T16:25:43.952Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-025"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-8.5",
      "safeguard_id": "8.5",
      "control": 8,
      "title": {
        "en": "Collect Detailed Audit Logs",
        "zh": "详细审计字段"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Detailed logging applies to assets holding sensitive data and high-consequence control planes. Required fields include event source, date/time, effective user or workload, source/destination context, action, object and result, with transaction/correlation identifiers where needed.",
          "zh": "详细日志面向承载敏感数据的资产和高后果控制面；字段包括事件源、日期/时间、有效用户/工作负载、源/目的上下文、动作、对象和结果，必要时加交易/关联 ID。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Define source-specific schemas and enable the most useful native/application events; preserve stable asset/account/data identities through normalization. Minimize secrets and payloads, document field transformations and protect verbose or sensitive audit streams from broader analyst access.",
          "zh": "按来源定义 Schema，启用最有用的原生/应用事件，归一时保留稳定资产、账户与数据身份；少记秘密/载荷，记录字段转换，对高敏/详细审计流做更严格访问控制。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Proxies, pooled connections and service accounts can replace the real actor; application context must restore it. NAT changes addresses, privacy redaction may remove detail and provider logs may omit fields. A field present but constant, truncated or unparseable fails usefulness.",
          "zh": "代理、连接池和服务账户会替换真实行为人，需应用上下文恢复。NAT 改地址、隐私脱敏减细节、服务商日志少字段。字段存在但固定、截断或无法解析，也不合格。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Execute representative read, write, delete, permission and administrative actions plus denials, then verify every required field and correlation across layers. Measure in-scope sources producing complete sampled events, not all logging-capable assets as the current CAS denominator implies.",
          "zh": "执行代表性的读写删、权限和管理动作及拒绝，核验每个字段与跨层关联。指标看范围内源能否产生完整抽样事件，不能像 CAS 那样用全部“能日志资产”作分母。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "8.5",
          "control": 8,
          "title": {
            "en": "Collect Detailed Audit Logs",
            "zh": "详细审计字段"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls8/",
          "snapshot_sha256": "BB5C01E764D3A2C232D06D1F839F90311343D93E4A858CB123E6D9911B5A4DC4",
          "retrieved_at": "2026-07-30T16:25:43.952Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-026"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-8.6",
      "safeguard_id": "8.6",
      "control": 8,
      "title": {
        "en": "Collect DNS Query Audit Logs",
        "zh": "DNS 查询日志"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Capture enterprise DNS decisions at internal, endpoint, cloud, mobile and approved external resolvers where appropriate, including query, type, response, client or identity context, policy action, resolver and time. Authoritative DNS and recursive-client logs answer different questions.",
          "zh": "采集企业内网、终端、云、移动和批准外部递归解析器的 DNS 决定，视情况包含查询、类型、回答、客户端/身份、策略动作、解析器和时间；权威 DNS 与递归客户端日志回答不同问题。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Enable logs at controlled resolvers and endpoint agents where source identity is otherwise lost, centralize them, govern retention/privacy and monitor encrypted-DNS bypass. For outsourced DNS, configure tenant exports/API and reconcile roaming devices and split namespaces.",
          "zh": "在受控解析器启用日志，若 NAT 遮住来源则补终端 Agent，集中化并治理保留/隐私，监测加密 DNS 绕过；外包 DNS 要配置租户导出/API，并对账漫游设备和 Split DNS。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "The CAS assumes the enterprise runs internal DNS, excluding outsourced and endpoint models. Caching means not every application lookup reaches a resolver; DoH/DoT, VPN split DNS and hard-coded IPs evade collection. Logs reveal a request, not malicious intent or the process without additional context.",
          "zh": "CAS 假设企业自建内网 DNS，漏掉外包和端点模型。缓存使并非每次应用查询都到解析器，DoH/DoT、VPN Split 和硬编码 IP 都会绕过。日志只能证明请求，不证明恶意或具体进程。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Resolve benign, blocked, nonexistent and direct/encrypted test domains from representative networks and devices; trace client, query, answer/action and time end to end. Compare endpoint observations with resolver logs to find NAT, cache and bypass gaps.",
          "zh": "从代表网络/设备解析正常、被拦、NXDOMAIN 和直连/加密测试域，追踪客户端、查询、回答/动作和时间；把端点观测与解析器日志对比，找缓存、NAT 和旁路。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "8.6",
          "control": 8,
          "title": {
            "en": "Collect DNS Query Audit Logs",
            "zh": "DNS 查询日志"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls8/",
          "snapshot_sha256": "BB5C01E764D3A2C232D06D1F839F90311343D93E4A858CB123E6D9911B5A4DC4",
          "retrieved_at": "2026-07-30T16:25:43.952Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-8.7",
      "safeguard_id": "8.7",
      "control": 8,
      "title": {
        "en": "Collect URL Request Audit Logs",
        "zh": "URL 请求日志"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Scope web and API requests visible at secure web gateways, proxies, endpoints, browsers, DNS/security services and applications, including remote and cloud paths. State whether logs contain full URL, origin/domain only, method, identity, result and uploaded/downloaded metadata; fragments and encrypted paths may be unavailable.",
          "zh": "覆盖代理、安全 Web 网关、终端、浏览器、DNS/安全服务和应用可见的 Web/API 请求，包括远程与云路径。须声明记录完整 URL 还是域名、方法、身份、结果与上传下载元数据；Fragment 和加密路径可能不可见。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Collect at the control point that can lawfully see the needed fields, bind user/device/session, centralize and redact secrets, tokens, health data and other unnecessary query content. Monitor client bypass and provider export health; use endpoint telemetry where traffic does not traverse a proxy.",
          "zh": "在合法且能看到所需字段的控制点采集，绑定用户/设备/会话，集中化并脱敏秘密、Token、健康信息等查询内容；监测客户端旁路和服务商导出，在不经代理时用终端遥测补足。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "TLS, certificate pinning, privacy relays and end-to-end applications limit path visibility. Full URLs can contain credentials or sensitive queries, so minimization is part of compliance. DNS logs cover domain resolution without URL paths; proxy logs cover observed requests without establishing application content or user intent.",
          "zh": "TLS、证书固定、隐私中继与端到端应用会限制路径可见性。完整 URL 可能含凭据或敏感查询，因此最小化也是合规要求。DNS 日志的证据边界是域名解析，不含 URL 路径；代理日志的边界是观测到的请求，不涵盖应用内容或用户意图。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Request benign, blocked, redirected and encoded test URLs from managed and remote devices and verify identity, destination, action, time and correlation. Try QUIC, direct IP, alternate browser and VPN paths; measure effective observed traffic paths, not merely assets with a logging setting.",
          "zh": "从受管/远程设备请求正常、被拦、重定向和编码 URL，核验身份、目的、动作、时间和关联；再测 QUIC、直连 IP、替代浏览器与 VPN。覆盖率看真实可观测流量路径，不只设备设置。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "8.7",
          "control": 8,
          "title": {
            "en": "Collect URL Request Audit Logs",
            "zh": "URL 请求日志"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls8/",
          "snapshot_sha256": "BB5C01E764D3A2C232D06D1F839F90311343D93E4A858CB123E6D9911B5A4DC4",
          "retrieved_at": "2026-07-30T16:25:43.952Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-8.8",
      "safeguard_id": "8.8",
      "control": 8,
      "title": {
        "en": "Collect Command-Line Audit Logs",
        "zh": "命令行日志"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Include interactive and non-interactive PowerShell, shell, command prompt, remote terminals, scripts, container exec, CI/CD runners and cloud command interfaces that can change enterprise state. Process creation without arguments may miss the decisive behavior; full command text may contain secrets.",
          "zh": "包括交互和非交互的 PowerShell、Shell、命令提示、远程终端、脚本、容器 Exec、CI/CD Runner 与云命令接口。只有进程创建且无参数，可能漏掉决定行为；完整命令又可能含秘密。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Enable platform-native command/process/script-block and terminal-session auditing according to risk, preserve user, effective privilege, parent, host/workload, command or content identity, result and time, and centralize quickly. Redact or prevent secrets on command lines and protect high-value admin recordings.",
          "zh": "按风险启用命令/进程/脚本块/终端会话审计，保留用户、有效权限、父进程、主机/工作负载、命令或内容身份、结果与时间，并快速集中；阻止秘密上命令行或做脱敏，保护高权录屏。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Attackers and admins can use APIs, GUI, in-memory calls or allowed interpreters without a conventional command line. Logging can expose passwords and tokens. Unsupported appliances and SaaS CLIs need API/audit alternatives; collection without review/detection remains incomplete operation.",
          "zh": "攻击者/管理员可走 API、GUI、内存调用或允许解释器而无传统命令行。日志可能泄露密码/Token。不支持设备和 SaaS CLI 需 API/审计替代；只采集不审阅/检测，运行仍不完整。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Run benign commands through direct, encoded, script, remote, sudo/elevation and container paths; verify capture and correlation without truncation. Execute a secret canary to confirm masking/prevention, then stop the sensor to test health alert.",
          "zh": "通过直连、编码、脚本、远程、sudo/提权与容器路径运行无害命令，验证采集、关联和不截断；执行秘密金丝雀确认阻止/遮罩，再停 Sensor 测健康告警。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "8.8",
          "control": 8,
          "title": {
            "en": "Collect Command-Line Audit Logs",
            "zh": "命令行日志"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls8/",
          "snapshot_sha256": "BB5C01E764D3A2C232D06D1F839F90311343D93E4A858CB123E6D9911B5A4DC4",
          "retrieved_at": "2026-07-30T16:25:43.952Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-8.9",
      "safeguard_id": "8.9",
      "control": 8,
      "title": {
        "en": "Centralize Audit Logs",
        "zh": "集中日志"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Centralization covers required events from every source that can export them, into governed stores where correlation, access control, retention and incident use are possible. The architecture may federate storage while preserving one discovery and custody path.",
          "zh": "把所有可导出的必需事件放入受治理、可关联、可控访问/保留并可供事件使用的存储体系。一个 SIEM 不必保存每个字节，但架构必须提供统一发现与证据保管路径。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Use authenticated, buffered pipelines and normalized stable identifiers; isolate ingestion from search, restrict tenant and analyst access, maintain source health and immutable/independent copies for critical evidence. Map every source to destination, parser, retention and consumer.",
          "zh": "用认证、有缓冲的管道和稳定归一身份，分离接入与查询，限制租户/分析员访问，维护源健康；关键证据保留不可变或独立副本。每个源映射目的、Parser、保留和消费者。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "An agent configured to forward does not count when events never arrive. Multi-region, air-gapped, provider and sovereignty boundaries may require federated stores with one discoverable custody path. Central compromise can erase evidence, so privileged separation and protected copies matter.",
          "zh": "Agent 配了转发但事件没到不能算。多地域、气隙、服务商和数据主权可能需联邦存储而非物理集中。中央失陷可擦除证据，因此高权分离和受保护副本重要。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Trace canary events from each source class, fail collector/network/parser components, and verify buffering, duplicate handling, order, integrity and alerting. Reconcile recently arriving source identities against the log-source inventory, with partial event sets and stale sources separate.",
          "zh": "从每类源追金丝雀，分别故障收集器、网络和 Parser，验证缓冲、去重、顺序、完整性和告警；把近期到达的源身份与日志源台账对账，部分事件集和陈旧源单列。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "8.9",
          "control": 8,
          "title": {
            "en": "Centralize Audit Logs",
            "zh": "集中日志"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls8/",
          "snapshot_sha256": "BB5C01E764D3A2C232D06D1F839F90311343D93E4A858CB123E6D9911B5A4DC4",
          "retrieved_at": "2026-07-30T16:25:43.952Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-8.10",
      "safeguard_id": "8.10",
      "control": 8,
      "title": {
        "en": "Retain Audit Logs",
        "zh": "日志保留"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Retain required audit logs at least 90 days across local, centralized, provider and archive tiers, while incident, legal and regulatory needs may require longer. The retention clock, event classes, search availability and restore time must be explicit.",
          "zh": "全部必需审计日志至少保留 90 天，覆盖本地、集中、服务商和归档层；事件、法律和法规可要求更久。要明确保留起算、事件类、可检索期和恢复时限。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Apply lifecycle and immutability/access rules by log class, monitor actual oldest event and early deletion, preserve schemas/keys needed to read archives, and align local buffers with central success. Legal holds and incident preservation override routine expiry for named evidence.",
          "zh": "按日志类别执行生命周期与不可变/访问策略，监测真实最老事件和提前删除，保存读取归档所需 Schema/密钥；本地缓冲与中央接收一致。具名事件/诉讼保全覆盖常规到期。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A 90-day setting can fail under quotas, ingest delay or timestamp parsing. Hot search for 30 days plus restorable archive can pass if response SLOs are met. Indefinite retention increases privacy, breach and cost risk; logs containing secrets need remediation, not permanent storage.",
          "zh": "90 天设置会因配额、接入延迟或时间解析而失败。30 天热查加可按 SLO 恢复的归档可以合规。无限保留增加隐私、泄露和成本风险；日志若含秘密应先修源头，不能永久保存。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Query events just inside and beyond 90 days in a time-shifted test or historical store, restore archived samples and verify integrity, identity and readable schema. Measure retained required events/sources, not the number of aggregating products configured for 90 days.",
          "zh": "在时间推进或历史存储中查询 90 天内外事件，恢复归档样本并验证完整性、身份与可读 Schema。指标看按期保留的必需事件/来源，不看配置 90 天的聚合产品数。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "8.10",
          "control": 8,
          "title": {
            "en": "Retain Audit Logs",
            "zh": "日志保留"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls8/",
          "snapshot_sha256": "BB5C01E764D3A2C232D06D1F839F90311343D93E4A858CB123E6D9911B5A4DC4",
          "retrieved_at": "2026-07-30T16:25:43.952Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-8.11",
      "safeguard_id": "8.11",
      "control": 8,
      "title": {
        "en": "Conduct Audit Log Reviews",
        "zh": "日志审阅"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Reviews cover risk-based detections, anomalies, source-health failures and human investigation of audit data at least weekly; the objective is a recorded decision and response, not opening a dashboard. Prioritize high-consequence identities, data, changes and control planes.",
          "zh": "至少每周审阅风险化检测、异常、源健康故障和人工调查，目标是有记录的判断与响应，不是打开 Dashboard。优先高后果身份、数据、变更与控制面。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Create queries/rules and analyst procedures with owners, expected frequency, baselines, triage, escalation, tuning and closure. Automate continuous detection where useful and conduct a documented weekly coverage review that includes failed data sources and unworked alerts.",
          "zh": "为查询/规则和分析流程设责任人、频率、基线、分诊、升级、调优和关闭；适合的检测持续自动化，同时每周做有记录的覆盖审阅，包含失效源和未处理告警。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "CAS only compares two review timestamps, so an empty or rubber-stamped review can pass. Low-volume environments still need source health and targeted review. AI/automated triage may assist but requires quality checks, provenance and a human escalation boundary.",
          "zh": "CAS 只比较两次审阅时间，空白或盖章审阅也能过。低流量环境仍要看源健康和针对性事件。AI/自动分诊可辅助，但要质量验证、来源和人工升级边界。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Inject benign canary anomalies and normal controls, then verify alert, analyst interpretation, evidence, disposition and response within SLO. Sample review records for quality and missed periods; track precision, backlog age, detection gaps and repeated false positives.",
          "zh": "注入无害异常金丝雀与正常对照，验证告警、分析解释、证据、处置和 SLO 内响应；抽查审阅质量与漏周期，跟踪精度、积压年龄、检测缺口和重复误报。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "8.11",
          "control": 8,
          "title": {
            "en": "Conduct Audit Log Reviews",
            "zh": "日志审阅"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls8/",
          "snapshot_sha256": "BB5C01E764D3A2C232D06D1F839F90311343D93E4A858CB123E6D9911B5A4DC4",
          "retrieved_at": "2026-07-30T16:25:43.952Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-8.12",
      "safeguard_id": "8.12",
      "control": 8,
      "title": {
        "en": "Collect Service Provider Logs",
        "zh": "服务提供商日志"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Data",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Scope providers whose services can affect identity, data, infrastructure, software delivery or security, including cloud, SaaS, MSP/MSSP and critical suppliers. “Where supported” requires a recorded capability and risk decision for every important event class.",
          "zh": "包括能影响身份、数据、基础设施、软件交付或安全的云、SaaS、MSP/MSSP 与关键供应商。对每类重要事件，“支持时”都要留下能力和风险决定。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Contract for log access, retention, clock, fields, incident availability and export; enable tenant audit, authentication/authorization, admin/support, data lifecycle and configuration events. Pull through APIs or protected storage, monitor gaps and preserve evidence outside a provider that may itself be compromised.",
          "zh": "合同约定日志访问、保留、时钟、字段、事件可用性和导出；启用租户认证/授权、管理/支持、数据生命周期和配置事件，经 API 或受保护存储拉取，监控缺口，并把关键证据保存在可能被攻陷的服务商之外。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Provider plans may charge for logs, omit support actions or retain them briefly. Purchasing a higher tier can be necessary; otherwise reduce dependency or add compensating controls. Provider attestations do not prove this tenant's export was enabled, and unavailable internal logs must be an explicit residual risk.",
          "zh": "服务商套餐可能额外收费、缺少支持行为或保留很短，需要升级套餐，否则降低依赖或补偿。Attestation 不能证明本租户开启导出；不可见内部日志必须作为明示剩余风险。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Perform tenant actions and provider-supported admin/data events, trace them to the enterprise store and verify identity, time, completeness and latency. Disable export or exhaust an API limit to test health detection; sample provider console history against collected events.",
          "zh": "执行租户动作和可支持的管理/数据事件，追到企业存储，核验身份、时间、完整度与时延；停导出或耗尽 API 限额测试健康发现，并抽样比对服务商 Console 历史。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "8.12",
          "control": 8,
          "title": {
            "en": "Collect Service Provider Logs",
            "zh": "服务提供商日志"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls8/",
          "snapshot_sha256": "BB5C01E764D3A2C232D06D1F839F90311343D93E4A858CB123E6D9911B5A4DC4",
          "retrieved_at": "2026-07-30T16:25:43.952Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-9.1",
      "safeguard_id": "9.1",
      "control": 9,
      "title": {
        "en": "Ensure Use of Only Fully Supported Browsers and Email Clients",
        "zh": "受支持的浏览器与邮件客户端"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Include every browser engine, embedded webview and mail client that users or automation can execute, together with edition, channel, version and update status. “Authorized” and “supported” are different; CIS also calls for the latest vendor-provided version, subject to controlled release safety.",
          "zh": "包括用户或自动化可执行的每种浏览器引擎、嵌入 WebView 和邮件客户端，以及版本线、渠道、版本和更新状态。“获批”和“受支持”不同；CIS 还要求用厂商最新版本，但要经过受控发布安全。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Standardize products and channels, auto-update through trusted rings, block unsupported or portable alternatives and monitor vendor lifecycle and emergency releases. Test business applications in a pilot while setting a short maximum deferral and removing old engines after activation.",
          "zh": "统一产品/渠道，经可信分批自动更新，阻断不支持或便携替代，监控厂商生命周期与紧急发布。先在试点验证业务，设短暂最大延期，激活后移除旧引擎。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "The CAS measures repeat contradictory supported/unsupported definitions, so its false-positive/negative ratios cannot be trusted verbatim. Embedded runtimes, kiosk apps and mail plugins may carry a separate engine. A vendor-supported older enterprise channel may be temporarily valid only with documented risk and deadline.",
          "zh": "CAS 对 M2-M5 的受支持/不支持定义重复矛盾，误报漏报公式不可直接用。嵌入 Runtime、Kiosk 和邮件插件可能带独立引擎。受厂商支持的旧企业渠道只能限时保留，并有风险与截止日。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Enumerate executing and installed versions, compare to authoritative current/support channels and launch an old portable copy as a negative control. Verify update, restart/activation and enforcement; measure deployment instances current and supported, not inventory product labels.",
          "zh": "枚举安装与正在执行的版本，对照权威当前/支持渠道，并启动旧便携副本作负控；验证更新、重启/激活和阻断。指标按部署实例算当前且受支持，不能按台账标签算。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "9.1",
          "control": 9,
          "title": {
            "en": "Ensure Use of Only Fully Supported Browsers and Email Clients",
            "zh": "受支持的浏览器与邮件客户端"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls9/",
          "snapshot_sha256": "893B95999A6ACDC28F3DE11419EF6E6640E491BA628EA37586763E76C0FF99C7",
          "retrieved_at": "2026-07-30T16:25:45.071Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-027"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-9.2",
      "safeguard_id": "9.2",
      "control": 9,
      "title": {
        "en": "Use DNS Filtering Services",
        "zh": "DNS 恶意域名过滤"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Cover all end-user devices on-premises, remote and roaming, across IPv4/IPv6, VPN, browsers/applications using encrypted DNS and offline transition. The service blocks known malicious domains; it does not determine that every unlisted domain is safe.",
          "zh": "覆盖所有内网、远程、漫游终端的 IPv4/IPv6、VPN，以及使用加密 DNS 的浏览器/应用和离线切换。服务只拦已知恶意域；未列出绝不等于安全。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Enforce an approved security resolver or local agent, authenticate encrypted resolution, prevent unauthorized bypass and define category, threat-feed, exception and fail-open/closed policy. Tie user/device context to logs and keep protected fallback resolvers with current policy.",
          "zh": "强制批准的安全解析器或本地 Agent，认证加密解析，防未授权绕过，并定义分类、威胁 Feed、例外和 Fail-open/closed；绑定用户/设备日志，保留带当前策略的受保护备用解析器。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Caching, hard-coded IPs, DNS over HTTPS, privacy relays and captive portals bypass ordinary settings. False positives need rapid owner-approved release and expiry. DNS filtering is one layer; compromised allowed domains, URLs and direct IP traffic require web/endpoint controls.",
          "zh": "缓存、硬编码 IP、DoH、隐私 Relay 和 Captive Portal 会绕开设置。误报需快速、责任人批准且会到期的放行。DNS 过滤只是层之一，受控域被入侵、URL 和直连 IP 需 Web/终端控制。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Query benign, malicious-test, newly registered or policy-blocked and allowed-exception domains through system, browser DoH, VPN and direct resolver paths. Verify action, block page, logging, update freshness and behavior during resolver outage; measure effective path coverage.",
          "zh": "经系统、浏览器 DoH、VPN 和直连路径查询正常、恶意测试、新注册/策略拦截与例外域，验证动作、阻断页、日志、更新新鲜度和故障行为；覆盖率看实际路径。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "9.2",
          "control": 9,
          "title": {
            "en": "Use DNS Filtering Services",
            "zh": "DNS 恶意域名过滤"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls9/",
          "snapshot_sha256": "893B95999A6ACDC28F3DE11419EF6E6640E491BA628EA37586763E76C0FF99C7",
          "retrieved_at": "2026-07-30T16:25:45.071Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-9.3",
      "safeguard_id": "9.3",
      "control": 9,
      "title": {
        "en": "Maintain and Enforce Network-Based URL Filters",
        "zh": "网络 URL 过滤"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Scope enterprise web traffic across office, remote, mobile, cloud workloads and applications, including HTTP(S), QUIC and alternate proxy paths. Define categories and reputational objects, direction, identities, action, inspection limits and which assets cannot be forced through the control.",
          "zh": "覆盖办公、远程、移动、云工作负载和应用的 Web 流量，包括 HTTP(S)、QUIC 与备用代理路径。定义分类/声誉对象、方向、身份、动作、检查限制，以及哪些资产无法强制经控制点。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Deploy secure web gateway/proxy, endpoint or network policy with continuously updated intelligence, authenticated user/device context, controlled exceptions and direct-egress prevention. Start high-impact rules with observation where false-positive cost is high and preserve a kill switch and rollback.",
          "zh": "部署安全 Web 网关、代理、终端或网络策略，持续更新情报，绑定身份/设备，控制例外并阻断直出。误报成本高的规则先观察，保留 Kill switch 和回滚。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "TLS pinning, end-to-end apps, CDNs and shared hosting limit URL inspection and can make IP blocking unsafe. Category labels are probabilistic and age quickly. The CAS measures browser configuration. Effective network filtering needs separate coverage for non-browser and bypass traffic.",
          "zh": "TLS Pin、端到端应用、CDN 和共享托管限制 URL 检查，按 IP 拦可能危险。分类标签有概率且很快过时。CAS 实际测浏览器配置，遗漏非浏览器与旁路流量，不能当有效过滤。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Request approved, blocked, newly categorized, direct-IP, encoded, redirect and QUIC destinations from representative paths. Verify intended access, logging, certificate/privacy handling, update health and exception expiry; report traffic-path coverage and bypasses separately from device count.",
          "zh": "从代表路径请求允许、被拦、新分类、直连 IP、编码、重定向和 QUIC 目的，验证业务、日志、证书/隐私、更新健康和例外到期；分别报告路径覆盖与绕过。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "9.3",
          "control": 9,
          "title": {
            "en": "Maintain and Enforce Network-Based URL Filters",
            "zh": "网络 URL 过滤"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls9/",
          "snapshot_sha256": "893B95999A6ACDC28F3DE11419EF6E6640E491BA628EA37586763E76C0FF99C7",
          "retrieved_at": "2026-07-30T16:25:45.071Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-9.4",
      "safeguard_id": "9.4",
      "control": 9,
      "title": {
        "en": "Restrict Unnecessary or Unauthorized Browser and Email Client Extensions",
        "zh": "浏览器与邮件扩展"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Include browser extensions, add-ons, native messaging hosts, mail plugins and sideloaded/developer components across every profile and channel. Store approval must bind publisher identity, component ID, version/update source, permissions, purpose and allowed population.",
          "zh": "包括每个 Profile/渠道的浏览器扩展、Add-on、Native Messaging Host、邮件插件和侧载/开发组件。商店审批必须绑定发布者、组件 ID、版本/更新源、权限、用途和人群。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Default-deny or centrally allowlist required components, force-install only managed ones, block developer mode and unapproved stores, review permission/version changes, and remove unnecessary extensions. Inventory both device and cloud-synchronized profiles and protect policy against user override.",
          "zh": "默认拒绝或中央 Allowlist，仅强装受管项，禁开发模式和未批准商店，审查权限/版本变化，移除无必要扩展；同时清点设备与云同步 Profile，并防用户改策略。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "An approved extension can be sold or its update channel compromised; continuous publisher/permission review matters. Embedded browsers and unmanaged personal profiles may sit outside enterprise policy and should not receive sensitive access. Navigator's “Applications” asset class conflicts with the core guide/CAS “Software,” without changing scope.",
          "zh": "获批扩展可被出售或更新链受损，发布者/权限需持续复核。嵌入浏览器与个人 Profile 可能不受策略，不能获敏感访问。Navigator 把资产类写 Applications，核心指南/CAS 写 Software，范围不应因此变化。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Install an approved extension, an unapproved store item, a sideloaded copy and an approved ID requesting new permissions. Verify execution, update and sync behavior plus removal; compare effective profiles to the authorized set and monitor policy tampering.",
          "zh": "安装批准扩展、未批准商店项、侧载副本和请求新权限的批准 ID，验证执行、更新、同步和移除；把有效 Profile 与批准集合比较并监测篡改。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "9.4",
          "control": 9,
          "title": {
            "en": "Restrict Unnecessary or Unauthorized Browser and Email Client Extensions",
            "zh": "浏览器与邮件扩展"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls9/",
          "snapshot_sha256": "893B95999A6ACDC28F3DE11419EF6E6640E491BA628EA37586763E76C0FF99C7",
          "retrieved_at": "2026-07-30T16:25:45.071Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-028"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-9.5",
      "safeguard_id": "9.5",
      "control": 9,
      "title": {
        "en": "Implement DMARC",
        "zh": "DMARC、SPF 与 DKIM"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The boundary includes every organizational and parked domain, subdomain, outbound sender, third-party mail platform and inbound verifier. SPF authorizes envelope sources, DKIM authenticates signed content/domain, and DMARC aligns identifiers and publishes handling/reporting; none alone stops look-alike domains.",
          "zh": "包括所有组织域、停放域、子域、出站发件方、第三方邮件平台和入站验证器。SPF 授权 Envelope 来源，DKIM 认证签名内容/域，DMARC 做标识对齐与处置/报告；都不能单独防相似域。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Inventory senders, configure scoped SPF below lookup limits, protect and rotate DKIM keys, publish DMARC reporting, analyze legitimate alignment, then progress from monitoring to quarantine/reject with explicit percentages and subdomain policy. Enable inbound verification and govern third-party senders.",
          "zh": "清点发件源，配置不超 DNS Lookup 的 SPF，保护/轮换 DKIM Key，发布 DMARC 报告，分析合法对齐，再从观察推进到 Quarantine/Reject，写明比例和子域策略；入站也验证，治理第三方发件。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Forwarding can break SPF and mailing lists can alter DKIM; alignment and ARC decisions need testing. A p=none record is visibility, not enforcement. The current CAS looks for DNS properties in the mail-agent input and sets both “uses/does not use” measures to one, so its six-item score is not executable.",
          "zh": "转发会破坏 SPF，邮件列表可能改 DKIM，需测试对齐和 ARC。 p=none 只是可见性。CAS 在邮件代理输入里找 DNS 属性，且“使用/不使用”都给 1，其六项分数不可执行。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Send aligned valid, SPF-only, DKIM-only, misaligned, spoofed and forwarded/list messages to representative receivers; verify authentication results, policy action and aggregate reports. Monitor unknown senders, failure trends and DNS changes for every domain, including non-sending domains with deny policies.",
          "zh": "向代表收件方发送对齐有效、仅 SPF、仅 DKIM、错对齐、伪造和转发/邮件列表测试，验证 Authentication-Results、动作与聚合报告；监控每个域未知发件、失败趋势和 DNS 变化，非发信域设拒绝。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "9.5",
          "control": 9,
          "title": {
            "en": "Implement DMARC",
            "zh": "DMARC、SPF 与 DKIM"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls9/",
          "snapshot_sha256": "893B95999A6ACDC28F3DE11419EF6E6640E491BA628EA37586763E76C0FF99C7",
          "retrieved_at": "2026-07-30T16:25:45.071Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-029"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-9.6",
      "safeguard_id": "9.6",
      "control": 9,
      "title": {
        "en": "Block Unnecessary File Types",
        "zh": "高风险附件类型"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The population is inbound email attachments and archive contents across every mail route, tenant, alias and provider; file type must be determined by content and nested structure, not extension alone. “Unnecessary” is business- and role-specific and can include executables, scripts, macro documents and password-protected archives.",
          "zh": "总体是经所有邮件路由、租户、别名和服务商进入的附件及压缩包内容；类型应按内容和嵌套识别，不能只看扩展名。“无必要”按业务/角色定义，可含可执行、脚本、宏文档和加密压缩包。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "At the mail gateway or cloud service, reject, quarantine or sanitize disallowed types; inspect MIME, magic, archives and links, control password-protected content, and provide an approved secure transfer alternative. Version rules and exceptions by recipient/use, with sender feedback and analyst review.",
          "zh": "在邮件网关/云服务拒绝、隔离或净化不允许类型，检查 MIME、Magic、压缩嵌套和链接，控制密码包，并提供获批安全传输替代；按收件人/用途版本化规则，例外有发件反馈和分析审查。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "File-type blocking leaves allowed document content, links and cloud shares exposed to other attack paths. Business workflows may require dangerous formats through sandboxed transfer. End-to-end encrypted email and direct SaaS messaging need separate controls; false positives require safe retrieval without teaching bypass.",
          "zh": "拦类型不代表允许文档安全，攻击者可用链接/云分享。业务若必需危险格式，应走沙箱转移。端到端加密邮件和 SaaS 私信需另控；误报取回路径不能教用户绕过。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Send benign required files, renamed executable, double extension, nested archive, encrypted archive and macro sample through internal/external routes. Verify action, user notification, quarantine access, logging and exception expiry; test every MX/connector and direct-delivery path.",
          "zh": "从内外、转发和备用路由发送正常必需文件、改名可执行、双扩展、嵌套包、加密包和宏样本，验证动作、通知、隔离访问、日志和例外到期；覆盖所有 MX/Connector 与直投路径。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "9.6",
          "control": 9,
          "title": {
            "en": "Block Unnecessary File Types",
            "zh": "高风险附件类型"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls9/",
          "snapshot_sha256": "893B95999A6ACDC28F3DE11419EF6E6640E491BA628EA37586763E76C0FF99C7",
          "retrieved_at": "2026-07-30T16:25:45.071Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-9.7",
      "safeguard_id": "9.7",
      "control": 9,
      "title": {
        "en": "Deploy and Maintain Email Server Anti-Malware Protections",
        "zh": "邮件系统反恶意软件"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Cover inbound, outbound and internal mail flow, attachments, URLs and collaboration messages where the service supports malware inspection, including alternate connectors and provider routing. State whether protection is signature, reputation, detonation, content disarm or post-delivery response.",
          "zh": "覆盖入站、出站和内部邮件的附件、URL 与协作消息，包括备用 Connector/服务商路由。声明保护是签名、声誉、沙箱、内容净化还是投递后响应。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Enable layered provider/gateway scanning, sandbox risky supported content, update engines automatically, quarantine safely and connect verdicts to endpoint/incident response. Protect administrative bypasses, test routing after tenant or MX changes and monitor engine/update/export health.",
          "zh": "启用服务商/网关多层扫描，对支持的高风险内容沙箱，自动更新引擎，安全隔离并把判定接事件响应；保护管理旁路，租户/MX 变化后测路由，监控引擎/更新/导出。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A configured product may skip internal mail, large files, encrypted archives or unsupported formats. Sandboxes can be evaded and generate privacy/data-location concerns. Email protection complements endpoint behavior detection; a clean verdict is not proof of safety.",
          "zh": "配置产品可能跳过内部邮件、大文件、加密包或不支持类型。沙箱可被规避并有隐私/地域问题。邮件防护与终端行为检测互补；“干净”判定不是安全证明。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Use industry-safe test files and benign detonation fixtures through external, internal, forwarded and alternate routes; verify block/quarantine, verdict, user notice, release control and telemetry. Confirm encrypted/password archives follow policy and that a scanner outage alerts.",
          "zh": "用行业安全测试文件与无害沙箱 Fixture 经外部、内部、转发和替代路径验证阻断/隔离、判定、通知、放行与遥测；检查加密/密码包政策和扫描服务故障告警。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "9.7",
          "control": 9,
          "title": {
            "en": "Deploy and Maintain Email Server Anti-Malware Protections",
            "zh": "邮件系统反恶意软件"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls9/",
          "snapshot_sha256": "893B95999A6ACDC28F3DE11419EF6E6640E491BA628EA37586763E76C0FF99C7",
          "retrieved_at": "2026-07-30T16:25:45.071Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-10.1",
      "safeguard_id": "10.1",
      "control": 10,
      "title": {
        "en": "Deploy and Maintain Anti-Malware Software",
        "zh": "反恶意软件覆盖"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Include every enterprise asset capable of an anti-malware control, with platform-appropriate endpoint, workload, cloud or native protection; explicitly enumerate unsupported IoT/OT, appliances, containers and serverless services. “Installed” is weaker than healthy, enforcing and reporting.",
          "zh": "包括一切能部署反恶意软件控制的企业资产，按平台采用终端、工作负载、云原生等保护，并明确列出不支持的 IoT/OT、设备、容器、Serverless。“已安装”弱于健康、强制且上报。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Deploy approved software through standard builds, enable real-time and scheduled protection appropriate to workload, protect tamper settings, centralize alerts and reconcile health to the asset inventory. Use workload/image/runtime or network controls where conventional agents are unsuitable.",
          "zh": "标准构建部署批准软件，按工作负载启用实时/计划保护，防篡改，集中告警，并把健康与资产台账对账；传统 Agent 不适合时用镜像、Runtime 或网络控制。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "On-demand scans while real-time protection is disabled cannot support a runtime claim. Exclusions, performance modes and conflicting agents can neutralize coverage. Linux/cloud or application servers still need a threat-model decision; unsupported assets require isolation, allowlisting, monitoring and lifecycle treatment.",
          "zh": "实时保护关闭时的按需扫描不能支撑运行兼容/保护结论。排除、性能模式与冲突 Agent 可让覆盖失效。Linux/云/应用服务器也要按威胁模型决定；不支持资产需隔离、允许清单、监测和生命周期处理。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Use safe industry test artifacts and configuration canaries to verify prevention/detection, quarantine, alert, update and response on each platform class. Measure recently healthy, correctly configured, reporting assets over eligible assets, with passive-only, disabled, stale and unsupported populations separate.",
          "zh": "各平台用安全行业测试制品和配置金丝雀验证防护/检测、隔离、告警、更新与响应；覆盖率是近期健康、正确配置且回报的合格资产，单列仅按需、禁用、陈旧和不支持。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "10.1",
          "control": 10,
          "title": {
            "en": "Deploy and Maintain Anti-Malware Software",
            "zh": "反恶意软件覆盖"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls10/",
          "snapshot_sha256": "BBDC6A8F61662575C58667EBB74C005F06950B21B0CF58D65E501814C00BE8B5",
          "retrieved_at": "2026-07-30T16:25:46.197Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-10.2",
      "safeguard_id": "10.2",
      "control": 10,
      "title": {
        "en": "Configure Automatic Anti-Malware Signature Updates",
        "zh": "恶意软件特征自动更新"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The requirement covers signature, reputation, model, rule and engine content used by each deployed anti-malware product, including offline and update-relay populations. Automatic-update configuration is not proof that content is current or authentic.",
          "zh": "覆盖每个反恶意软件使用的签名、声誉、模型、规则和引擎内容，包括离线与更新 Relay 资产。配置自动更新，不代表内容当前或真实。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Use vendor-authenticated channels or controlled mirrors, configure frequent automatic retrieval, monitor content age and failed/rejected updates, stage engine changes where needed and provide a secure offline import workflow. Protect proxy, certificate and repository settings from tampering.",
          "zh": "用厂商认证通道或受控镜像频繁自动取回，监控内容年龄和失败/拒绝，必要时分批引擎变化，并提供安全离线导入；保护代理、证书和仓库设置。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Air-gapped and intermittently connected assets need bounded manual transfer and receipts. Rollback may be necessary for faulty definitions but must retain threat coverage and a deadline. Behavior-only products still have models/policies or service versions whose freshness and availability require evidence.",
          "zh": "气隙与间歇在线资产需有期限的手工传输和回执。坏定义可能需回滚，但必须保留威胁覆盖并设截止。行为型产品也有模型/策略或服务版本，其新鲜度和可用性同样要证据。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Record actual engine/content versions and publisher times, block the update path in a test group and verify alert/recovery, then deliver a known safe detection introduced by a new content set. Measure healthy current assets over all eligible anti-malware-capable assets, not only those already installed.",
          "zh": "记录真实引擎/内容版本与发布时间，在测试组阻断更新路径，验证告警/恢复，再投递只有新内容能识别的安全样本；覆盖率用全部有能力资产作分母，不能只看已安装。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "10.2",
          "control": 10,
          "title": {
            "en": "Configure Automatic Anti-Malware Signature Updates",
            "zh": "恶意软件特征自动更新"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls10/",
          "snapshot_sha256": "BBDC6A8F61662575C58667EBB74C005F06950B21B0CF58D65E501814C00BE8B5",
          "retrieved_at": "2026-07-30T16:25:46.197Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-10.3",
      "safeguard_id": "10.3",
      "control": 10,
      "title": {
        "en": "Disable Autorun and Autoplay for Removable Media",
        "zh": "禁用可移动介质自动运行"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Scope every asset and account path capable of executing content automatically when removable or mounted media appears, including AutoRun/AutoPlay, desktop handlers, virtual media, disk images and device-specific launch functions. Manual user execution remains a separate risk.",
          "zh": "覆盖所有能在可移动/挂载介质出现时自动执行内容的资产和账户路径，包括 AutoRun/AutoPlay、桌面 Handler、虚拟介质、磁盘镜像和设备特定启动功能。用户手工执行是另一个风险。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Disable auto-execution through secure baselines, prevent ordinary override and apply to all media types and user profiles. Combine with device control, allowlisting and scanning; document any operational workflow that mounts virtual or service media automatically.",
          "zh": "在安全基线禁自动执行，阻止普通用户恢复，覆盖所有介质类型和用户 Profile；结合设备控制、Allowlisting 和扫描，并记录会自动挂虚拟/维修介质的业务流程。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Disabling the UI prompt is not necessarily disabling handler execution. Legacy/OT maintenance may need brokered media and supervised procedure. This safeguard does not block users from opening a malicious file, nor network shares that imitate removable content.",
          "zh": "关掉 UI 提示未必关掉 Handler 执行。旧系统/OT 维护可走受监督中转。此项不能阻止用户手动打开恶意文件，也不覆盖模拟移动介质的网络共享。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Insert safe media containing autorun metadata, mixed content and a virtual-media image under standard and admin users; verify no code launches, policy remains after update/reboot and an attempted change alerts. Inspect effective configuration; assigned policy is supporting evidence.",
          "zh": "在普通与管理用户下插入含 Autorun Metadata、混合内容和虚拟介质镜像的安全样本，确认无代码启动，重启/更新后策略仍在，尝试更改会告警；检查有效配置而非分配策略。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "10.3",
          "control": 10,
          "title": {
            "en": "Disable Autorun and Autoplay for Removable Media",
            "zh": "禁用可移动介质自动运行"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls10/",
          "snapshot_sha256": "BBDC6A8F61662575C58667EBB74C005F06950B21B0CF58D65E501814C00BE8B5",
          "retrieved_at": "2026-07-30T16:25:46.197Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-10.4",
      "safeguard_id": "10.4",
      "control": 10,
      "title": {
        "en": "Configure Automatic Anti-Malware Scanning of Removable Media",
        "zh": "可移动介质自动扫描"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Eligible assets are those that accept removable media and run supported anti-malware protection; media, virtual mounts and encrypted volumes must be accounted for. Scan timing and depth determine whether content can execute before a verdict.",
          "zh": "合格资产是既接受可移动介质又运行受支持反恶意软件的设备；介质、虚拟挂载和加密卷都要算。扫描时机与深度决定内容会不会在判定前执行。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Configure scan-on-mount or before-open, current content and quarantine, block access until completion for higher-risk zones, and log media/device identity and result. Pair with device authorization and an alternative secure-transfer station for unsupported or sensitive systems.",
          "zh": "配置挂载即扫或打开前扫，保持内容当前并隔离；高风险区完成前阻断访问，记录介质/设备身份和结果。结合设备授权，对不支持/敏感系统提供安全中转站。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Large media can cause unacceptable delay; define size/time behavior without silently skipping. Encrypted files may be unscannable, and trusted vendor media can still be compromised. OT exceptions need controlled stations, one-way transfer where appropriate and chain of custody.",
          "zh": "大介质会导致延迟，需定义大小/超时行为而不能静默跳过。加密文件不可扫描，可信厂商介质也可能受损。OT 例外需受控中转、必要时单向传输和保管链。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Insert clean, safe test-detection, nested archive and encrypted media; verify access sequencing, detection/quarantine, user notice and central log. Measure eligible media-capable assets with proven effective policy and recent health, not all anti-malware-capable assets as the CAS denominator does.",
          "zh": "插入干净、安全检测、嵌套包和加密介质，验证访问顺序、检测/隔离、通知和中央日志。指标按“能接介质资产”算有效策略，不能像 CAS 用全部反恶意软件能力资产作分母。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "10.4",
          "control": 10,
          "title": {
            "en": "Configure Automatic Anti-Malware Scanning of Removable Media",
            "zh": "可移动介质自动扫描"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls10/",
          "snapshot_sha256": "BBDC6A8F61662575C58667EBB74C005F06950B21B0CF58D65E501814C00BE8B5",
          "retrieved_at": "2026-07-30T16:25:46.197Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-10.5",
      "safeguard_id": "10.5",
      "control": 10,
      "title": {
        "en": "Enable Anti-Exploitation Features",
        "zh": "反利用缓解"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Scope hardware, OS, runtime, browser and application mitigations such as DEP/NX, ASLR, control-flow protection, sandboxing, code signing and platform integrity on every supported asset/software role. Default availability differs by architecture, compiler, compatibility and workload.",
          "zh": "覆盖硬件、OS、Runtime、浏览器和应用的 DEP/NX、ASLR、控制流保护、沙箱、代码签名、平台完整性等缓解；默认能力因架构、编译器、兼容与工作负载而异。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Enable supported mitigations through baselines and build/runtime policy, test application compatibility, prevent downgrade and record narrowly scoped per-process exceptions. Keep OS, firmware and applications current because mitigations depend on the implementation and cannot repair every vulnerability.",
          "zh": "通过基线与构建/运行策略启用支持功能，做应用兼容，阻止降级，并记录窄的逐进程例外；持续更新 OS、固件和应用，因为缓解依赖实现，不能修复所有漏洞。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A feature enabled globally may be disabled for the vulnerable process; legacy applications can require exceptions. Mitigations increase exploitation cost but do not prove immunity. Containers inherit host/kernel controls, while JIT runtimes and mobile platforms need platform-specific evidence.",
          "zh": "全局启用可能在易受害进程上被关闭；旧应用可有例外。缓解只增加利用成本，不证明免疫。容器继承宿主内核，JIT Runtime 与移动平台要用平台特定证据。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Inspect effective runtime state and launch benign compatibility/exploit-mitigation test fixtures in a lab, verifying prevention and telemetry. Attempt to disable a feature and check tamper detection; measure supported assets/applications with required mitigations active, not assets with a policy assigned.",
          "zh": "检查真实运行状态，在实验室运行无害兼容/缓解 Fixture，验证阻断和遥测；尝试关闭功能测篡改发现。指标按支持的资产/应用上必需缓解生效计算。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "10.5",
          "control": 10,
          "title": {
            "en": "Enable Anti-Exploitation Features",
            "zh": "反利用缓解"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls10/",
          "snapshot_sha256": "BBDC6A8F61662575C58667EBB74C005F06950B21B0CF58D65E501814C00BE8B5",
          "retrieved_at": "2026-07-30T16:25:46.197Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-10.6",
      "safeguard_id": "10.6",
      "control": 10,
      "title": {
        "en": "Centrally Manage Anti-Malware Software",
        "zh": "集中管理反恶意软件"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Central management covers policy, health, updates, detections, response, exclusions and tamper state for every deployed product and tenant. Counting product brands centrally configured ignores unmanaged assets and disconnected agents.",
          "zh": "中央管理覆盖所有部署产品/租户的策略、健康、更新、检测、响应、排除与防篡改；只数多少产品“中央配置”，会漏掉未管资产和断连 Agent。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Enroll assets automatically, use role-based protected administration, standardize policies, monitor heartbeats and drift, integrate incident workflows and retain emergency rollback. Reconcile console agents to the asset inventory in both directions and separate security administration from endpoint administration where needed.",
          "zh": "自动注册资产，以 RBAC 保护管理，标准化策略，监测心跳/漂移，接入事件流程并保留紧急回滚；Console 与资产台账双向对账，必要时分离安全管理与终端管理。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Multiple consoles may be necessary across sovereign, OT or provider boundaries but require federated inventory and response. Console compromise creates broad authority, so MFA, privileged workstations and audit are essential. Offline devices need time-bounded local policy and reconnection enforcement.",
          "zh": "主权、OT 或服务商边界可能需要多个 Console，但需联邦台账与响应。Console 失陷权限极大，需 MFA、特权工作站和审计。离线设备需限时本地策略与重连强制。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Change a test policy, isolate or scan a canary endpoint, then verify delivery, result and rollback. Stop an agent, clone an identity and disconnect a device to test stale/duplicate detection; measure recently managed eligible assets, not centrally managed product count.",
          "zh": "对金丝雀端点下发策略、隔离或扫描并验证送达、结果与回滚；停 Agent、克隆身份、断连设备测试陈旧/重复发现。覆盖率看近期受管的合格资产，不看产品数。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "10.6",
          "control": 10,
          "title": {
            "en": "Centrally Manage Anti-Malware Software",
            "zh": "集中管理反恶意软件"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls10/",
          "snapshot_sha256": "BBDC6A8F61662575C58667EBB74C005F06950B21B0CF58D65E501814C00BE8B5",
          "retrieved_at": "2026-07-30T16:25:46.197Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-10.7",
      "safeguard_id": "10.7",
      "control": 10,
      "title": {
        "en": "Use Behavior-Based Anti-Malware Software",
        "zh": "基于行为的恶意软件防护"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Include assets and workloads where behavior telemetry and prevention can observe process, memory, file, identity or network actions; declare which platforms, containers, cloud workloads and scripts are covered. Signature plus heuristic marketing is not enough without a testable behavior decision.",
          "zh": "包括行为遥测/防护能观察进程、内存、文件、身份或网络动作的资产/工作负载，明确平台、容器、云和脚本覆盖。“签名加启发式”营销不等于可测试的行为判定。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Enable behavior/EDR capabilities, tune prevention by asset role, protect sensors, centralize high-fidelity telemetry and connect containment to incident response. Establish baselines and exceptions without suppressing whole techniques or trusted-parent abuse.",
          "zh": "启用行为/EDR，按资产角色调优防护，保护 Sensor，集中高保真遥测并连接遏制；设基线与例外，不能整类抑制技术或忽略可信父进程滥用。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Behavior products can miss living-off-the-land, kernel, cloud-control-plane and low-and-slow activity and can generate false positives. Detection-only may be appropriate during tuning but is not prevention. Exclusions and sensor degraded modes must be visible, owned and expiring.",
          "zh": "行为产品会漏 Living-off-the-land、内核、云控制面和低慢活动，也会误报。调优期只检测可以合理，但不等于防护。排除和 Sensor 降级必须可见、具名并到期。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Run safe simulations of suspicious child processes, credential-access-like behavior, persistence and ransomware-like file activity under approved test scope, alongside benign administrative controls. Verify detect/prevent/contain, evidence and analyst action; record endpoint-security state and product versions.",
          "zh": "在批准范围安全模拟可疑子进程、凭据访问类行为、持久化和勒索式文件活动，同时跑正常管理员对照；验证检测/阻断/遏制、证据与分析动作，并记录端点安全状态和版本。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "10.7",
          "control": 10,
          "title": {
            "en": "Use Behavior-Based Anti-Malware Software",
            "zh": "基于行为的恶意软件防护"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls10/",
          "snapshot_sha256": "BBDC6A8F61662575C58667EBB74C005F06950B21B0CF58D65E501814C00BE8B5",
          "retrieved_at": "2026-07-30T16:25:46.197Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-11.1",
      "safeguard_id": "11.1",
      "control": 11,
      "title": {
        "en": "Establish and Maintain a Data Recovery Process",
        "zh": "数据恢复流程"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The recovery process covers systems, data, configurations, identities, keys, infrastructure definitions and provider dependencies required to restore business services after deletion, corruption, ransomware, region loss or provider failure. It maps business recovery priorities, RTO/RPO and minimum viable service so backup treatment follows criticality.",
          "zh": "恢复流程覆盖在误删、损坏、勒索、地域或服务商故障后恢复业务所需的系统、数据、配置、身份、密钥、基础设施定义和外部依赖，并按业务优先级、RTO/RPO 与最小可用服务排序，不能把所有备份一视同仁。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Assign business, data, platform, security and crisis owners; document recovery order, dependencies, clean-room requirements, backup security, communications, decision authority and validation. Reconcile with continuity and incident plans, and review annually plus after major architecture, provider or business change.",
          "zh": "指定业务、数据、平台、安全和危机负责人，写清恢复顺序、依赖、净室、备份安全、通信、决策权和验收；与连续性/事件计划对齐，每年及架构、服务商、业务重大变化时更新。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "The current CAS completeness formula divides three process elements by months since review, a dimensional error. A documented process establishes design intent; recoverability remains untested until a representative service is restored and accepted. SaaS, keys, identity, DNS, certificates, licenses and IaC may be prerequisites that ordinary data backups omit; unknown dependency or owner is a recovery gap.",
          "zh": "CAS 当前完整度公式把三个流程要素除以上次复核后的月数，量纲错误。文档建立设计意图；代表性服务完成恢复与验收前，可恢复性仍未经测试。SaaS、密钥、身份、DNS、证书、许可证和 IaC 可能是普通数据备份遗漏的前置条件；未知依赖或责任人就是恢复缺口。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Tabletop and technically rehearse a representative destructive scenario from declaration through clean restore, dependency startup, integrity/security validation and business acceptance. Compare measured recovery point/time with objectives and record blockers, manual knowledge and untested components.",
          "zh": "桌演并技术演练一个代表破坏场景，从宣告到干净恢复、依赖启动、完整性/安全验证和业务验收；把实测恢复点/时间与目标比较，记录阻塞、人工知识和未测组件。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "11.1",
          "control": 11,
          "title": {
            "en": "Establish and Maintain a Data Recovery Process",
            "zh": "数据恢复流程"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls11/",
          "snapshot_sha256": "64B9FC7DBD72CA64F77263A3253BCCD64F658CFD626A18DD543020FB8171C94F",
          "retrieved_at": "2026-07-30T16:25:47.206Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-030"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-11.2",
      "safeguard_id": "11.2",
      "control": 11,
      "title": {
        "en": "Perform Automated Backups",
        "zh": "自动备份"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Recover",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "In-scope assets and services are chosen from business/data recovery requirements, including databases, files, SaaS, cloud state, endpoint data not otherwise synchronized, configurations, code/artifacts and critical identity/key material. Replication and snapshots count only when they preserve usable point-in-time recovery from the relevant failure.",
          "zh": "范围由业务与数据恢复要求决定，包括数据库、文件、SaaS、云状态、未同步终端数据、配置、代码/制品和关键身份/密钥材料。复制与快照只有在能抵御目标故障并恢复时间点时才算。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Automate backups at least weekly and more frequently to meet RPO, monitor job and object success, capture application-consistent state, encrypt and version data, and inventory destinations and retention. New assets inherit policy automatically; failures create owned incidents with bounded retry and escalation.",
          "zh": "至少每周并按 RPO 更频繁地自动备份，监控 Job 与对象成功、应用一致性、加密、版本、目的和保留；新资产自动继承策略，失败生成具名事件而非无限静默重试。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "CAS measures configuration but omits its own recent-success M6/M7 from the score. A green job can back up zero bytes, the wrong tenant or corrupted encrypted data. Serverless/SaaS exports, large databases and laptops need service-specific evidence; excluded transient state must be reproducible and documented.",
          "zh": "CAS 只计配置，自己定义的近期成功 M6/M7 却未入分数。绿色 Job 可备份 0 字节、错误租户或已损坏密文。Serverless/SaaS 导出、大库和笔记本需服务特定证据；排除的短命状态必须可重建且有文档。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Modify a canary file/record, run the job and verify timestamp, scope, application consistency, destination object, immutability and restore. Reconcile recent successful backup objects to every in-scope asset/data set and report missed, partial, stale and never-protected populations.",
          "zh": "修改金丝雀文件/记录后跑备份，验证时间、范围、应用一致性、目的对象、不可变和恢复；把近期成功对象与每个范围资产/数据集对账，报告遗漏、部分、陈旧和从未保护。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "11.2",
          "control": 11,
          "title": {
            "en": "Perform Automated Backups",
            "zh": "自动备份"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls11/",
          "snapshot_sha256": "64B9FC7DBD72CA64F77263A3253BCCD64F658CFD626A18DD543020FB8171C94F",
          "retrieved_at": "2026-07-30T16:25:47.206Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-11.3",
      "safeguard_id": "11.3",
      "control": 11,
      "title": {
        "en": "Protect Recovery Data",
        "zh": "恢复数据保护"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Recovery copies inherit at least the confidentiality, integrity and access requirements of the source, plus stronger resistance to destructive administrators and malware. Scope storage, catalogs, metadata, credentials, keys, transfer, restore environments and provider support—not only backup payload encryption.",
          "zh": "恢复副本至少继承源数据的机密、完整和访问要求，并额外抵抗破坏性管理员与恶意软件。范围包括载荷、目录、元数据、凭据、密钥、传输、恢复环境和服务商支持，不只“备份加密”。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Encrypt in transit and at rest, separate backup and production identities/administration, enforce MFA and least privilege, make critical copies immutable, monitor access/deletion, protect keys and test integrity. Use independent accounts/tenants where the threat model includes production compromise.",
          "zh": "传输/静态加密，分离备份与生产身份/管理，MFA 与最小权限，关键副本不可变，监测访问/删除，保护密钥并验完整性；若威胁模型含生产失陷，使用独立账号/租户。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "CAS reduces this safeguard to encryption, which leaves ransomware and privileged deletion untested. Deduplication, shared keys and backup agents can bridge tenants. Legal access, break-glass and provider support require custody and monitoring; encryption without recoverable keys destroys availability.",
          "zh": "CAS 把本项缩成加密，未测勒索和高权删除。去重、共享密钥和备份 Agent 会桥接租户。法定访问、破窗和服务商支持需保管/监测；没有可恢复密钥的加密会毁掉可用性。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Attempt read, alteration and deletion using ordinary production and backup operators, then verify denial/alert or documented authority. Restore and hash/sample content, inspect key and immutability policy, and confirm logs survive. Compare protection requirements copy by copy to source classification.",
          "zh": "用普通生产和备份管理员尝试读、改、删，验证拒绝/告警或明示权力；恢复并哈希/抽样内容，检查密钥和不可变策略，确认日志存活，并逐副本对照源分级要求。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "11.3",
          "control": 11,
          "title": {
            "en": "Protect Recovery Data",
            "zh": "恢复数据保护"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls11/",
          "snapshot_sha256": "64B9FC7DBD72CA64F77263A3253BCCD64F658CFD626A18DD543020FB8171C94F",
          "retrieved_at": "2026-07-30T16:25:47.206Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-11.4",
      "safeguard_id": "11.4",
      "control": 11,
      "title": {
        "en": "Establish and Maintain an Isolated Instance of Recovery Data",
        "zh": "隔离恢复副本"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Recover",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "At least one recovery instance must be isolated from the failure and authority domain that can destroy production and primary backups. Isolation can be offline, immutable with independent administration, cross-account/region/provider or off-site, but geographic distance alone does not separate credentials or control planes.",
          "zh": "至少一份恢复数据要与能破坏生产及主备份的故障/权限域隔离。离线、独立管理的不可变、跨账号/地域/服务商或异地都可实现；距离远但共用凭据/控制面不算隔离。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Design a distinct trust path with separate credentials, write-once or delayed deletion, protected catalog/keys and controlled restore channel. Keep versioned points before likely attacker dwell time and monitor any bridge; document which failures each copy survives and its reattachment procedure.",
          "zh": "设计不同信任路径，独立凭据、只写或延迟删除、受保护目录/密钥和受控恢复通道；保留早于可能攻击驻留期的版本，监控桥接，并说明每份副本能抵抗哪些故障及如何重新连接。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A cloud bucket in another region under the same compromised root is not isolated. Permanently online mounts and shared backup credentials collapse the boundary. Offline media needs inventory, environment and freshness; immutable copies still preserve malware, so clean-point selection and scanning remain necessary.",
          "zh": "同一 Root 管理的跨地域 Bucket 不是隔离。永久在线挂载和共享备份凭据会塌边界。离线介质需台账、环境与新鲜度；不可变也会保存恶意软件，因此要选干净点并扫描。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Compromise or disable a test production administrator and attempt to enumerate/delete the isolated copy. Simulate primary region/account and backup-console loss, then restore through the independent path. Verify deletion delay, credential separation, clean-room access and last good recovery point.",
          "zh": "禁用或“攻陷”测试生产管理员，尝试枚举/删除隔离副本；模拟主地域/账号和备份 Console 故障后走独立路径恢复，验证删除延迟、凭据分离、净室访问和最后良好点。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "11.4",
          "control": 11,
          "title": {
            "en": "Establish and Maintain an Isolated Instance of Recovery Data",
            "zh": "隔离恢复副本"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls11/",
          "snapshot_sha256": "64B9FC7DBD72CA64F77263A3253BCCD64F658CFD626A18DD543020FB8171C94F",
          "retrieved_at": "2026-07-30T16:25:47.206Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-11.5",
      "safeguard_id": "11.5",
      "control": 11,
      "title": {
        "en": "Test Data Recovery",
        "zh": "恢复演练"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Recover",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The quarterly sample must represent business criticality, technology, size, encryption, provider and recovery path; its selection method prevents an easiest-small-files bias. Over time, every critical service and dependency should be exercised, including full service reconstruction and not just file extraction.",
          "zh": "季度抽样必须代表业务关键度、技术、规模、加密、服务商和恢复路径，不能只挑最好恢复的小文件；长期轮转应覆盖每个关键服务和依赖，包括全服务重建而非只解压文件。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Maintain a risk-based rotation, isolated test environment, success criteria for RTO/RPO, integrity, security and business function, and remediation owners. Preserve commands, versions, keys and human steps; convert repeated manual recovery into tested automation.",
          "zh": "维护风险化轮转、隔离测试环境，以及 RTO/RPO、完整性、安全和业务功能成功标准；保留命令、版本、密钥和人工步骤，给修复指定责任人，并把重复人工过程自动化。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A tool reporting “restore successful” may deliver corrupt, stale or unusable data. Tests must include an isolated copy periodically. Privacy limits test access, so use controlled staff/masking without skipping integrity. CAS pass rate needs declared sample selection; otherwise a tiny biased sample can report 100%.",
          "zh": "工具显示“恢复成功”可能只得到损坏、陈旧或不可用数据；隔离副本也要周期测试。隐私可用受控人员/脱敏，不可跳过完整性。CAS 的恢复成功率必须配抽样规则，否则挑一个小样本就能 100%。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Restore from selected points without using production shortcuts, validate data/application semantics, authentication, network dependencies, security baseline and user acceptance, then securely dispose of test copies. Record measured times, data loss, failures and retest closure.",
          "zh": "不借生产捷径从选定点恢复，验证数据/应用语义、认证、网络依赖、安全基线和用户验收，随后安全销毁测试副本；记录实测时间、数据损失、失败和复测关闭。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "11.5",
          "control": 11,
          "title": {
            "en": "Test Data Recovery",
            "zh": "恢复演练"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls11/",
          "snapshot_sha256": "64B9FC7DBD72CA64F77263A3253BCCD64F658CFD626A18DD543020FB8171C94F",
          "retrieved_at": "2026-07-30T16:25:47.206Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-12.1",
      "safeguard_id": "12.1",
      "control": 12,
      "title": {
        "en": "Ensure Network Infrastructure is Up-to-Date",
        "zh": "网络基础设施生命周期"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Include physical/virtual routers, switches, firewalls, wireless, controllers, VPN, load balancers, DNS/DHCP, SD-WAN, cloud networking and NaaS features with software/firmware and support state. “Latest stable” is role/vendor specific and differs from merely supported.",
          "zh": "包括物理/虚拟路由、交换、防火墙、无线、控制器、VPN、负载均衡、DNS/DHCP、SD-WAN、云网络和 NaaS 的软件/固件与支持状态。“最新稳定”由角色/厂商决定，不等于仅“仍受支持”。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Review versions at least monthly, subscribe to vendor security/lifecycle notices, qualify stable targets, stage and roll out with redundant paths and rollback, and replace unsupported products. Record provider-managed service release evidence and tenant actions still required.",
          "zh": "至少每月查版本，订阅厂商安全/生命周期通知，验证稳定目标，带冗余路径和回滚分批升级，并替换不受支持产品；托管服务记录发布证据和租户仍需动作。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A newer release can introduce severe defects, so controlled deferral is valid with evidence and deadline. HA pairs running mixed versions may be temporarily required. NaaS marketing leaves tenant features and appliance currency unverified; end-of-support hardware needs a funded replacement or isolation plan.",
          "zh": "新版本也会有严重缺陷，有证据与截止日的受控延期可合理。HA 对可能短期混跑版本。NaaS 宣传不能证明租户功能/设备更新；EOL 硬件需有预算替换或隔离。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Reconcile every network asset/control plane to current and supported authoritative versions, sample running state, and deploy a lab/canary update including failover/rollback. Report unsupported, vulnerable, deferred, unreachable and provider-opaque populations separately.",
          "zh": "把每个网络资产/控制面与权威当前/支持版本对账，抽查运行状态，并在实验室/金丝雀部署含故障转移/回滚的更新；不支持、易受害、延期、不可达和服务商不透明分别报告。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "12.1",
          "control": 12,
          "title": {
            "en": "Ensure Network Infrastructure is Up-to-Date",
            "zh": "网络基础设施生命周期"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls12/",
          "snapshot_sha256": "B86C7314F9857EE4AFD9ACAD5661B3A82B1F8B43C6C0D91165DE0B14B6531E53",
          "retrieved_at": "2026-07-30T16:25:48.241Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-12.2",
      "safeguard_id": "12.2",
      "control": 12,
      "title": {
        "en": "Establish and Maintain a Secure Network Architecture",
        "zh": "安全网络架构"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The architecture covers segmentation, least privilege and availability across user, server, management, cloud, remote, partner, OT/IoT, Internet and service/control planes. Segments are trust and policy boundaries, not simply subnets; identity and application controls may enforce them in zero-trust designs.",
          "zh": "覆盖用户、服务器、管理、云、远程、伙伴、OT/IoT、互联网和服务/控制面，至少处理分段、最小权限与可用性。Segment 是信任/策略边界，不仅是子网；零信任架构可用身份/应用控实现。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Derive zones and allowed flows from services/data, minimize transitive reachability, separate management, add resilient paths and capacity, and enforce through firewalls, security groups, proxies, identity-aware gateways and routing. Review designs and effective state through change control and threat scenarios.",
          "zh": "从服务和数据流推导区域与允许流，减少传递可达，隔离管理面，增加冗余/容量；用防火墙、安全组、代理、身份网关和路由执行，并通过变更控制和威胁场景审查设计/实效。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "The CAS segment test says one segment both fails and passes due overlapping conditions and treats an unauthorized device as the sole least-privilege test. Microservices, shared control planes, DNS, identity and backup can cross zones. Flat networks require explicit risk and phased redesign; segmentation that breaks emergency/safety paths is also defective.",
          "zh": "CAS 在一个 Segment 时既写 Fail 又写 Pass，并用“未授权设备能否接入”代替全部最小权限。微服务、共享控制面、DNS、身份、备份会跨区。平网需有风险和分期重构；分段若破坏应急/安全路径也有缺陷。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Test allowed business flows and denied lateral/management paths from representative identities/assets, then fail a link/control component and observe availability and policy consistency. Compute effective reachability against approved flows and discover undocumented paths.",
          "zh": "从代表身份/资产测试允许业务流和拒绝横向/管理路径，再故障链路/控制组件观察可用与政策一致；计算有效可达与批准流的偏差，发现未记录路径。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "12.2",
          "control": 12,
          "title": {
            "en": "Establish and Maintain a Secure Network Architecture",
            "zh": "安全网络架构"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls12/",
          "snapshot_sha256": "B86C7314F9857EE4AFD9ACAD5661B3A82B1F8B43C6C0D91165DE0B14B6531E53",
          "retrieved_at": "2026-07-30T16:25:48.241Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-031"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-12.3",
      "safeguard_id": "12.3",
      "control": 12,
      "title": {
        "en": "Securely Manage Network Infrastructure",
        "zh": "安全管理网络基础设施"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Management includes interactive, API and automated changes to all network devices and cloud/service controls, from administrator workstation through bastion/controller to target. It covers protocol, identity, reachability, configuration provenance, secrets, backups and emergency console paths.",
          "zh": "包括管理员工作站经跳板/控制器到网络设备与云/服务控制面的交互、API 和自动变更；覆盖协议、身份、可达、配置来源、秘密、备份和应急 Console。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Use dedicated management networks/resources, central AAA/MFA, encrypted protocols, version-controlled templates/IaC, reviewed deployment and protected out-of-band recovery. Disable public and insecure interfaces, rotate keys, restrict API scopes and log command/config changes.",
          "zh": "使用专用管理网/资源、中央 AAA/MFA、加密协议、版本化模板/IaC、评审部署和受保护带外恢复；关闭公网与不安全接口，轮换密钥，收窄 API Scope，记录命令/配置变化。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "IaC coverage by “network segment,” as CAS measures, leaves device and cloud-policy coverage unresolved. Controller-generated and emergency state may be legitimate but must reconcile. Serial console, vendor tunnels and lost-controller modes need physical/custody controls and audited break-glass.",
          "zh": "CAS 以“网段使用 IaC”计覆盖，不能证明全部设备或云策略受管。控制器生成/应急状态可以合法，但要对账。串口、厂商隧道和控制器丢失模式需物理/保管和审计破窗。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Attempt management from production/user networks, direct target paths, old credentials and insecure protocols; trace an approved change from commit to effective config, drift detection and rollback. Sample console and provider-support access, not just SSH/HTTPS configuration.",
          "zh": "从生产/用户网、直连目标、旧凭据和不安全协议尝试管理；从提交追批准变更到有效配置、漂移和回滚，并抽查 Console/服务商支持，不能只看 SSH/HTTPS。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "12.3",
          "control": 12,
          "title": {
            "en": "Securely Manage Network Infrastructure",
            "zh": "安全管理网络基础设施"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls12/",
          "snapshot_sha256": "B86C7314F9857EE4AFD9ACAD5661B3A82B1F8B43C6C0D91165DE0B14B6531E53",
          "retrieved_at": "2026-07-30T16:25:48.241Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-12.4",
      "safeguard_id": "12.4",
      "control": 12,
      "title": {
        "en": "Establish and Maintain Architecture Diagram(s)",
        "zh": "架构图与网络文档"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Documentation includes current trust zones, networks, routes, boundaries, external/provider links, Internet exposure, management/control planes, critical services, data flows and security enforcement points across on-premises and cloud. A presentation diagram without identifiers or ownership cannot support operations.",
          "zh": "文档包含现行信任区、网络、路由、边界、外部/服务商链路、互联网暴露、管理/控制面、关键服务、数据流和强制点，横跨本地与云。只有展示方框而无标识/责任，不能支撑运营。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Generate from authoritative inventories/IaC where possible, add business/trust meaning and owners, version changes and review annually plus on material changes. Maintain separate context, trust/flow, deployment and recovery views linked by stable asset/service IDs; this preserves both legibility and traceability.",
          "zh": "能从权威台账/IaC 生成的先生成，再补业务/信任含义和责任人；版本化变更，每年及重大变化时更新。用稳定资产/服务 ID 连接上下文、信任/流向、部署和恢复多视图，别做一张看不懂的大图。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Represent dynamic and autoscaled resources by pattern and control plane; enumerating every pod creates immediate staleness. Sensitive diagrams require access control and incident-time availability. Accuracy requires live-state checks beyond a review date, and topology without identity, data or provider boundaries misses decisive paths.",
          "zh": "动态/自动扩容资源用模式与控制面表达，不必画每个 Pod。敏感图要控访问，也要能在事件中取得。复核日期不能证明准确；只有拓扑、无身份/数据/服务商边界，会漏决定性路径。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Select routes, cloud controls and services from live state and trace them onto diagrams, then select documented paths and verify reality. Introduce a test change through the approved workflow; record unknown links, stale objects and ownership gaps.",
          "zh": "从实时路由、云控制和服务抽样回图，再从图抽样回现实；引入测试变更走批准流程，记录未知链路、陈旧对象和责任缺口。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "12.4",
          "control": 12,
          "title": {
            "en": "Establish and Maintain Architecture Diagram(s)",
            "zh": "架构图与网络文档"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls12/",
          "snapshot_sha256": "B86C7314F9857EE4AFD9ACAD5661B3A82B1F8B43C6C0D91165DE0B14B6531E53",
          "retrieved_at": "2026-07-30T16:25:48.241Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-12.5",
      "safeguard_id": "12.5",
      "control": 12,
      "title": {
        "en": "Centralize Network Authentication, Authorization, and Auditing (AAA)",
        "zh": "集中网络认证、授权与审计（AAA）"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Scope administrator and, where applicable, user/device authentication, authorization and accounting for routers, switches, wireless, VPN, firewalls, controllers and cloud network services. Central login without command/role authorization or durable accounting only satisfies part of AAA.",
          "zh": "覆盖路由、交换、无线、VPN、防火墙、控制器和云网络服务的管理员，以及适用的用户/设备认证、授权和审计。只集中登录、无命令/角色授权和持久审计，只完成 AAA 的一部分。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Integrate network devices with resilient central identity/AAA, named admin accounts, MFA or strong upstream auth, role/command policy and tamper-resistant accounting; restrict and vault local fallback accounts. Use at least two available services or a tested failure design.",
          "zh": "接入有弹性的中央身份/AAA，实名管理员、MFA 或强上游认证、角色/命令策略和防篡改 Accounting；限制并入库本地回退账户。至少两个服务或已演练的故障设计。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Fail-open authentication can turn an outage into unrestricted access; fail-closed can strand recovery, so local break-glass is controlled and tested. Shared RADIUS/TACACS accounts, provider consoles and devices without protocol support need explicit alternative evidence. CAS's corrupted title is an editorial defect, not a change in intent.",
          "zh": "Fail-open 会把故障变成无约束访问，Fail-closed 会锁死恢复，本地破窗因此必须受控、可测。共享 RADIUS/TACACS 账户、服务商 Console 和不支持协议设备需替代证据。CAS 标题损坏只是编辑缺陷，不改变本意。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Authenticate allowed and denied roles, attempt prohibited commands, disable a user and test failover/outage/local fallback. Trace command and configuration accounting to the named person and target; reconcile every network asset and its effective AAA order.",
          "zh": "测试允许/拒绝角色、禁止命令、禁用用户、故障转移/停机/本地回退；把命令和配置审计追到具名人和目标，并逐设备核对有效 AAA 顺序。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "12.5",
          "control": 12,
          "title": {
            "en": "Centralize Network Authentication, Authorization, and Auditing (AAA)",
            "zh": "集中网络认证、授权与审计（AAA）"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls12/",
          "snapshot_sha256": "B86C7314F9857EE4AFD9ACAD5661B3A82B1F8B43C6C0D91165DE0B14B6531E53",
          "retrieved_at": "2026-07-30T16:25:48.241Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-032"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-12.6",
      "safeguard_id": "12.6",
      "control": 12,
      "title": {
        "en": "Use of Secure Network Management and Communication Protocols",
        "zh": "安全网络管理与通信协议"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The population includes management and access/communication protocols on wired, wireless, WAN, VPN, device and cloud networks: SSH/HTTPS/SNMPv3, secure routing/control, 802.1X, WPA2-Enterprise or stronger and authenticated/encrypted equivalents. Approval binds version, cipher, authentication and role.",
          "zh": "包括有线、无线、WAN、VPN、设备与云网络的管理和接入/通信协议：SSH/HTTPS/SNMPv3、安全路由控制、802.1X、WPA2-Enterprise 或更强同类。批准必须绑定版本、算法、认证和角色。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Maintain an authorized protocol/configuration catalog, disable plaintext/legacy versions, manage certificates/keys, enforce enterprise wireless and port identity, and monitor downgrade or rogue service. Segment unavoidable legacy protocols and broker management through secure gateways.",
          "zh": "维护批准协议/配置目录，关闭明文与旧版本，管理证书/密钥，强制企业无线和端口身份，监测降级/Rogue 服务；无法移除的旧协议分段并经安全网关代理。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "An “approved protocol” with anonymous, shared, expired or weak configuration still fails. Consumer WPA2-PSK is not WPA2-Enterprise, and SNMPv3 can use weak modes. CAS defines both M6 and M7 as unauthorized management protocols; implementers must rebuild measures from the intended authorized/improper populations.",
          "zh": "“批准协议”若匿名、共享、过期或弱配置仍失败。消费级 WPA2-PSK 不是 WPA2-Enterprise，SNMPv3 也可弱配置。CAS 把 M6/M7 都定义成未授权管理协议，须按原意重建指标。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Scan and negotiate every representative management/access path for protocols, versions and ciphers; attempt downgrade, weak credential, rogue AP/server and invalid certificate. Verify expected connectivity and logs across primary and failover.",
          "zh": "扫描并协商代表管理/接入路径的协议、版本与算法，尝试降级、弱凭据、Rogue AP/服务器和无效证书；主/备路径都验证业务与日志。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "12.6",
          "control": 12,
          "title": {
            "en": "Use of Secure Network Management and Communication Protocols",
            "zh": "安全网络管理与通信协议"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls12/",
          "snapshot_sha256": "B86C7314F9857EE4AFD9ACAD5661B3A82B1F8B43C6C0D91165DE0B14B6531E53",
          "retrieved_at": "2026-07-30T16:25:48.241Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-033"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-12.7",
      "safeguard_id": "12.7",
      "control": 12,
      "title": {
        "en": "Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure",
        "zh": "远程设备 VPN 与 AAA"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Scope remote end-user devices accessing private enterprise resources; require authentication through enterprise-managed VPN and AAA before access. Public SaaS access may instead follow identity-aware application controls, while split tunnels and device tunnels require declared path treatment.",
          "zh": "覆盖远程终端访问私有企业资源，要求在访问前经企业管理 VPN 与 AAA。公共 SaaS 可走身份感知应用控制；Split Tunnel 和 Device Tunnel 要明确路径。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Configure approved VPN/ZTNA clients and gateways, MFA/AAA, device identity/posture, destination least privilege, session limits and revocation. Prevent direct alternate routes, protect profiles and make enrolment conditional on managed device state; separate vendor and admin paths.",
          "zh": "配置批准 VPN/ZTNA Client/Gateway、MFA/AAA、设备身份/姿态、最小目的、会话限制和撤销；防直连备用路径，保护 Profile，注册取决于受管设备状态，分开厂商/管理员。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "The CAS final operation labels the intersection M1 instead of M11, so literal automation overwrites the denominator. Always-on machine VPN may precede user AAA but sensitive access needs a user decision. VPN is not required merely to claim compliance if a stronger identity-aware path replaces network access; the architecture must prove equivalence.",
          "zh": "CAS 最后交集写成 M1 而非 M11，照抄会覆盖分母。机器 Always-on VPN 可先于用户 AAA，但敏感资源仍需用户决定。若更强身份感知方式取代网络访问，不必为形式强上 VPN，但架构要证明等效。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Connect approved/unapproved devices and identities through primary, fallback and alternate protocols; verify pre-auth isolation, AAA decision, destination scope, logs and session termination after revocation. Measure remote devices whose actual private-resource paths traverse both controls.",
          "zh": "用批准/未批准设备和身份走主、备、替代协议，验证预认证隔离、AAA、目的范围、日志和撤销后终止；只计算真实私有资源路径同时经过两项控制的远程资产。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "12.7",
          "control": 12,
          "title": {
            "en": "Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure",
            "zh": "远程设备 VPN 与 AAA"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls12/",
          "snapshot_sha256": "B86C7314F9857EE4AFD9ACAD5661B3A82B1F8B43C6C0D91165DE0B14B6531E53",
          "retrieved_at": "2026-07-30T16:25:48.241Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-034"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-12.8",
      "safeguard_id": "12.8",
      "control": 12,
      "title": {
        "en": "Establish and Maintain Dedicated Computing Resources for All Administrative Work",
        "zh": "专用管理计算环境"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Include every workstation, virtual desktop, bastion or isolated browser/terminal used for privileged work. It must be physically or logically separated from ordinary user activity and the primary network, and must not have general Internet access; required update/source paths are tightly mediated.",
          "zh": "包括用于特权工作的工作站、VDI、跳板或隔离浏览/终端。它要与日常用户活动和主网物理或逻辑隔离，不可有通用互联网；必要更新/源路径须严格中介。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Issue hardened privileged access workstations or dedicated virtual sessions, restrict software and destinations, use separate admin identities/MFA, prevent email/web/productivity use and mediate files/updates. Protect boot, device, clipboard and credential boundaries and monitor sessions.",
          "zh": "发放加固 PAW 或专用虚拟会话，限制软件与目的，使用独立管理员身份/MFA，禁止邮件/Web/办公并中介文件/更新；保护启动、设备、剪贴板和凭据边界，监测会话。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A second VM on the same compromised daily endpoint offers weak separation unless host and credential risk are addressed. Cloud consoles still need a dedicated environment. Vendor docs and patches may require a curated proxy; blanket Internet access is not justified, while a resource with no tested recovery can lock administrators out.",
          "zh": "在同一已污染日常主机开第二 VM，除非 Host/凭据风险受控，否则隔离很弱。云 Console 同样需要专用环境。文档/补丁可经 Curated Proxy；全网访问不合理，但无法恢复的 PAW 也会锁死管理员。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Attempt general Internet, email, unapproved software, user-network and direct management access from both privileged and ordinary workstations. Verify only approved admin targets and controlled update routes work; inspect DNS, proxy, clipboard, drive and browser escape paths.",
          "zh": "分别从特权和普通工作站尝试通用互联网、邮件、未批准软件、用户网和直连管理；只允许批准管理目标和受控更新，检查 DNS、代理、剪贴板、磁盘和浏览器逃逸。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "12.8",
          "control": 12,
          "title": {
            "en": "Establish and Maintain Dedicated Computing Resources for All Administrative Work",
            "zh": "专用管理计算环境"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls12/",
          "snapshot_sha256": "B86C7314F9857EE4AFD9ACAD5661B3A82B1F8B43C6C0D91165DE0B14B6531E53",
          "retrieved_at": "2026-07-30T16:25:48.241Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-13.1",
      "safeguard_id": "13.1",
      "control": 13,
      "title": {
        "en": "Centralize Security Event Alerting",
        "zh": "安全告警集中化"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Central alerting covers security-relevant events from endpoint, identity, network, cloud/SaaS, application, data and provider sources, including source-health alerts. Centralization means one governed triage and correlation operating model; data can remain in federated stores when sovereignty or scale requires it.",
          "zh": "集中告警覆盖终端、身份、网络、云/SaaS、应用、数据和服务商的安全事件，也包括源健康。集中指一个受治理的分诊/关联运营模型；数据因主权或规模可留在联邦存储。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Route normalized high-value alerts to a SIEM or equivalent analytics platform, map stable asset/account identities, assign severity, owner, playbook and SLO, deduplicate without losing scope and monitor rule/source health. Separate detection engineering, platform administration and case disposition.",
          "zh": "把归一高价值告警送 SIEM/分析平台，映射稳定资产/账户身份，设严重度、责任人、Playbook 和 SLO；去重但不丢范围，监测规则/来源健康，并分离检测工程、平台管理和案件处置。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Central logs without security rules do not satisfy alerting, and vendor defaults rarely reflect local architecture. Too many low-quality alerts conceal high-risk events. Air-gapped/federated environments can centralize governance and cases without moving all raw data; every blind spot has an owner and compensating method.",
          "zh": "中央有日志但无安全规则，不满足告警；厂商默认很少贴合本地架构。低质量海量告警会淹没高危。气隙/联邦环境可集中治理和案件而不搬全部原始数据，每个盲区仍需责任人与补偿。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Generate cross-source canary behavior and verify correlation, case creation, enrichment, analyst decision and response; then stop one source and break one parser. Measure eligible security-event sources delivering useful alerts, alert backlog/age and missed/duplicate outcomes, not product installation.",
          "zh": "生成跨源金丝雀行为，验证关联、开案、富化、分析决定和响应；再停一个源、破一个 Parser。指标看合格安全事件源能否产生有用告警，以及积压年龄、漏报/重复结果，不能看产品安装。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "13.1",
          "control": 13,
          "title": {
            "en": "Centralize Security Event Alerting",
            "zh": "安全告警集中化"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls13/",
          "snapshot_sha256": "F31FFE89DE5087977E7CB6FBD81EC876602871F30C8EA815C0DF862CA40F65BF",
          "retrieved_at": "2026-07-30T16:26:00.266Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-13.2",
      "safeguard_id": "13.2",
      "control": 13,
      "title": {
        "en": "Deploy a Host-Based Intrusion Detection Solution",
        "zh": "主机入侵检测"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Eligible assets are endpoints, servers and workloads where host telemetry can detect unauthorized change or behavior, including file/process, identity, configuration and integrity signals. Declare platforms and event classes covered; an anti-malware agent may overlap but needs an actual detection capability.",
          "zh": "适用资产是能用主机遥测发现未授权变化/行为的终端、服务器和工作负载，包括文件/进程、身份、配置、完整性。反恶意软件可重叠，但必须有真实检测能力。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Deploy HIDS/EDR or platform-native telemetry with protected sensors, tuned rules, central health and alert routing. Establish baselines for critical files/configuration and suspicious behaviors, link to asset roles and preserve enough evidence for investigation.",
          "zh": "部署 HIDS/EDR 或原生遥测，保护 Sensor、调优规则、集中健康/告警；为关键文件/配置和可疑行为建基线，关联资产角色并留足调查证据。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Installed software is the only thing CAS measures, so a silent or untuned agent can pass. Containers, immutable hosts and serverless require image/runtime/cloud alternatives. High-change paths need scoped tuning; broad exclusions, missing kernel visibility or local attacker tampering are explicit residual risks.",
          "zh": "CAS 只测软件安装，静默或未调优 Agent 也可通过。容器、不可变宿主和 Serverless 需镜像/Runtime/云替代。高变路径要精准调优；大范围排除、缺内核可见或易被本地攻击者停用都是剩余风险。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Modify a monitored benign file/configuration, simulate safe suspicious process behavior and stop the agent; verify detection, identity, context, alert and analyst action. Measure recently healthy assets with tested rules over eligible assets, plus blind/degraded modes.",
          "zh": "修改受监控无害文件/配置，安全模拟可疑进程，再停 Agent，验证发现、身份、上下文、告警与分析动作；以近期健康且规则实测的资产/合格资产为覆盖，另列 Blind/Degraded。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "13.2",
          "control": 13,
          "title": {
            "en": "Deploy a Host-Based Intrusion Detection Solution",
            "zh": "主机入侵检测"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls13/",
          "snapshot_sha256": "F31FFE89DE5087977E7CB6FBD81EC876602871F30C8EA815C0DF862CA40F65BF",
          "retrieved_at": "2026-07-30T16:26:00.266Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-13.3",
      "safeguard_id": "13.3",
      "control": 13,
      "title": {
        "en": "Deploy a Network Intrusion Detection Solution",
        "zh": "网络入侵检测"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The coverage population is risk-relevant boundaries and internal chokepoints across Internet, cloud, data center, campus, wireless, remote, partner and sensitive east-west paths. A sensor sees only traffic delivered to it; encrypted payload, overlay and same-host traffic may remain opaque.",
          "zh": "覆盖互联网、云、数据中心、园区、无线、远程、伙伴和敏感东西向的风险边界/关键点。Sensor 只能看实际送达的流量，加密载荷、Overlay 和同主机流量可能不可见。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Place NIDS or cloud-native equivalents from architecture and threat paths, engineer taps/mirrors/flow, manage signatures and analytics, decrypt only where lawful/needed, centralize alerts and monitor packet loss, asymmetry, clock and sensor health.",
          "zh": "按架构与威胁路径布置 NIDS/云等效物，正确设计 TAP/Mirror/Flow，管理签名和分析；仅在合法必要时解密，集中告警，并监测丢包、非对称、时钟和 Sensor 健康。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "CAS counts covered boundaries without verifying traffic reaches a sensor. Cloud mirrors, NAT, QUIC, service meshes and asymmetric routing create gaps. Detection is not prevention; privacy and performance can constrain decryption, so endpoint/application telemetry must close named blind spots.",
          "zh": "CAS 数边界覆盖却不证流量进入 Sensor。云 Mirror、NAT、QUIC、服务网格和非对称路由造盲区。检测不等于阻断；隐私/性能限制解密时，终端/应用遥测补具名缺口。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Replay safe protocol and detection fixtures from both directions at representative boundaries; verify packet visibility, decoding, alert and source/destination attribution. Test high-volume loss, encryption and failover routes; measure observable traffic paths and health, not merely boundary count.",
          "zh": "从双向在代表边界回放安全协议/检测 Fixture，验证流量可见、解码、告警与源目的归因；测试高流量丢失、加密和故障转移。指标看可观测流量路径与健康，不只边界数。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "13.3",
          "control": 13,
          "title": {
            "en": "Deploy a Network Intrusion Detection Solution",
            "zh": "网络入侵检测"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls13/",
          "snapshot_sha256": "F31FFE89DE5087977E7CB6FBD81EC876602871F30C8EA815C0DF862CA40F65BF",
          "retrieved_at": "2026-07-30T16:26:00.266Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-13.4",
      "safeguard_id": "13.4",
      "control": 13,
      "title": {
        "en": "Perform Traffic Filtering Between Network Segments",
        "zh": "网段间流量过滤"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Scope every route between trust segments, accounts/projects, clusters, management planes and partner/remote zones, including IPv4/IPv6, overlay, transit and failover paths. Filtering policy derives from approved service/data flows and identity, not a vague rule that a firewall exists.",
          "zh": "覆盖信任区、云账号/项目、集群、管理面、伙伴/远程之间的全部路由，含 IPv4/IPv6、Overlay、Transit 和 Failover。策略来自批准服务/数据流和身份，不是“有防火墙”。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Default-deny new inter-zone communication, permit narrow source/destination/service/identity flows, manage through reviewed policy-as-code, expire temporary rules and remove shadowed/unused access. Apply controls at the enforcement point closest to the trust boundary and log decisions.",
          "zh": "新跨区默认拒绝，只允许窄源、目的、服务/身份；通过评审策略即代码管理，临时规则到期，清除 Shadow/未用权限，在离信任边界最近的强制点执行并记日志。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A “properly configured” device can still enforce an over-broad design. Shared services, DNS, identity, monitoring and backups need controlled cross-zone paths. Flat legacy/OT networks require staged segmentation and compensating monitoring; emergency rules are time-limited and reviewed after use.",
          "zh": "设备“配置正确”仍可能执行过宽设计。DNS、身份、监测、备份等共享服务需受控跨区。旧/OT 平网要分期隔离和补偿监测；应急规则限时并事后审阅。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Test every representative allowed flow and denied lateral/management path, including alternate route, IPv6 and failover. Compute effective reachability and inspect permissive, shadowed and expired rules; map each permit to owner, purpose and last use.",
          "zh": "代表性测试所有允许业务流和拒绝横向/管理路径，包括备用路由、IPv6、故障转移；计算有效可达，查宽泛、遮蔽、过期规则，每条 Permit 追责任、用途和最后使用。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "13.4",
          "control": 13,
          "title": {
            "en": "Perform Traffic Filtering Between Network Segments",
            "zh": "网段间流量过滤"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls13/",
          "snapshot_sha256": "F31FFE89DE5087977E7CB6FBD81EC876602871F30C8EA815C0DF862CA40F65BF",
          "retrieved_at": "2026-07-30T16:26:00.266Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-13.5",
      "safeguard_id": "13.5",
      "control": 13,
      "title": {
        "en": "Manage Access Control for Remote Assets",
        "zh": "远程资产访问准入"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The population is remote assets and sessions accessing enterprise resources, managed or otherwise. Access level depends on current anti-malware/EDR health, secure-configuration compliance, OS/application currency and identity; a one-time compliant enrolment cannot authorize indefinitely.",
          "zh": "总体是所有远程接入企业资源的资产/会话，无论受管与否；访问量依据反恶意软件/EDR、基线合规、OS/应用更新和身份的当前状态，一次注册合规不能永久授权。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Use NAC/ZTNA/VPN/conditional access to evaluate device identity and fresh posture, grant least resource scope, quarantine or limit noncompliant devices and provide remediation. Sign and protect posture signals, define fail behavior and separate employee, BYOD, vendor and admin policies.",
          "zh": "用 NAC/ZTNA/VPN/条件访问评估设备身份与新鲜姿态，按资源最小授权，对不合规资产隔离/限制并提供修复；签名保护姿态信号，定义故障行为，区分员工、BYOD、厂商和管理员。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "CAS counts authorization systems configured with policies but does not test whether posture is true or current. Client-reported health can be spoofed. BYOD may receive browser/VDI access under an untrusted-device posture; outages need a bounded fail mode, and critical patch exceptions must reduce access.",
          "zh": "CAS 只数授权系统配置了政策，不验证姿态真假/新鲜度；客户端自报可伪造。BYOD 可仅给浏览器/VDI 而非设备信任；服务故障需有界模式，高危补丁例外必须降权限。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Connect compliant, stale-patch, disabled-protection, tampered/unmanaged and offline-status devices; verify decisions, limited remediation path, logs and state change during an existing session. Measure successful recent posture evaluations and granted scope against remote sessions/assets.",
          "zh": "让合规、缺补丁、停防护、被篡改/未管和状态离线设备接入，验证决定、有限修复通道、日志与会话中状态变化。以远程资产/会话为分母看近期真实姿态评估与授权范围。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "13.5",
          "control": 13,
          "title": {
            "en": "Manage Access Control for Remote Assets",
            "zh": "远程资产访问准入"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls13/",
          "snapshot_sha256": "F31FFE89DE5087977E7CB6FBD81EC876602871F30C8EA815C0DF862CA40F65BF",
          "retrieved_at": "2026-07-30T16:26:00.266Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-13.6",
      "safeguard_id": "13.6",
      "control": 13,
      "title": {
        "en": "Collect Network Traffic Flow Logs",
        "zh": "网络流量与流日志"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Collect flow records and/or packet data from network devices at boundaries and internal paths needed for detection and investigation, with direction, endpoints, ports/protocol, time, bytes/packets, action and tenant/segment context. Sampling and NAT reduce what can be inferred.",
          "zh": "采集用于检测/调查的边界和内部路径流记录或包，包含方向、端点、端口/协议、时间、字节/包、动作和租户/网段上下文；采样与 NAT 会限制推断。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Enable NetFlow/IPFIX/VPC flow or packet capture at selected points, synchronize time, centralize securely, document sampling and retention, map translated/overlay identities and monitor exporter/collector loss. Choose packets only where benefit, privacy and capacity justify them.",
          "zh": "在选定点启用 NetFlow/IPFIX/VPC Flow 或 Packet，统一时钟，安全集中，记录采样/保留，映射 NAT/Overlay 身份并监测出口/收集丢失；只有收益、隐私、容量合理时才抓包。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "CAS focuses on boundary devices, which can omit lateral movement. Flow logs do not show application intent or full payload, and packet capture can expose sensitive content. Sampling misses short/low-volume activity; cloud provider filters and costs need tenant-specific validation.",
          "zh": "CAS 聚焦边界设备，可能漏横向。Flow 不给应用意图/完整载荷，抓包又会暴露敏感内容。采样漏短/低量活动，云服务商过滤与成本须租户实测。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Generate allowed, denied, east-west, IPv6 and failover flows and trace expected fields through export and analytics. Compare interface counters with exported/accepted records during a burst; verify NAT mapping and sensor health alerts.",
          "zh": "生成允许、拒绝、东西向、IPv6 和故障转移流，追踪全部字段；突发时比较接口计数与导出/接收记录，验证 NAT 映射和 Sensor 健康告警。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "13.6",
          "control": 13,
          "title": {
            "en": "Collect Network Traffic Flow Logs",
            "zh": "网络流量与流日志"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls13/",
          "snapshot_sha256": "F31FFE89DE5087977E7CB6FBD81EC876602871F30C8EA815C0DF862CA40F65BF",
          "retrieved_at": "2026-07-30T16:26:00.266Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-13.7",
      "safeguard_id": "13.7",
      "control": 13,
      "title": {
        "en": "Deploy a Host-Based Intrusion Prevention Solution",
        "zh": "主机入侵防御"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Eligible assets support a host control capable of blocking or containing malicious behavior, not merely alerting. Define protected techniques, enforcement mode and workloads; EDR installed in detect-only mode belongs to 13.2 until prevention is active.",
          "zh": "合格资产要有能阻断/遏制恶意行为的主机控制，而非只告警；明确保护技术、强制模式和工作负载。EDR 只检测时属于 13.2，开启防护后才属本项。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Enable risk-appropriate prevention for exploit, behavior, file/integrity and network actions, protect policy and sensor, stage tuning with benign controls and connect isolation/rollback to incident response. Limit every exception to the exact role; global disablement fails scope control.",
          "zh": "按风险启用 Exploit、行为、文件/完整性和网络防护，保护策略/Sensor，从观察到强制逐步调优，并连接隔离/回滚；用角色级例外，不可全局关闭。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Prevention can disrupt critical systems and attackers can evade or kill sensors. OT and high-availability servers may use detect/respond or application allowlisting as an explicit alternative. CAS only checks installation, so it cannot distinguish prevention, detection, disabled policy or failed agent.",
          "zh": "防护会干扰关键系统，攻击者也会规避/终止 Sensor。OT/高可用服务器可在明确边界下改为检测响应或 Allowlisting。CAS 只查安装，分不出防护、检测、禁用和故障。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Run safe simulations that should block and similar legitimate administrative tasks that should pass; verify prevention, process/system outcome, telemetry and recovery. Tamper with the sensor and exhaust resources in test scope; measure healthy enforcing eligible assets and exception age.",
          "zh": "运行应被阻断的安全模拟和应通过的相似正常运维，验证阻断、系统结果、遥测和恢复；在测试范围篡改 Sensor、耗资源，指标看健康强制资产和例外年龄。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "13.7",
          "control": 13,
          "title": {
            "en": "Deploy a Host-Based Intrusion Prevention Solution",
            "zh": "主机入侵防御"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls13/",
          "snapshot_sha256": "F31FFE89DE5087977E7CB6FBD81EC876602871F30C8EA815C0DF862CA40F65BF",
          "retrieved_at": "2026-07-30T16:26:00.266Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-13.8",
      "safeguard_id": "13.8",
      "control": 13,
      "title": {
        "en": "Deploy a Network Intrusion Prevention Solutions",
        "zh": "网络入侵防御"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Scope boundaries and paths where inline or provider controls can safely block known exploit, protocol or policy violations, including cloud gateways and internal high-value zones. Placement must identify failure behavior, encrypted visibility and availability consequence.",
          "zh": "覆盖适合 Inline/服务商控制安全阻断已知利用、协议或政策违规的边界/路径，含云网关和内部高价值区；位置必须声明故障模式、加密可见性和可用后果。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Deploy NIPS/NGFW/cloud controls in staged detect-to-block modes, keep signatures/engines current, tune with local traffic, use HA and rollback, and route blocks to investigation. Limit signatures to protocols and paths they can interpret reliably.",
          "zh": "用 Detect-to-block 分阶段部署 NIPS/NGFW/云控制，保持签名/引擎当前，按本地流量调优，HA/回滚，并把阻断送调查；只对能可靠解析的协议/路径启用规则。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Coverage count establishes inventory placement only; packet traversal and rule enforcement require path-replay evidence. TLS/QUIC, evasion, fragmentation and cloud routing may obscure payload. Inline prevention on safety/latency-critical paths needs careful failure design; false-positive exceptions are exact and expiring.",
          "zh": "覆盖数只建立设备与路径清单；报文确实经过设备且规则执行，需要路径回放证据。TLS/QUIC、规避、分片和云路由会遮蔽载荷。安全或时延关键路径上的在线阻断需要审慎设计故障模式；误报例外必须精确且会到期。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Replay safe blocking fixtures and benign near-matches through primary/failover/IPv6 paths; verify drop/reset, service continuity, logs and analyst response. Simulate device/service failure and overload to confirm declared fail-open/closed behavior.",
          "zh": "在主、备、IPv6 路径回放安全阻断 Fixture 和相似正常流，验证 Drop/Reset、业务连续和告警；模拟设备/服务故障与过载，确认 Fail-open/closed 符合声明。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "13.8",
          "control": 13,
          "title": {
            "en": "Deploy a Network Intrusion Prevention Solutions",
            "zh": "网络入侵防御"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls13/",
          "snapshot_sha256": "F31FFE89DE5087977E7CB6FBD81EC876602871F30C8EA815C0DF862CA40F65BF",
          "retrieved_at": "2026-07-30T16:26:00.266Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-13.9",
      "safeguard_id": "13.9",
      "control": 13,
      "title": {
        "en": "Deploy Port-Level Access Control",
        "zh": "端口级网络准入"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Port-level access control covers wired, wireless and equivalent access edges before ordinary network reachability, using 802.1X, certificates or comparable user/device authentication. Include switch ports, APs, docks, virtual access and fallback networks; unused physical ports remain part of scope.",
          "zh": "在普通网络可达前，用 802.1X、证书或等效用户/设备认证控制有线、无线及等效接入边缘；覆盖交换端口、AP、Dock、虚拟接入、回退网，闲置物理端口也在范围。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Deploy resilient supplicant, authenticator and AAA/PKI, assign dynamic least-privilege segments/roles, disable unused ports and tightly govern MAB or guest fallback. Protect certificate enrollment/revocation and synchronize identity/device inventory with policy.",
          "zh": "部署有弹性的 Supplicant、Authenticator、AAA/PKI，动态分配最小区/角色，关闭闲置端口，严格治理 MAB/Guest 回退；保护证书注册/撤销，并同步身份/设备台账。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "MAB authenticates an identifier that can be copied and is a compatibility exception. CAS's alternative client-certificate metric uses all network infrastructure assets, not access endpoints, so its denominator needs rebuilding. Printers, phones, IoT/OT and emergency access require narrow roles, monitoring and lifecycle.",
          "zh": "MAB 只认易复制标识，是兼容例外。CAS 替代证书指标用全部网络设备作分母，而非接入端，需重建。打印机、电话、IoT/OT 与应急接入需窄角色、监测和生命周期。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Connect authorized, revoked, unknown, non-supplicant and spoofed-MAC devices to representative ports/APs; verify placement, denial/quarantine, accounting and failover. Test certificate expiry, AAA outage and port reconfiguration; measure actual edge ports/clients under enforcing policy.",
          "zh": "在代表端口/AP 接入批准、已撤销、未知、不支持 Supplicant 和伪造 MAC 的设备，验证放置、拒绝/隔离、Accounting 和 Failover；测试证书到期、AAA 故障与端口改配，以实际边缘强制为指标。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "13.9",
          "control": 13,
          "title": {
            "en": "Deploy Port-Level Access Control",
            "zh": "端口级网络准入"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls13/",
          "snapshot_sha256": "F31FFE89DE5087977E7CB6FBD81EC876602871F30C8EA815C0DF862CA40F65BF",
          "retrieved_at": "2026-07-30T16:26:00.266Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-13.10",
      "safeguard_id": "13.10",
      "control": 13,
      "title": {
        "en": "Perform Application Layer Filtering",
        "zh": "应用层过滤"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The population is application protocols and requests crossing exposed or sensitive boundaries, including web/API, DNS, email and selected industrial/business protocols. Coverage must state direction, applications, routes, methods and whether the control understands decrypted content or only metadata.",
          "zh": "范围是跨外部或敏感边界的 Web/API、DNS、邮件和选定工业/业务应用协议；声明方向、应用、路由、方法，以及能否解密内容还是只看元数据。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Use reverse/forward proxies, WAF/API gateways, application firewalls or cloud services with positive schemas, authentication context, rate limits and protocol validation. Version policy with applications, observe before blocking, protect bypass/origin paths and monitor engine health.",
          "zh": "用正向/反向代理、WAF/API Gateway、应用防火墙或云服务执行正 Schema、认证上下文、限速和协议验证；策略随应用版本化，先观察后阻断，保护 Origin/旁路并监测引擎。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "CAS publishes M2 / M1 over network infrastructure assets. That ratio does not identify application routes, APIs, methods, protocol versions, direct-origin paths, or whether filtering inspects decrypted content. TLS, custom protocols, business-logic abuse, and client-side actions exceed generic filtering; exceptions need an owner and expiry.",
          "zh": "CAS 发布了以网络基础设施资产为对象的 M2 / M1。该比率没有识别应用路由、API、方法、协议版本、Origin 直连路径，也没有说明过滤能否检查解密后的内容。TLS、自定义协议、业务逻辑和客户端行为超出通用过滤；例外需有责任人和到期时间。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Send valid, malformed, oversized, unauthorized-method, encoded and direct-origin requests plus legitimate edge cases; verify intended permit/block, application health and logs. Test alternate ports/protocol versions and provider bypass; measure protected application paths, not network infrastructure assets.",
          "zh": "发送有效、畸形、超大、未授权方法、编码和直连 Origin 请求及正常边界样本，验证 Permit/Block、应用健康和日志；测试替代端口/协议版本和服务商旁路，按受保护应用路径计覆盖。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "13.10",
          "control": 13,
          "title": {
            "en": "Perform Application Layer Filtering",
            "zh": "应用层过滤"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls13/",
          "snapshot_sha256": "F31FFE89DE5087977E7CB6FBD81EC876602871F30C8EA815C0DF862CA40F65BF",
          "retrieved_at": "2026-07-30T16:26:00.266Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-035"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-13.11",
      "safeguard_id": "13.11",
      "control": 13,
      "title": {
        "en": "Tune Security Event Alerting Thresholds",
        "zh": "告警阈值调优"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Network",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Tuning applies to rules, thresholds, baselines, suppressions, correlations and severity/routing across centralized security alerting, at least monthly. The goal is improved signal and coverage with controlled change, not simply lowering volume.",
          "zh": "至少每月调优集中告警里的规则、阈值、基线、抑制、关联和严重度/路由；目标是可控地提升信号和覆盖，不是单纯降量。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Use adjudicated cases, threat/architecture changes, source health and analyst feedback to propose versioned changes; test against historical and synthetic positive/negative controls, peer-review, deploy gradually and retain rollback. Expire suppressions and monitor detection drift.",
          "zh": "根据已裁决案件、威胁/架构变化、源健康和分析反馈提出版本化变更；用历史与合成正负控测试，同行评审、渐进发布、可回滚，抑制到期，并监测检测漂移。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "CAS tests only the date of last tuning, so arbitrary monthly edits can pass while degrading coverage. Low-frequency detections need longer evaluation windows; seasonal business shifts and data-source changes alter baselines. Automated/AI tuning cannot silently publish policy without provenance, constraints and rollback.",
          "zh": "CAS 只看上次调优日期，任意月改也可过且可能劣化。低频检测需更长窗口，季节业务与源变化会改基线。自动/AI 调优必须有来源、约束与回滚，不能静默发布。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Replay known true/false cases before and after each change and compare precision, recall on the controlled set, latency, volume and missed high-consequence scenarios. Verify one canary alert continues to fire and audit monthly decisions even when no threshold changes.",
          "zh": "变更前后回放已知真/假样本，比较受控集上的精度/召回、时延、量和漏高后果场景；验证一个 Canary 始终触发，即使本月无需改阈值也记录评估决定。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "13.11",
          "control": 13,
          "title": {
            "en": "Tune Security Event Alerting Thresholds",
            "zh": "告警阈值调优"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls13/",
          "snapshot_sha256": "F31FFE89DE5087977E7CB6FBD81EC876602871F30C8EA815C0DF862CA40F65BF",
          "retrieved_at": "2026-07-30T16:26:00.266Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-14.1",
      "safeguard_id": "14.1",
      "control": 14,
      "title": {
        "en": "Establish and Maintain a Security Awareness Program",
        "zh": "安全意识计划"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The workforce population includes employees, contractors, temporary staff, interns, executives and other people using enterprise assets or data, with language, accessibility, role, location and start-date considerations. The program is an operating system for behavior, reporting and reinforcement—not an annual video.",
          "zh": "总体包括员工、承包商、临时工、实习、管理层及其他使用企业资产/数据的人，并考虑语言、无障碍、角色、地点和入职时间。它是行为、报告与强化的运营体系，不是一年一段视频。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Train at hire and at least annually, update content annually and after meaningful threat/business change, provide accessible/localized channels, safe reporting and role-based reinforcement. HR owns population/timing, security owns risk/content and managers close noncompletion without coercive or deceptive exercises.",
          "zh": "入职及至少每年培训，内容每年和威胁/业务重大变化后更新，提供可访问、本地化、无障碍与安全报告；HR 管总体/时间，安全管风险/内容，经理闭环未完成，不用羞辱性演练。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Completion records attendance; separate tests establish understanding and behavior. Workers without accounts still need relevant physical/data training. Phishing simulations must avoid humiliation and measure/report coaching; high click rates alone can reflect exercise design. The repeated CAS module formulas use population/document booleans as denominators and are not reliable.",
          "zh": "完成不证明理解或行为。无账号员工也需相关物理/数据培训。钓鱼演练应无羞辱并用于报告/辅导；高点击也可能来自演练设计。CAS 重复模块公式用总体/文档布尔作分母，不可靠。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Reconcile authoritative workforce rosters to completion, test new-hire timing and content comprehension with scenario decisions, then measure reporting, repeat-risk and intervention outcomes over time. Sample accommodations and contractor/provider populations; inspect overdue and unreachable people separately.",
          "zh": "用权威人员名册对账完成，测试入职时点和场景理解，再长期看报告、重复风险和干预结果；抽查承包商与无障碍人群，单列逾期/无法触达。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "14.1",
          "control": 14,
          "title": {
            "en": "Establish and Maintain a Security Awareness Program",
            "zh": "安全意识计划"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls14/",
          "snapshot_sha256": "B3AB523467DE4AACC7A8227C3CC2056EE99F14A3A254D1769D5EAC5C90C30305",
          "retrieved_at": "2026-07-30T16:26:01.267Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-14.2",
      "safeguard_id": "14.2",
      "control": 14,
      "title": {
        "en": "Train Workforce Members to Recognize Social Engineering Attacks",
        "zh": "社会工程识别"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Training covers phishing, business email compromise, voice/video impersonation, QR codes, messaging, support scams, tailgating and AI-enabled pretexting across work and personal channels used for business. Recognition must connect to an immediate safe reporting path.",
          "zh": "覆盖钓鱼、BEC、语音/视频冒充、二维码、即时消息、支持诈骗、尾随和 AI 预设，横跨工作与用于工作的个人渠道；识别必须连接立即可用的报告路径。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Teach observable cues, independent verification of money/credential/data requests, no-blame reporting and what to do after interaction. Tailor examples to real roles and languages, reinforce near current campaigns, and ensure help desk and finance processes withstand impersonation so technical and dual-authorization controls carry their share of defense.",
          "zh": "讲可观察线索、独立核验资金/凭据/数据请求、无责报告和事后动作；按真实角色/语言给例子，结合当前活动强化，同时让 Helpdesk/财务流程能抵抗冒充，不能把责任全推给用户。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Highly convincing attacks may lack visible cues, so technical controls and dual authorization remain necessary. A simulated failure is training data, not misconduct. Executives, support, finance and vendors face different pretexts; personal devices and out-of-band calls need privacy-aware guidance.",
          "zh": "高度逼真攻击可能没有明显线索，所以仍需技术与双人授权。模拟失误是培训数据，不是处分证据。高管、支持、财务和厂商遇到不同预设；个人设备与带外电话要隐私化指导。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Use varied, ethical simulations and tabletop scenarios with positive and ambiguous controls; measure timely reporting, correct verification and response, not clicks alone. Confirm reports preserve headers/context and reach an operating triage queue; coach recurrent gaps.",
          "zh": "用多样、合乎伦理的模拟和桌演，带正常/模糊对照；衡量及时报告、正确核验和响应，不只点击。确认报告保留 Header/上下文并进入有人运营的队列，反复缺口要辅导。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "14.2",
          "control": 14,
          "title": {
            "en": "Train Workforce Members to Recognize Social Engineering Attacks",
            "zh": "社会工程识别"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls14/",
          "snapshot_sha256": "B3AB523467DE4AACC7A8227C3CC2056EE99F14A3A254D1769D5EAC5C90C30305",
          "retrieved_at": "2026-07-30T16:26:01.267Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-036"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-14.3",
      "safeguard_id": "14.3",
      "control": 14,
      "title": {
        "en": "Train Workforce Members on Authentication Best Practices",
        "zh": "认证最佳实践"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Scope passwords, MFA, passkeys, recovery, device prompts, password managers, service-desk identity proofing and credential handling for every workforce account type. Users need to know which requests the enterprise will never make and how to report unexpected prompts.",
          "zh": "覆盖所有人员账户的口令、MFA、Passkey、恢复、设备 Prompt、密码管理器与 Helpdesk 核验。员工应清楚企业绝不会索要什么、意外 Prompt 如何报告。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Teach unique managed passwords, phishing-resistant MFA, prompt verification, no credential sharing, secure recovery and immediate reporting. Pair messages with usable approved tools and remove policies that train workarounds; refresh when authentication methods or attacks change.",
          "zh": "讲唯一受管口令、抗钓鱼 MFA、Prompt 核验、不共享凭据、安全恢复和立即报告；同时提供好用的批准工具，移除会逼人绕过的政策，认证方法/攻击变化时刷新。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Training cannot fix legacy shared accounts, MFA fatigue or a weak reset process. Accessibility and device availability affect factor choice. Service/workload credentials are an engineering responsibility; telling users to “use strong passwords” without tools and enforcement is a program failure.",
          "zh": "培训修不好共享旧账户、MFA Fatigue 和弱重置。无障碍/设备可用性影响因素选择。服务/工作负载凭据由工程负责；只说“强口令”却无工具和强制，是计划失败。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Run scenario questions and safe unexpected-prompt/recovery exercises, then measure correct rejection/reporting and password-manager/MFA adoption without collecting secrets. Test whether support follows the same identity-proofing rules taught to users.",
          "zh": "用场景和安全的意外 Prompt/恢复演练，测拒绝/报告与密码管理器/MFA 采用，绝不收集秘密；检查 Support 是否也执行教给用户的身份核验。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "14.3",
          "control": 14,
          "title": {
            "en": "Train Workforce Members on Authentication Best Practices",
            "zh": "认证最佳实践"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls14/",
          "snapshot_sha256": "B3AB523467DE4AACC7A8227C3CC2056EE99F14A3A254D1769D5EAC5C90C30305",
          "retrieved_at": "2026-07-30T16:26:01.267Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-036"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-14.4",
      "safeguard_id": "14.4",
      "control": 14,
      "title": {
        "en": "Train Workforce on Data Handling Best Practices",
        "zh": "数据处理最佳实践"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Training follows the enterprise's actual classifications and workflows for collection, storage, access, sharing, transfer, retention and disposal across email, collaboration, cloud, removable media, printing, remote work and AI tools. Generic “protect confidential data” language is not actionable.",
          "zh": "内容跟随真实数据分类和收集、存储、访问、共享、传输、保留、销毁流程，覆盖邮件、协作、云、介质、打印、远程和 AI；泛泛“保护机密”不可行动。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Give role-specific examples, approved destinations and transfer methods, labeling, recipient verification, minimal access, clean desk/media and incident/reporting steps. Align UI labels and tools with the policy so the safe path is the easy path; update when data uses/providers change.",
          "zh": "按角色给批准目的与方法、标签、收件核验、最小访问、桌面/介质和事件步骤；UI/工具与政策一致，让安全路径最容易，数据用途/服务商变化时更新。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "People cannot determine sensitivity when inventories/labels are absent. Aggregation and derived data can increase risk; encrypted sharing still needs recipient authorization. Training does not legitimize prohibited processing or shift provider/data-owner obligations to users.",
          "zh": "资产/标签缺失时，人无法判断敏感度。聚合/派生可升风险；加密分享仍需收件授权。培训不能把被禁止处理变合法，也不能把数据所有者/服务商义务转嫁给用户。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Use realistic decisions such as external sharing, misaddressed mail, public link, AI prompt and disposal; measure correct handling and reporting, then inspect whether approved tools support the answer. Analyze real near misses to improve process without exposing individuals.",
          "zh": "用外部分享、错发邮件、公开链接、AI Prompt 和销毁等真实决策，测正确处理/报告，并检查批准工具是否支持答案；用真实 Near miss 改流程但不暴露个人。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "14.4",
          "control": 14,
          "title": {
            "en": "Train Workforce on Data Handling Best Practices",
            "zh": "数据处理最佳实践"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls14/",
          "snapshot_sha256": "B3AB523467DE4AACC7A8227C3CC2056EE99F14A3A254D1769D5EAC5C90C30305",
          "retrieved_at": "2026-07-30T16:26:01.267Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-036"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-14.5",
      "safeguard_id": "14.5",
      "control": 14,
      "title": {
        "en": "Train Workforce Members on Causes of Unintentional Data Exposure",
        "zh": "非故意数据暴露"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Cover common accidental causes: wrong recipient/autocomplete, public links, excessive permissions, lost devices, unsafe printing/disposal, screenshots, misconfigured cloud storage, code/log secrets and posting data to consumer/AI services. Emphasize immediate containment and reporting.",
          "zh": "覆盖错收件/自动补全、公开链接、过宽权限、丢设备、不安全打印/销毁、截图、云误配、代码/日志秘密和向消费/AI 服务发数据等意外暴露，强调立即遏制和报告。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Teach pause-and-verify steps, approved sharing defaults, recipient/permission checks, data minimization and rapid recall/revocation/reporting. Reinforce with safer product defaults, DLP and access controls; adapt examples to developers, support, sales, researchers and remote workers.",
          "zh": "教停一下再核验、批准分享默认、收件/权限检查、数据最小化和快速 Recall/Revoke/Report，并用更安全产品默认、DLP、访问控制强化；按开发、支持、销售、研究、远程角色调整。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Some “user errors” are predictable UI or process design failures. A report should not trigger automatic punishment, or concealment increases. Encrypted files can still go to the wrong person; public data may still carry integrity or contractual limits.",
          "zh": "许多“用户错误”是可预测 UI/流程缺陷。报告若必然受罚，会促使隐瞒。加密文件仍会发错人；公开数据也可能有完整性/合同限制。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Run scenario exercises and controlled sharing canaries, verify participants can identify exposure, revoke access and report with useful context. Track time from real exposure to report, recovery outcome and recurring system causes; these outcomes drive system redesign and avoid personal blame.",
          "zh": "用场景和受控分享 Canary，验证识别、撤权和带上下文报告；跟踪真实暴露到报告的时间、恢复结果与重复系统根因，不能归罪个人。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "14.5",
          "control": 14,
          "title": {
            "en": "Train Workforce Members on Causes of Unintentional Data Exposure",
            "zh": "非故意数据暴露"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls14/",
          "snapshot_sha256": "B3AB523467DE4AACC7A8227C3CC2056EE99F14A3A254D1769D5EAC5C90C30305",
          "retrieved_at": "2026-07-30T16:26:01.267Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-036"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-14.6",
      "safeguard_id": "14.6",
      "control": 14,
      "title": {
        "en": "Train Workforce Members on Recognizing and Reporting Security Incidents",
        "zh": "事件识别与报告"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The workforce should recognize observable security events relevant to their role—unexpected MFA, malware warning, lost asset, account change, suspicious data access or system behavior—and know one simple, available reporting path plus urgent alternatives.",
          "zh": "员工应能识别与其角色相关的可观察事件，如意外 MFA、恶意软件告警、资产丢失、账户变化、可疑数据访问/系统行为，并知道一个简单常用的报告入口与紧急替代。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Teach what to report, how quickly, what evidence to preserve, what actions to avoid and where to report; provide 24/7 or risk-appropriate channels, acknowledgement and feedback. Route reports into the incident process and protect reporters from retaliation.",
          "zh": "讲报告什么、多快、保留哪些证据、避免什么动作和去哪里；提供 24/7 或匹配风险的渠道、确认和反馈，接入事件流程并保护报告者。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Training is useless if the queue is unstaffed or requires an inaccessible account. People are not expected to classify incidents perfectly; the SOC owns triage. Privacy, labor and safety considerations affect evidence handling; emergency physical danger follows local emergency channels.",
          "zh": "若队列无人值守或必须用已锁账号，培训无用。员工不必精准定级，SOC 负责。隐私、劳动和安全会影响证据处理；现实人身紧急情况走本地应急渠道。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Submit test reports through email, portal, phone and after-hours paths; verify receipt, triage, correlation, escalation and feedback within SLO. Scenario-test preservation and immediate containment choices, and measure useful report latency and quality; raw volume is a secondary signal.",
          "zh": "经邮件、Portal、电话和下班渠道提交测试报告，验证接收、分诊、关联、升级和反馈；场景测试保全/遏制选择，以有用报告的时延/质量为指标，不追求数量。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "14.6",
          "control": 14,
          "title": {
            "en": "Train Workforce Members on Recognizing and Reporting Security Incidents",
            "zh": "事件识别与报告"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls14/",
          "snapshot_sha256": "B3AB523467DE4AACC7A8227C3CC2056EE99F14A3A254D1769D5EAC5C90C30305",
          "retrieved_at": "2026-07-30T16:26:01.267Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-036"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-14.7",
      "safeguard_id": "14.7",
      "control": 14,
      "title": {
        "en": "Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates",
        "zh": "缺失安全更新识别与报告"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The audience covers users of managed and unmanaged enterprise devices who may see update prompts, unsupported warnings, failed restarts or application version problems. Training must identify the legitimate enterprise update experience and reporting channel, including phishing-like fake updates.",
          "zh": "面向可能看到更新 Prompt、不支持警告、重启失败或版本问题的受管/非受管设备用户；培训要说明真实企业更新体验和 IT 报告入口，也要防“假更新”钓鱼。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Teach users not to bypass or indefinitely postpone updates, to keep devices powered/connected during maintenance, distinguish approved prompts and report missing/failed updates to IT. Pair with automatic patching, clear notifications and accessible support.",
          "zh": "教用户不绕过或无限延期，维护窗保持开机/联网，识别批准 Prompt，并向 IT 报告缺失/失败；同时自动补丁、清晰通知和支持必须可用。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Users cannot determine backend, firmware or silent application currency; engineering owns measurement. The current Navigator omits the explicit “notify IT” sentence that appears in the v8.1 core guide/CAS, illustrating why source snapshots must be named. Training must not encourage installing from arbitrary pop-ups.",
          "zh": "用户无法判断后台、固件和静默应用版本，工程负责度量。Navigator 漏掉核心指南/CAS 的“通知 IT”句，说明必须固定来源快照。培训不能鼓励从任意弹窗安装。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Present legitimate, failed, overdue and fake update scenarios and verify correct action/reporting; on a test device, confirm a report reaches asset/patch owners and closes after remediation. Track recurring user-visible failures back to automation and communication.",
          "zh": "给出正常、失败、逾期和假更新场景，验证动作/报告；在测试设备确认报告能到资产/补丁负责人并修复关闭，把重复可见故障回馈自动化/沟通。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "14.7",
          "control": 14,
          "title": {
            "en": "Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates",
            "zh": "缺失安全更新识别与报告"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls14/",
          "snapshot_sha256": "B3AB523467DE4AACC7A8227C3CC2056EE99F14A3A254D1769D5EAC5C90C30305",
          "retrieved_at": "2026-07-30T16:26:01.267Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-036"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-14.8",
      "safeguard_id": "14.8",
      "control": 14,
      "title": {
        "en": "Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks",
        "zh": "不安全网络风险"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Cover home, public Wi-Fi, guest, cellular, hotel/captive portal, personal hotspot and other networks used for enterprise activity, including metadata exposure, rogue access points, insecure routers and unsafe sharing. Guidance must match the actual VPN/ZTNA and device controls.",
          "zh": "覆盖家庭、公共 Wi-Fi、Guest、蜂窝、酒店/Captive Portal、热点等用于企业活动的网络，包括元数据、Rogue AP、弱家用路由和不安全共享；指导要匹配真实 VPN/ZTNA/设备控制。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Teach network selection, home-router administration/update/encryption, avoiding shared credentials, use of enterprise protected access, disabling unnecessary sharing and what to do when only an untrusted network is available. Provide managed tools and support; expert router configuration is not a user prerequisite.",
          "zh": "教网络选择、家用路由管理/更新/加密、不共享凭据、使用企业保护接入、关不必要共享和无可信网时怎么办；提供受管工具/支持，不能要求人人成为路由专家。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Modern encrypted applications reduce but do not erase network risk; users should not infer a network is safe from a padlock. Captive portals can interrupt VPN. Workers cannot secure landlord/hotel infrastructure, so device/application architecture must contain risk and offer cellular/VDI alternatives.",
          "zh": "现代加密应用降低但未消除网络风险，不能把锁图标理解为网络安全。Captive Portal 可打断 VPN。员工无法加固房东/酒店网络，架构应靠设备/应用包含风险并提供蜂窝/VDI 替代。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Scenario-test a fake/ambiguous hotspot and remote-access failure; verify users choose the protected path and report issues. Confirm managed devices automatically enforce firewall, DNS and VPN/identity controls on public profiles; sample home guidance for feasibility and accessibility.",
          "zh": "场景测试假/模糊热点与远程接入故障，验证选受保护路径和报告；确认受管设备在公共 Profile 自动强制防火墙、DNS、VPN/身份，并抽样家用指南可行/无障碍。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "14.8",
          "control": 14,
          "title": {
            "en": "Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks",
            "zh": "不安全网络风险"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls14/",
          "snapshot_sha256": "B3AB523467DE4AACC7A8227C3CC2056EE99F14A3A254D1769D5EAC5C90C30305",
          "retrieved_at": "2026-07-30T16:26:01.267Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-036"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-14.9",
      "safeguard_id": "14.9",
      "control": 14,
      "title": {
        "en": "Conduct Role-Specific Security Awareness and Skills Training",
        "zh": "角色化安全技能"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The population and curriculum derive from real duties and privileges: administrators, developers, help desk, SOC, finance, HR, executives, data owners, procurement, legal, facilities and high-risk operators. Awareness explains choices; skills training must enable correct performance in the tools and processes used.",
          "zh": "总体和课程来自真实职责与权限：管理员、开发、Helpdesk、SOC、财务、HR、高管、数据所有者、采购、法务、设施和高风险操作。意识讲选择，技能培训必须让人会用本地工具/流程完成任务。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Map critical tasks and failure modes to roles, assess prerequisites, provide hands-on labs and refresh after tool/threat changes. Managers own attendance and job application; subject experts validate content, while role changes trigger new training and obsolete privileges/training are removed.",
          "zh": "把关键任务/失败模式映射角色，评估前置能力，提供 Hands-on Lab，工具/威胁变化后刷新；经理负责参加与上岗应用，专家验内容，调岗触发新培训并移除旧权限/要求。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "One role can span several risk domains, and contractors/providers may perform privileged tasks. Certifications and generic courses do not prove local competence. Training cannot compensate indefinitely for unusable processes or excessive privilege; repeated errors demand system and control redesign.",
          "zh": "一人可跨多个风险域，承包商/服务商也可能做高权工作。证书和通用课不证明本地能力。若流程不可用或权限过宽，培训不能永久补偿；重复错误要求系统重设计。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Use practical performance assessments—secure change, code review, identity proofing, incident triage, vendor assessment or payment verification—with positive/negative cases. Measure demonstrated task capability and operational outcomes, then remediate gaps; completion alone is insufficient.",
          "zh": "用安全变更、代码审查、身份核验、事件分诊、供应商评估、付款确认等实操，带正负案例；测任务能力与运营结果并补缺，不能只数完成。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "14.9",
          "control": 14,
          "title": {
            "en": "Conduct Role-Specific Security Awareness and Skills Training",
            "zh": "角色化安全技能"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls14/",
          "snapshot_sha256": "B3AB523467DE4AACC7A8227C3CC2056EE99F14A3A254D1769D5EAC5C90C30305",
          "retrieved_at": "2026-07-30T16:26:01.267Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-036"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-15.1",
      "safeguard_id": "15.1",
      "control": 15,
      "title": {
        "en": "Establish and Maintain an Inventory of Service Providers",
        "zh": "服务提供商总账"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Identify",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Include every external entity that stores/processes data, operates technology, supplies security/identity/software, provides infrastructure, has privileged access or materially supports availability—including cloud/SaaS, MSP, processors/subprocessors, contractors and critical open-source/commercial dependencies where a provider relationship exists.",
          "zh": "包括存储/处理数据、运营技术、提供安全/身份/软件、基础设施、高权接入或关键可用支持的外部实体：云/SaaS、MSP、处理者/分包、承包商，以及有服务关系的关键软件依赖。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Reconcile procurement, accounts payable, SSO/OAuth, network/API integrations, data flows, software inventory and business-owner attestations. Record service, legal entity, owner/contact, classification, data/access, systems, regions, subprocessors, contract/renewal, exit path and lifecycle; review annually and on change.",
          "zh": "对账采购、应付、SSO/OAuth、网络/API 集成、数据流、软件台账和业务责任人声明；记录服务、法律实体、责任人、分级、数据/访问、系统、地区、分包、合同/续约、退出与生命周期，每年及变化时更新。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A marketplace app or free SaaS can be a provider without a purchase order. Open-source projects without a service contract belong in software-supply-chain governance; invented vendor obligations have no enforceable counterparty. CAS classifies providers as Users, a metadata choice that must not narrow the population; missing providers cannot be excluded from the denominator.",
          "zh": "免费/市场 App 无 PO 也可能是服务商。无服务合同的开源项目应走软件供应链治理，不能凭空制造合同义务。CAS 把服务商归 Users 只是元数据，不能缩范围；漏记供应商也不能排分母。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Select providers from expense, OAuth, DNS/network, data-flow and application sources and trace both directions to the inventory. Add and terminate a test supplier through workflow. Measure accurate/complete providers against an independently assembled population, with shadow and dormant services separate.",
          "zh": "从费用、OAuth、DNS/网络、数据流和应用来源抽供应商，双向回台账；让测试供应商走新增/终止。分母用独立拼出的总体，影子/休眠服务单列。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "15.1",
          "control": 15,
          "title": {
            "en": "Establish and Maintain an Inventory of Service Providers",
            "zh": "服务提供商总账"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls15/",
          "snapshot_sha256": "6987C580534344D0FE4C30694EFBA342A165145B53FB87BFE53160867B099415",
          "retrieved_at": "2026-07-30T16:26:02.291Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-15.2",
      "safeguard_id": "15.2",
      "control": 15,
      "title": {
        "en": "Establish and Maintain a Service Provider Management Policy",
        "zh": "服务提供商管理政策"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The policy governs provider discovery, classification, due diligence, contracting, onboarding, access/data flow, assessment, monitoring, incident/change, renewal and decommissioning. Requirements scale by inherent and residual risk while defining minimum non-negotiable controls.",
          "zh": "政策覆盖发现、分级、尽调、合同、上线、访问/数据流、评估、监控、事件/变化、续约和退出；按固有/剩余风险缩放要求，并规定不可让步的最低控制。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Assign business, procurement, legal, privacy, security, data and technical responsibilities; define evidence standards, approval authority, exceptions, remediation, continuous monitoring and exit. Review annually and after material regulation, threat, provider or business-model change; integrate with procurement and architecture gates.",
          "zh": "分配业务、采购、法务、隐私、安全、数据和技术责任，定义证据标准、批准、例外、修复、持续监控和退出；每年及法规、威胁、供应商、业务模式变化时更新，并接采购/架构 Gate。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A five-topic document can pass CAS completeness while workflows ignore it. Small providers may lack standard reports but still need proportionate evidence and contractual commitments. The policy cannot transfer enterprise accountability to a provider or require rights the contract/business cannot exercise.",
          "zh": "五主题文档可过 CAS，但流程可能完全不执行。小供应商无标准报告时仍需相称证据/合同。政策不能把企业责任转给服务商，也不能要求合同/业务无法执行的权利。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Walk a low- and high-risk provider through request to exit and verify every gate, evidence and decision. Test emergency procurement and contract renewal, inspect exceptions and overdue assessments, and confirm shadow-provider discoveries enter governance.",
          "zh": "让一低一高风险服务商从申请走到退出，验证每个 Gate、证据和决定；测试紧急采购/续约，检查例外、逾期评估和影子供应商进入治理。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "15.2",
          "control": 15,
          "title": {
            "en": "Establish and Maintain a Service Provider Management Policy",
            "zh": "服务提供商管理政策"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls15/",
          "snapshot_sha256": "6987C580534344D0FE4C30694EFBA342A165145B53FB87BFE53160867B099415",
          "retrieved_at": "2026-07-30T16:26:02.291Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-15.3",
      "safeguard_id": "15.3",
      "control": 15,
      "title": {
        "en": "Classify Service Providers",
        "zh": "服务提供商分级"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Classification reflects data sensitivity/volume, privilege and connectivity, service criticality/recoverability, substitutability, concentration, jurisdictions, regulations, software/update authority, threat exposure, inherent controls and residual risk. Provider size or spend alone is a poor proxy.",
          "zh": "分级考虑数据敏感/体量、权限/连接、关键度/可恢复、可替代、集中度、司法辖区、法规、软件/更新权、威胁暴露、固有控制和剩余风险；规模/花费不是好代理。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Define tier criteria and evidence, classify before onboarding, select assessment, contract, monitoring, and exit requirements by tier, and review annually plus on scope, subprocessor, incident, or architecture change. Business and security owners approve residual tier and dependencies.",
          "zh": "定义 Tier 标准/证据，上线前分级，并按 Tier 选择评估、合同、监控和退出；每年及范围、分包、事件、架构变化时重审，业务/安全共同批准剩余风险。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A provider can have low confidentiality impact and critical availability impact; keep those ratings separate in a multidimensional model. Parent-company certification may not cover the service/region. CAS only counts assigned classifications, so arbitrary or stale labels can pass without risk validity.",
          "zh": "低机密供应商也可能有高可用风险，应多维而非单标签。母公司认证未必覆盖所用服务/地区。CAS 只数是否有分类，随意或陈旧标签也能过，不能证明风险有效。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Give independent reviewers representative providers and edge cases and compare decisions; trace each tier to actual requirements and sample evidence. Simulate a provider gaining sensitive data or privileged integration and verify reclassification and new controls.",
          "zh": "让独立评审者处理代表与边缘案例，比较结果；把 Tier 追到实际要求并抽证据。模拟供应商取得敏感数据或高权集成，验证重分级与新控制。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "15.3",
          "control": 15,
          "title": {
            "en": "Classify Service Providers",
            "zh": "服务提供商分级"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls15/",
          "snapshot_sha256": "6987C580534344D0FE4C30694EFBA342A165145B53FB87BFE53160867B099415",
          "retrieved_at": "2026-07-30T16:26:02.291Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-15.4",
      "safeguard_id": "15.4",
      "control": 15,
      "title": {
        "en": "Ensure Service Provider Contracts Include Security Requirements",
        "zh": "合同安全要求"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Scope contracts, orders, data-processing terms, SLAs and incorporated policies for providers according to classification. Requirements can include control baseline, least privilege, encryption, logs/evidence, vulnerability/change, incident/breach notice, subprocessor, data location/use, continuity, audit, remediation, disposal/return and exit assistance.",
          "zh": "按供应商分级覆盖合同、订单、DPA、SLA 和引入政策；可含最低安全、最小权限、加密、日志/证据、漏洞/变化、事件/泄露通知、分包、数据地区/用途、连续性、审计、修复、销毁/返还和退出帮助。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Use tiered clauses with legal/procurement/security review, ensure obligations bind the exact service and subprocessors, negotiate notification and evidence timelines that meet response needs, and map each clause to an operating owner. Review annually and at renewal/scope change.",
          "zh": "用分层条款经法务/采购/安全复核，确保准确服务及分包都受约束，通知/证据时间满足响应，并把条款映射运营责任人；每年及续约/范围变化时复核。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A signed contract cannot create a technical capability or make an unenforceable promise useful. Standard click-through services may offer no negotiation; choose a lower-risk design, compensating control or alternative. CAS checks current review/contracts but not clause presence or performance, so its metric is insufficient.",
          "zh": "签合同不能凭空创造技术能力或使不可执行承诺有用。Click-through 服务不能谈判时，应降低风险设计、补偿或换商。CAS 只看合同/复核新鲜，不看条款存在与履行，远远不够。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Sample high-risk contracts and trace required events—incident notice, log request, deletion, assessment, recovery—to executable contacts, rights and evidence. Tabletop a breach and termination against the contract; record gaps, waivers and remediation instead of assuming boilerplate works.",
          "zh": "抽高风险合同，把事件通知、日志请求、删除、评估、恢复追到可执行联系人、权利和证据；桌演泄露/终止，记录缺口、豁免和修复，不能假设 Boilerplate 有效。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "15.4",
          "control": 15,
          "title": {
            "en": "Ensure Service Provider Contracts Include Security Requirements",
            "zh": "合同安全要求"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls15/",
          "snapshot_sha256": "6987C580534344D0FE4C30694EFBA342A165145B53FB87BFE53160867B099415",
          "retrieved_at": "2026-07-30T16:26:02.291Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-15.5",
      "safeguard_id": "15.5",
      "control": 15,
      "title": {
        "en": "Assess Service Providers",
        "zh": "服务提供商评估"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Users",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Assess each provider at onboarding, at least annually and at renewal according to classification, using evidence scoped to the exact service, entity, region, period and controls. SOC reports, certifications, PCI attestations, questionnaires, tests and architecture interviews answer different questions.",
          "zh": "上线、至少每年和续约时，按分级评估准确服务、法律实体、地区、期间和控制。SOC、认证、PCI、问卷、技术测试和架构访谈回答不同问题。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Start with service/data/access architecture and shared responsibility, request primary evidence, review exceptions/complementary user controls/subprocessors/incidents, validate remediation and issue a residual-risk decision with expiry. Increase depth for privileged, critical or software-supply-chain providers.",
          "zh": "先画服务/数据/访问和共享责任，收一手证据，审例外、用户补充控制、分包与事件，验证修复并作有到期的剩余风险决定；高权、关键或供应链服务加深。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A clean certification opinion does not mean no exceptions and may exclude the product used. CAS 15.5 mistakenly measures “monitoring guidance,” duplicating 15.6 instead of assessment performance. Provider refusal is evidence of uncertainty and requires a conscious risk/design decision with no automatic pass or fail.",
          "zh": "干净认证意见不等于无例外，且可能排除所用产品。CAS 15.5 错把“监控指导”当评估，实质重复 15.6。供应商拒绝是“不确定”证据，需要设计/风险决定，不能自动通过或失败。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "For sampled providers, trace claimed controls to report sections, tenant configuration and enterprise responsibilities; verify report period/bridge letter and close findings. Reperform a technical or process control where contract and risk permit; test decision escalation for inadequate evidence.",
          "zh": "抽样把供应商声明追到报告章节、租户配置和企业责任，确认报告期间/Bridge Letter 并关闭发现；合同/风险允许时复做技术或流程控制，并测试证据不足升级。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "15.5",
          "control": 15,
          "title": {
            "en": "Assess Service Providers",
            "zh": "服务提供商评估"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls15/",
          "snapshot_sha256": "6987C580534344D0FE4C30694EFBA342A165145B53FB87BFE53160867B099415",
          "retrieved_at": "2026-07-30T16:26:02.291Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-037"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-15.6",
      "safeguard_id": "15.6",
      "control": 15,
      "title": {
        "en": "Monitor Service Providers",
        "zh": "服务提供商持续监测"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Data",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Monitoring follows provider risk between assessments: security advisories/incidents, releases and breaking changes, control/report updates, domain/certificate and external exposure, service availability, subprocessor/ownership/location changes, access/data-flow drift and dark-web signals where lawful and useful.",
          "zh": "在两次评估间监控安全通告/事件、Release/破坏性变化、控制报告、域名/证书/外暴露、可用性、分包/所有权/地域、访问/数据流漂移和合法有用的暗网信号。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Define sources, cadence, thresholds, owner and response by provider tier; combine provider notices, tenant logs, technical telemetry, contract events and credible external intelligence. Reassess or contain when a change crosses a threshold and record false reports and source limits.",
          "zh": "按 Tier 定来源、频率、阈值、责任和响应，结合供应商通知、租户日志、技术遥测、合同事件和可信外部情报；越阈值即重评/遏制，并记录假消息与来源限制。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Internet ratings and dark-web mentions are noisy, externally observable proxies and cannot replace service-specific evidence. CAS 15.6 counts written guidance, not actual observations. Providers may change silently, so contract notification plus technical detection and business-owner review form the boundary.",
          "zh": "互联网评分和暗网提及噪声高，只是外部代理，不能替代服务证据。CAS 15.6 只数书面指导，不数实际观测。供应商可能静默变化，需合同通知、技术发现和业务复核共同兜底。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Inject a test provider notice, OAuth-scope change, service outage or overdue evidence and verify triage, owner, decision and access/data response. Sample whether monitored signals cover the provider's actual service and whether alerts close; track stale feeds and unobserved providers.",
          "zh": "注入测试通知、OAuth Scope 变化、停机或逾期证据，验证分诊、责任、决定和访问/数据响应；抽查信号是否覆盖真实服务、告警是否关闭，并跟踪陈旧 Feed/未观测商。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "15.6",
          "control": 15,
          "title": {
            "en": "Monitor Service Providers",
            "zh": "服务提供商持续监测"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls15/",
          "snapshot_sha256": "6987C580534344D0FE4C30694EFBA342A165145B53FB87BFE53160867B099415",
          "retrieved_at": "2026-07-30T16:26:02.291Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-15.7",
      "safeguard_id": "15.7",
      "control": 15,
      "title": {
        "en": "Securely Decommission Service Providers",
        "zh": "服务提供商安全退出"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Decommissioning covers contracts, users/service accounts, keys/tokens/certificates, network and API links, SSO/OAuth, data flows, stored/backup data, domains, software/agents, support access, billing and dependent providers. It must preserve required records while ending provider authority.",
          "zh": "退出覆盖合同、用户/服务账户、Key/Token/证书、网络/API、SSO/OAuth、数据流、存储/备份数据、域名、软件/Agent、支持访问、账单和依赖商；保留法定记录同时终止权限。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Plan exit before onboarding, identify successor/export and retention, freeze changes, export/validate data, revoke access and routes, rotate shared secrets, request and verify disposal, update inventories and monitor for residual use. Assign business, technical, data, legal and security acceptance.",
          "zh": "上线前就规划退出，确定替代/导出和保留，冻结变化，导出/验数据，撤访问/路由，轮换共享秘密，请求/验证销毁，更新台账并监测残留；业务、技术、数据、法务、安全共同验收。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Deletion certificates may exclude backups/subprocessors and need scoped interpretation. Legal hold can retain data without retaining access. CAS considers only providers terminated in the last 12 months, so an empty denominator requires “not tested/no recent exits,” not automatic compliance; conduct a simulated exit when necessary.",
          "zh": "删除证明可能排除备份/分包，需看范围。诉讼保全可留数据，不能留访问。CAS 只看近 12 月已终止供应商，空总体应记“未实测/无近期退出”，不能自动合规；必要时模拟退出。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Run an exit checklist against a real or test service, then attempt old login, token, API, network route, DNS/email and data retrieval. Reconcile provider events and expenses after closure, validate exported data and deletion evidence, and retest after provider retention windows.",
          "zh": "用真实或测试服务走清单，再尝试旧登录、Token、API、路由、DNS/邮件和取数；结案后对账事件/费用，验证导出与删除证据，并在服务商保留窗口后复测。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "15.7",
          "control": 15,
          "title": {
            "en": "Securely Decommission Service Providers",
            "zh": "服务提供商安全退出"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls15/",
          "snapshot_sha256": "6987C580534344D0FE4C30694EFBA342A165145B53FB87BFE53160867B099415",
          "retrieved_at": "2026-07-30T16:26:02.291Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-16.1",
      "safeguard_id": "16.1",
      "control": 16,
      "title": {
        "en": "Establish and Maintain a Secure Application Development Process",
        "zh": "安全应用开发流程"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The process covers software the enterprise designs, builds, configures or materially customizes, including web/mobile/API, services, infrastructure code, data/AI pipelines and low-code workflows. It spans requirements, design, coding, dependencies, build, test, release, operation, vulnerability intake and retirement, scaled by consequence.",
          "zh": "覆盖企业设计、开发、配置或深度定制的软件，包括 Web/移动/API、服务、IaC、数据/AI 管道和低代码，从需求、设计、编码、依赖、构建、测试、发布、运行、漏洞接收一直到退役，按后果缩放。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Define secure design/coding standards, roles, training, threat modeling, component/source trust, secrets, reviews/tests, release gates, exception and response. Embed evidence in version control and CI/CD, review annually and after material platform, threat or product change, and give product teams usable paved roads.",
          "zh": "定义安全设计/编码、角色、培训、威胁建模、组件/来源信任、秘密、评审/测试、发布 Gate、例外和响应，把证据嵌入版本库/CI/CD；每年及平台、威胁、产品重大变化时更新，并给团队好用的 Paved Road。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A six-topic document can pass CAS while delivery bypasses it. Purchased SaaS follows provider governance unless custom code/config creates an application boundary. Small changes need proportionate controls, while emergency fixes retain retrospective review; speed is not an exemption from traceability.",
          "zh": "六主题文档可过 CAS，但交付可能全绕过。采购 SaaS 主要走供应商治理，除非定制代码/配置形成新应用边界。小改可相称简化，应急修复仍需事后评审；速度不是免追溯。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Select representative changes and trace security requirements, design decision, review, tests, artifact provenance, approval and deployed result. Introduce a safe failing check and verify it blocks or follows an explicit risk gate; inspect hotfix and low-code paths.",
          "zh": "从代表变更追安全要求、设计决定、评审、测试、制品来源、批准和部署结果；放一个安全的失败检查，验证发布被阻断或走显式风险 Gate，并检查 Hotfix/低代码路径。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "16.1",
          "control": 16,
          "title": {
            "en": "Establish and Maintain a Secure Application Development Process",
            "zh": "安全应用开发流程"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls16/",
          "snapshot_sha256": "78BEFD8EB1628E546CA330222996DCA16DD2C9EF7FC70A606844C44A4F64872E",
          "retrieved_at": "2026-07-30T16:26:03.475Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-16.2",
      "safeguard_id": "16.2",
      "control": 16,
      "title": {
        "en": "Establish and Maintain a Process to Accept and Address Software Vulnerabilities",
        "zh": "软件漏洞接收与处置"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Scope external and internal reports for every supported product/component, with a public or discoverable reporting channel, safe-harbor expectations where appropriate, product/version ownership and coordinated handling. Scanner tickets alone do not replace human-reported logic or supply-chain issues.",
          "zh": "覆盖所有受支持产品/组件的内外部漏洞报告，提供公开或可发现的入口、适当 Safe Harbor、产品/版本责任和协调处置。扫描器工单不能替代人发现的逻辑/供应链问题。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Publish contact or security.txt , acknowledge securely, protect reporter/data, deduplicate and track intake, validation, severity, owner, remediation, test, advisory and disclosure timelines. Maintain backup contacts, spam/abuse handling and metrics; review annually and on product/process change.",
          "zh": "发布联系或 security.txt ，安全确认和交换，保护报告者/数据，去重并跟踪接收、验证、严重度、责任、修复、测试、公告和披露；有备用联系人/垃圾处理/指标，每年及变化时更新。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A mailbox that nobody monitors is not a process. Legal threats or mandatory accounts discourage reporting. Third-party-only vulnerabilities need upstream coordination and customer mitigation; disclosure timing balances user protection and repair evidence, with no guarantee a reporter's severity or exploit claim is correct.",
          "zh": "无人看邮箱不是流程。法律威胁或强制注册会赶走报告者。纯第三方漏洞需上游协调和客户缓解；披露时间平衡用户保护与修复证据，报告者给的严重度/利用主张也须核验。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Submit a benign test report from outside and inside, verify acknowledgement, confidential exchange, triage, ownership, fix test and closure timing. Test duplicate, invalid, embargoed and critical reports plus an unavailable primary responder; inspect aged/unassigned cases.",
          "zh": "从外部和内部提交无害测试报告，验证确认、保密通信、分诊、认领、修复测试和时延；测试重复、无效、Embargo、高危和主响应人失联，检查老化/无主案件。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "16.2",
          "control": 16,
          "title": {
            "en": "Establish and Maintain a Process to Accept and Address Software Vulnerabilities",
            "zh": "软件漏洞接收与处置"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls16/",
          "snapshot_sha256": "78BEFD8EB1628E546CA330222996DCA16DD2C9EF7FC70A606844C44A4F64872E",
          "retrieved_at": "2026-07-30T16:26:03.475Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-16.3",
      "safeguard_id": "16.3",
      "control": 16,
      "title": {
        "en": "Perform Root Cause Analysis on Security Vulnerabilities",
        "zh": "漏洞根因分析"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The population should include security vulnerabilities whose consequence, recurrence or systemic pattern warrants analysis, with a declared threshold; doing a shallow RCA on every low-value scanner finding can crowd out learning. Root cause reaches design, requirement, dependency, test, tooling and organizational conditions beyond the faulty line.",
          "zh": "对后果高、重复或呈系统模式的安全漏洞做根因分析，并声明阈值；所有低价值扫描项都做浅 RCA 会挤掉学习。根因要追到设计、需求、依赖、测试、工具和组织条件，不停在出错代码行。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Use a blameless method to distinguish introduction, escape and impact-enabling causes, classify patterns, assign systemic actions and feed standards, training, templates, tests and architecture. Link actions to owners/dates and verify they reduce the affected class across products.",
          "zh": "无责地区分引入原因、逃逸原因和放大影响原因，分类模式，分配系统行动，反馈标准、培训、模板、测试和架构；行动有责任/日期并验证能跨产品降低同类。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "“Developer mistake” is not a root cause. Some third-party or legacy issues lack full source/history, so record evidence limits and focus on containment/selection. The last-12-month CAS denominator becomes empty without recent cases; run a retrospective sample or report not tested, never automatic effectiveness.",
          "zh": "“开发者失误”不是根因。第三方/遗留可能无完整源码历史，应记录证据界限并聚焦遏制/选型。近 12 月无案例时 CAS 分母为空，应用历史样本/演练或记未测试，不能自动有效。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Sample addressed vulnerabilities and trace RCA evidence to code/history and follow-up controls. Inject or use historical related cases to test whether the new guard catches recurrence; measure completed high-priority RCAs, action closure and repeated classes; document count remains a process metric.",
          "zh": "抽样已处理漏洞，把 RCA 证据追到代码/历史与后续控制；用相关历史/注入案例验证新 Guard 能抓复发。指标看高优 RCA、行动关闭和同类复发，不看文档数。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "16.3",
          "control": 16,
          "title": {
            "en": "Perform Root Cause Analysis on Security Vulnerabilities",
            "zh": "漏洞根因分析"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls16/",
          "snapshot_sha256": "78BEFD8EB1628E546CA330222996DCA16DD2C9EF7FC70A606844C44A4F64872E",
          "retrieved_at": "2026-07-30T16:26:03.475Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-16.4",
      "safeguard_id": "16.4",
      "control": 16,
      "title": {
        "en": "Establish and Manage an Inventory of Third-Party Software Components",
        "zh": "第三方组件与 SBOM"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Identfy",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Include direct and transitive open-source/commercial libraries, frameworks, plugins, container bases, build tools and runtime services used or planned, linked to exact product, version, environment and released artifact. Package names without ecosystem, source and digest are ambiguous.",
          "zh": "包括当前和计划使用的直接/传递开源与商业库、框架、插件、容器 Base、构建工具和运行服务，并关联准确产品、版本、环境与发布制品；只有包名、无生态/来源/摘要会歧义。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Generate and reconcile SBOMs from lockfiles, build and artifacts, record supplier/source, version/digest, license, support, risk and owner, and review at least monthly plus every build. Preserve provenance and dependency relationships; remove unused/planned items that never pass approval.",
          "zh": "从 Lockfile、Build 和 Artifact 生成/对账 SBOM，记录供应商/来源、版本/摘要、许可证、支持、风险和责任人，至少每月及每次构建审查；保留来源/依赖关系，未过批准的计划项及时移除。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "CAS labels the security function “Identfy” and compares a day measure to 12 months despite the safeguard's monthly cadence. An SBOM alone leaves completeness, reachability, trust and deployment unresolved. Vendored/static, generated, SaaS APIs and AI models/datasets need their own component/provenance representation.",
          "zh": "CAS 把功能写成 “Identfy”，又把以天计的时效拿去与 12 个月比较，而本项要求月审。SBOM 不证明完整、可达、可信或部署。Vendored/静态、生成代码、SaaS API、AI 模型/数据集需各自来源表示。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Build a test artifact with direct/transitive components and compare source lock, resolver, SBOM, artifact scan and running deployment. Substitute a digest or dependency source to verify detection; measure released artifacts with complete current component identity, not a global list.",
          "zh": "构建含直接/传递依赖的测试制品，对比源码锁、Resolver、SBOM、制品扫描和运行部署；替换摘要/来源验证发现。指标看发布制品组件身份是否完整当前，不看一张全局名单。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "16.4",
          "control": 16,
          "title": {
            "en": "Establish and Manage an Inventory of Third-Party Software Components",
            "zh": "第三方组件与 SBOM"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls16/",
          "snapshot_sha256": "78BEFD8EB1628E546CA330222996DCA16DD2C9EF7FC70A606844C44A4F64872E",
          "retrieved_at": "2026-07-30T16:26:03.475Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-038"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-16.5",
      "safeguard_id": "16.5",
      "control": 16,
      "title": {
        "en": "Use Up-to-Date and Trusted Third-Party Software Components",
        "zh": "可信且及时的第三方组件"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The decision covers component version, source, publisher/maintainer, integrity/provenance, support, known risk, release maturity and compatibility. “Latest” is not automatically trustworthy or safe; “trusted” is a reviewable enterprise decision, not popularity.",
          "zh": "判定同时看组件版本、来源、发布者/维护者、完整性/Provenance、支持、已知风险、成熟度和兼容性。“最新”不自动可信/安全，“可信”也必须可复核，不能等于 Star 数。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Resolve only through controlled repositories, pin and verify digests/signatures/provenance, monitor advisories and support, update within risk SLO and test before promotion. Prefer maintained, narrowly scoped components and remove abandoned or redundant dependencies; define emergency substitution/rollback.",
          "zh": "只经受控仓库解析，固定并验摘要/签名/来源，监控通告与支持，在风险 SLO 内更新并先测试；优先维护良好、窄功能组件，移除废弃/重复依赖，定义紧急替换/回滚。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A trusted component can become compromised and an old version may be safer during a bad release, requiring time-bounded hold. Forks transfer maintenance responsibility to the enterprise. CAS only checks up-to-date items for trust, potentially ignoring explicit trust of older components; assess both dimensions over all components.",
          "zh": "可信组件也会被攻陷，坏版本期间旧版可能暂时更安全，需限时 Hold。Fork 后维护责任转给企业。CAS 只对“最新项”测信任，可能忽略旧项是否获批；两维都要覆盖全部组件。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Attempt dependency confusion, typosquat/unapproved registry, modified digest, unsupported and known-vulnerable versions in a test build. Verify block/review, artifact linkage and deployed version; sample upstream ownership/release authenticity and update outcomes.",
          "zh": "在测试构建尝试依赖混淆、Typosquat、未批准 Registry、改摘要、不支持和已知漏洞版本，验证阻断/评审、制品关联和部署版本，并抽验上游所有权/发布真实性和更新结果。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "16.5",
          "control": 16,
          "title": {
            "en": "Use Up-to-Date and Trusted Third-Party Software Components",
            "zh": "可信且及时的第三方组件"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls16/",
          "snapshot_sha256": "78BEFD8EB1628E546CA330222996DCA16DD2C9EF7FC70A606844C44A4F64872E",
          "retrieved_at": "2026-07-30T16:26:03.475Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-16.6",
      "safeguard_id": "16.6",
      "control": 16,
      "title": {
        "en": "Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities",
        "zh": "应用漏洞严重度与发布门槛"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The system rates vulnerabilities in application context using exploitability, exposure, privilege, data/business consequence, chaining, control strength and active exploitation. It defines release-blocking and remediation decisions for code, dependencies, configuration and design findings across pre- and post-production.",
          "zh": "系统要用应用上下文评估可利用性、暴露、权限、数据/业务后果、串链、现有控制和活跃利用，并为代码、依赖、配置、设计的发布前后发现设发布阻断/修复决定。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Create consistent severity/risk criteria, triage authority, SLOs, minimum release acceptability, exception/expiry and escalation. Calibrate scanner severities, document overrides with evidence and review annually plus after significant incidents or threat/model changes.",
          "zh": "制定一致严重度/风险标准、分诊权、SLO、最低发布可接受度、例外/到期和升级；校准扫描器分数，覆盖需证据，每年及重大事件/威胁/模型变化时更新。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "CVSS alone lacks business and architecture context; lowering severity to ship is not risk treatment. A low technical score can unlock a critical chain, while unreachable code may be lower risk with proof. Emergency releases still require named risk ownership and a near-term fix/retest.",
          "zh": "CVSS 没有业务/架构上下文；为上线降分不是风险处置。低技术分也可能打开关键链，有证据的不可达代码可降风险。应急发布仍需具名风险责任和近期修复/复测。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Give multiple reviewers representative standalone, chained and context-changing findings and compare decisions. Test a release containing a gate-level finding and an expiring exception; verify block, approval, deployed-state tracking and later remediation.",
          "zh": "给多名评审者独立、串链和上下文改变的代表发现，比较决定；测试含 Gate 级问题和将到期例外的发布，验证阻断、批准、部署跟踪和后续修复。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "16.6",
          "control": 16,
          "title": {
            "en": "Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities",
            "zh": "应用漏洞严重度与发布门槛"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls16/",
          "snapshot_sha256": "78BEFD8EB1628E546CA330222996DCA16DD2C9EF7FC70A606844C44A4F64872E",
          "retrieved_at": "2026-07-30T16:26:03.475Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-16.7",
      "safeguard_id": "16.7",
      "control": 16,
      "title": {
        "en": "Use Standard Hardening Configuration Templates for Application Infrastructure",
        "zh": "应用基础设施硬化模板"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Scope servers, web/app/database platforms, containers, orchestration, PaaS and tenant-configurable SaaS components supporting each application. The application must not reopen insecure ports, accounts, permissions or settings after a base image passes.",
          "zh": "覆盖支撑应用的服务器、Web/App/DB 平台、容器、编排、PaaS 和租户可配置 SaaS；应用不能在 Base Image 合规后又重新打开不安全端口、账户、权限或设置。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Use versioned, tested templates from authoritative hardening guidance, deploy through images/IaC/policy, add application-specific deltas and prevent drift in CI/CD and runtime. Pin service/version/profile and treat SaaS settings and provider responsibilities as code/evidence where possible.",
          "zh": "用权威加固的版本化测试模板，经镜像/IaC/策略部署，叠加应用特定 Delta，在 CI/CD 和运行时防漂移；固定服务/版本/Profile，尽量把 SaaS 设置与共享责任也变成代码/证据。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "CAS inputs only asset and network standards, omitting application/software baseline context. PaaS/SaaS hides underlying settings but leaves tenant identity, network, data and logging controls. Hardening that breaks required behavior needs a narrow documented delta, not wholesale template disablement.",
          "zh": "CAS 只用资产和网络标准输入，漏应用/软件基线上下文。PaaS/SaaS 隐藏底层但仍留租户身份、网络、数据和日志。硬化若破业务，应做窄 Delta，不可整套关闭。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Build and deploy a representative stack, scan effective settings, exercise business functions and inject application configuration that weakens a baseline control. Verify release rejection or explicit exception and runtime drift repair; reconcile components to templates.",
          "zh": "构建部署代表 Stack，扫描有效设置，跑业务并注入会削弱基线的应用配置，验证发布拒绝或显式例外与运行漂移修复；把组件与模板对账。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "16.7",
          "control": 16,
          "title": {
            "en": "Use Standard Hardening Configuration Templates for Application Infrastructure",
            "zh": "应用基础设施硬化模板"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls16/",
          "snapshot_sha256": "78BEFD8EB1628E546CA330222996DCA16DD2C9EF7FC70A606844C44A4F64872E",
          "retrieved_at": "2026-07-30T16:26:03.475Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-16.8",
      "safeguard_id": "16.8",
      "control": 16,
      "title": {
        "en": "Separate Production and Non-Production Systems",
        "zh": "生产与非生产隔离"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Separation covers identities, accounts/projects, networks, data, keys/secrets, CI/CD authority, monitoring and administration between production and development/test. Having a test system is not sufficient; the point is preventing lower-trust code, people and data from crossing into production unchecked.",
          "zh": "分离覆盖生产与开发/测试的身份、账号/项目、网络、数据、密钥/秘密、CI/CD 权力、监测和管理。拥有一个测试环境不够，目标是防低信任代码、人员和数据未经 Gate 越进生产。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Use separate accounts/tenants/clusters and credentials, controlled artifact promotion, least production access, synthetic/masked test data and explicit one-way deployment. Block production secrets/data in lower environments and stop non-production systems from managing production.",
          "zh": "使用独立账号/租户/集群和凭据，受控制品晋级，最小生产访问，合成/脱敏测试数据和单向部署；禁止生产秘密/数据进低环境，禁止非生产系统管理生产。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "CAS merely counts production systems with a non-production counterpart and its metric text reverses the population; it does not test separation. Shared control planes and CI/CD can collapse isolation. Small systems may use logical separation, but it must withstand the same negative tests.",
          "zh": "CAS 只数“生产有没有非生产对应”，指标文字还反了，并未测试分离。共享控制面和 CI/CD 会塌隔离。小系统可逻辑分离，但须经同样负测。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Attempt production access with a developer/test identity and secret, push an unsigned/unapproved artifact, and move test/production data across boundaries. Verify denial and audit while approved promotion/diagnostics work; inspect shared runners, registries, backups and observability.",
          "zh": "用开发/测试身份和秘密尝试生产访问，推未签名/未批准制品，跨边界搬测试/生产数据，验证拒绝/审计且批准晋级/诊断正常；检查共享 Runner、Registry、备份与监测。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "16.8",
          "control": 16,
          "title": {
            "en": "Separate Production and Non-Production Systems",
            "zh": "生产与非生产隔离"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls16/",
          "snapshot_sha256": "78BEFD8EB1628E546CA330222996DCA16DD2C9EF7FC70A606844C44A4F64872E",
          "retrieved_at": "2026-07-30T16:26:03.475Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-039"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-16.9",
      "safeguard_id": "16.9",
      "control": 16,
      "title": {
        "en": "Train Developers in Application Security Concepts and Secure Coding",
        "zh": "开发人员安全技能"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The population includes developers, testers, architects, DevOps/SRE, data/ML and low-code builders according to languages, frameworks, platforms, roles and product risks. Annual generic OWASP training does not equip someone to secure an unfamiliar local stack.",
          "zh": "包括开发、测试、架构、DevOps/SRE、数据/ML 和低代码人员，按语言、框架、平台、职责和产品风险配课；一年一次通用 OWASP 课不能让人掌握陌生本地栈。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Map role/environment to secure design, coding, dependency, secrets, testing and response skills; train at least annually and on major platform change using local examples and labs. Provide secure libraries, reviewers and just-in-time guidance so knowledge can be applied.",
          "zh": "把角色/环境映射安全设计、编码、依赖、秘密、测试与响应技能，至少每年和平台大变时训练，用本地案例/实验；提供安全库、Reviewer 和 Just-in-time 指导，使知识能落地。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Training cannot compensate for unsafe frameworks, impossible deadlines or missing review. Seniority and certifications do not prove current platform skill. AI-generated code remains the developer/team's responsibility and needs provenance, review and tests; non-coding product roles still need secure requirements training.",
          "zh": "培训补不了危险 Framework、不可能期限和缺失评审。资历/证书不证明当前平台能力。AI 生成代码仍由团队负责，需来源、评审和测试；不写代码的产品角色也要安全需求能力。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Use practical tasks such as fixing authz, injection, secret, dependency or cloud-policy flaws in the actual stack, and review subsequent code outcomes. Reconcile personnel/roles to current training, including contractors, and remediate skill gaps; attendance remains an input only.",
          "zh": "在真实技术栈做授权、注入、秘密、依赖或云策略修复实操，并看后续代码结果；把人员/角色与当前训练对账，含承包商，发现能力缺口就补而非只数出席。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "16.9",
          "control": 16,
          "title": {
            "en": "Train Developers in Application Security Concepts and Secure Coding",
            "zh": "开发人员安全技能"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls16/",
          "snapshot_sha256": "78BEFD8EB1628E546CA330222996DCA16DD2C9EF7FC70A606844C44A4F64872E",
          "retrieved_at": "2026-07-30T16:26:03.475Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-16.10",
      "safeguard_id": "16.10",
      "control": 16,
      "title": {
        "en": "Apply Secure Design Principles in Application Architectures",
        "zh": "安全设计原则"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Apply least privilege, complete mediation, deny-by-default, trust-boundary validation, safe failure, separation, minimization and attack-surface reduction to application architecture and every sensitive operation. “Never trust input” includes identities, state, events, model/tool output and provider callbacks, not only strings.",
          "zh": "把最小权限、完全中介、默认拒绝、信任边界校验、安全失败、职责分离、最小化和攻击面缩减应用到架构和每个敏感操作。“不信输入”包含身份、状态、事件、模型/工具输出与服务商 Callback，不只字符串。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Record security invariants and trust/data flows, centralize authorization at each object/action, validate size/type/range/state, design abuse limits and failure modes, remove unnecessary interfaces and review material design changes before code. Link threat model to tests and telemetry.",
          "zh": "记录安全不变量和信任/数据流，在每个对象/动作做授权，校验大小/类型/范围/状态，设计滥用限制与故障模式，去掉无必要接口，并在编码前审重大设计；威胁模型连接测试/遥测。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "CAS counts application infrastructure components said to apply principles, an unverifiable unit. Framework middleware can be bypassed by background jobs, direct storage, cache or admin paths. Secure design reduces whole classes; deployment evidence and change tests establish implementation.",
          "zh": "CAS 数“应用基础组件应用了原则”，单位无法验证。Middleware 可被后台 Job、直存、Cache 和管理路径绕过。安全设计降整类风险但不能证明实现，控制必须在部署和变更后仍成立。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Test allowed and denied actions at API, object, tenant, workflow and alternate paths; fuzz/state-test inputs and fail dependencies to observe safe behavior. Trace sampled high-risk operations to a documented invariant, enforcement point, negative test and alert.",
          "zh": "在 API、对象、租户、流程和替代路径测试允许/拒绝，Fuzz/状态测试输入并故障依赖观察安全行为；抽样高风险操作须追到不变量、强制点、负测和告警。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "16.10",
          "control": 16,
          "title": {
            "en": "Apply Secure Design Principles in Application Architectures",
            "zh": "安全设计原则"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls16/",
          "snapshot_sha256": "78BEFD8EB1628E546CA330222996DCA16DD2C9EF7FC70A606844C44A4F64872E",
          "retrieved_at": "2026-07-30T16:26:03.475Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-16.11",
      "safeguard_id": "16.11",
      "control": 16,
      "title": {
        "en": "Leverage Vetted Modules or Services for Application Security Components",
        "zh": "采用审查过的安全模块"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Scope security-critical functions such as identity, authorization, cryptography, secrets, session, validation, logging, payments and updates. The choice compares vetted standards/platform services with custom code and records exactly what assurance and configuration are inherited.",
          "zh": "包括身份、授权、加密、秘密、会话、校验、日志、支付和更新等安全关键功能；选型比较审查过的标准/平台服务与自研，并记录继承的保证和配置。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Default to mature maintained modules/services, pin and configure safely, review source/provider and threat assumptions, wrap them through a paved interface and prohibit ad-hoc cryptography/auth. If custom work is unavoidable, require expert design review, tests and maintenance owner.",
          "zh": "默认用成熟维护模块/服务，固定且安全配置，审来源/服务商和威胁假设，经 Paved Interface 封装，禁止随手自创加密/认证；确需自研则专家设计审查、测试和维护责任。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "“Vetted” is contextual and can age or be misconfigured. Cloud identity or KMS shifts responsibility but does not remove tenant policy and key concerns. CAS marks no-custom-code cases effectively N/A; the enterprise should still prove the selected service is vetted and correctly integrated, while empty denominators remain “not applicable with evidence.”",
          "zh": "“Vetted”有上下文且会过时/误配。云身份/KMS 转移责任但保留租户政策/密钥问题。CAS 把无自研视 N/A，企业仍应证明所选服务经审并正确集成；空分母应“有证据不适用”。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Inventory security components and identify custom logic, then exercise algorithm/config downgrade, key/session misuse, authorization bypass and logging failure around the vetted module. Verify version/provenance and that application glue does not defeat the module's guarantees.",
          "zh": "清点安全组件/自研逻辑，测试算法/配置降级、密钥/会话误用、授权绕过和日志故障；验证版本/来源和应用胶水没有破坏模块保证。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "16.11",
          "control": 16,
          "title": {
            "en": "Leverage Vetted Modules or Services for Application Security Components",
            "zh": "采用审查过的安全模块"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls16/",
          "snapshot_sha256": "78BEFD8EB1628E546CA330222996DCA16DD2C9EF7FC70A606844C44A4F64872E",
          "retrieved_at": "2026-07-30T16:26:03.475Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-16.12",
      "safeguard_id": "16.12",
      "control": 16,
      "title": {
        "en": "Implement Code-Level Security Checks",
        "zh": "代码级安全检查"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The testing portfolio covers source, bytecode/binary, dependencies, infrastructure code, APIs and running application behavior according to language and architecture. Static and dynamic analysis see different defect classes; generated code, low-code and configuration need suitable equivalents.",
          "zh": "测试组合覆盖源码、字节码/二进制、依赖、IaC、API 和运行行为，按语言/架构选择；生成代码、低代码和配置需适当等效物，SAST 与 DAST 看不同缺陷。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Run fast checks on changes and deeper SAST, DAST, IAST, fuzzing, secret, and dependency tests in CI/CD or controlled environments; tune rules, protect baselines, and gate by verified risk. Authenticate dynamic tests and cover API business roles; track suppressions and tool health.",
          "zh": "变更时跑快速检查，CI/CD 或受控环境跑更深 SAST/DAST/IAST/Fuzz/秘密/依赖，调规则、保护 Baseline，并按已验证风险 Gate；动态测试要有认证、覆盖 API/角色，抑制和工具健康受管。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Tools establish findings within their executed rules and reachable context. Runtime generation, business logic and unreachable context remain outside that evidence boundary. Dynamic tests must avoid production harm and legal boundary violations. CAS asks whether each in-house application was “verified” by static or dynamic tools without depth, cadence or outcome; that is only coverage evidence.",
          "zh": "工具只对实际执行的规则和可达上下文建立发现；运行时生成、业务逻辑和不可达上下文仍在该证据边界之外。动态测试必须避免生产伤害和越过法律授权。CAS 只问每个自研应用是否被静态或动态工具“验证”，没有深度、周期或结果，因此只能形成覆盖证据。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Seed safe known flaws and clean controls for each tool/class, verify detection, triage, gate and fix/retest. Measure eligible repositories/releases and executable paths actually tested with current rules, plus false-positive/negative controls—not tools installed or a single scan ever run.",
          "zh": "为每工具/类别植入安全已知缺陷和干净对照，验证发现、分诊、Gate 和修复/复测；指标看合格仓库/发布和可执行路径是否用当前规则实测，还要有误报/漏报控制。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "16.12",
          "control": 16,
          "title": {
            "en": "Implement Code-Level Security Checks",
            "zh": "代码级安全检查"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls16/",
          "snapshot_sha256": "78BEFD8EB1628E546CA330222996DCA16DD2C9EF7FC70A606844C44A4F64872E",
          "retrieved_at": "2026-07-30T16:26:03.475Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-16.13",
      "safeguard_id": "16.13",
      "control": 16,
      "title": {
        "en": "Conduct Application Penetration Testing",
        "zh": "应用渗透测试"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Software",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Scope critical applications and material releases across unauthenticated and authenticated roles, APIs, business workflows, integrations, tenants and provider boundaries. Testing relies on skilled adversarial reasoning and should target authorization and logic beyond automated scanners.",
          "zh": "覆盖关键应用和重大发布的匿名/认证角色、API、业务流、集成、租户与服务商边界；依靠有能力的对抗推理，重点发现授权/逻辑问题，超出自动扫描。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Define risk-based cadence/change triggers, rules of engagement, test identities/data, source/design access level and coordinated response. Use independent qualified testers, preserve coverage and evidence, protect production and route findings into vulnerability/root-cause processes.",
          "zh": "按风险定周期/变更触发、规则、测试身份/数据和源码/设计可见度，使用独立合格测试者，保护生产与证据，把发现接漏洞/RCA 流程。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A broad annual black-box test may miss new high-risk releases; targeted tests trigger on change. “Authenticated” with one admin role is inadequate. Third-party/SaaS testing requires authorization. A clean report reflects tested paths and time, never a certificate that the application is secure.",
          "zh": "年度宽泛黑盒会漏新高风险发布，重大变化需目标测试。“Authenticated”只有管理员一角不够。第三方/SaaS 测试需授权。干净报告只说明当时路径，不是安全证书。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Exercise anonymous, ordinary, privileged, cross-tenant and abuse workflows, validate chained impact safely and retest fixes with positive controls. Record roles, endpoints, versions, limitations and untested paths; measure critical scope and finding closure, not report existence.",
          "zh": "从匿名、普通、高权、跨租户和滥用流程安全验证串链影响，并复测修复和正常正控；记录角色、端点、版本、限制与未测路径，以关键范围/发现关闭为指标。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "16.13",
          "control": 16,
          "title": {
            "en": "Conduct Application Penetration Testing",
            "zh": "应用渗透测试"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls16/",
          "snapshot_sha256": "78BEFD8EB1628E546CA330222996DCA16DD2C9EF7FC70A606844C44A4F64872E",
          "retrieved_at": "2026-07-30T16:26:03.475Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-16.14",
      "safeguard_id": "16.14",
      "control": 16,
      "title": {
        "en": "Conduct Threat Modeling",
        "zh": "威胁建模"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Threat modeling covers new and materially changed applications before code, mapping assets, actors, trust boundaries, data/state flows, entry points, abuse cases and dependencies across architecture and infrastructure. It is a decision practice, not a diagram template.",
          "zh": "在编码前对新建/重大变更应用梳理资产、参与者、信任边界、数据/状态流、入口、滥用和依赖，横跨架构与基础设施；这是决策实践，不是一张模板图。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Use trained multidisciplinary participants, choose a method proportionate to risk, state assumptions and rank threats, then create design requirements, tests, telemetry and accepted residual risks with owners. Revisit when identities, data, integrations, AI tools/models or deployment boundaries change.",
          "zh": "由受训多学科人员用相称方法，声明假设、排序威胁并生成设计要求、测试、遥测和具名剩余风险；身份、数据、集成、AI 模型/工具或部署边界变化时重访。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Counting applications with a workshop, as CAS does, cannot show coverage or quality. Models can become stale and inherit wrong diagrams. Third-party internals may be opaque, so model the observable contract and failure modes; low-risk changes may use lightweight delta analysis but never an unexplained N/A.",
          "zh": "CAS 只数开过 Workshop 的应用，证明不了质量/覆盖。模型会陈旧并继承错误架构图。第三方内部不透明时建可见合同与故障；低风险变化可做轻量 Delta，但不能无解释 N/A。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Select modeled threats and trace them to implemented controls and negative tests; add an architectural change or adversary scenario and verify the model catches the new path. Sample unmodeled production incidents/bugs to improve the method and inspect unresolved actions.",
          "zh": "挑建模威胁追到实现控制和负测；加入架构变化/对手场景，验证模型能发现新路径；抽样未建模的生产事件/漏洞改方法，并查未完成行动。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "16.14",
          "control": 16,
          "title": {
            "en": "Conduct Threat Modeling",
            "zh": "威胁建模"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls16/",
          "snapshot_sha256": "78BEFD8EB1628E546CA330222996DCA16DD2C9EF7FC70A606844C44A4F64872E",
          "retrieved_at": "2026-07-30T16:26:03.475Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-17.1",
      "safeguard_id": "17.1",
      "control": 17,
      "title": {
        "en": "Designate Personnel to Manage Incident Handling",
        "zh": "事件处置负责人"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Respond",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Designate one primary and at least one backup with authority to coordinate and document response/recovery, available for the organization's risk hours. If an external provider leads operations, an internal owner still directs enterprise decisions and accountability.",
          "zh": "指定一个主负责人和至少一个备份，有权协调和记录响应/恢复，覆盖组织风险时段；即使外部服务商主操作，仍要有内部负责人监督企业决定与责任。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Name people/roles, coverage/on-call, delegation, decision and spending authority, provider interface and succession; equip them with independent access to plans, contacts and communication. Review annually and on personnel, provider, structure or material risk change.",
          "zh": "写明人员/角色、值班覆盖、授权、决策/支出权、服务商接口和继任，并给独立访问计划、联系人、通信的能力；每年及人员、服务商、结构或风险变化时更新。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A name in a plan can be on leave, lack privileges or lack authority. Follow-the-sun and small organizations may use roles/providers, but accountability and backup remain explicit. Provider SLA response is not enterprise command; conflicts and unavailable leadership need escalation rules.",
          "zh": "计划里的名字可能休假、无权限或无权拍板。Follow-the-sun/小组织可用角色/服务商，但责任和备份仍明确。服务商 SLA 不等于企业指挥；领导冲突/失联需升级规则。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Page the primary and backup in an exercise, verify acknowledgement, access, handoff, decision log and continuity when one is unavailable. Confirm HR/on-call/provider records agree and that authority is recognized by technical, legal and executive teams.",
          "zh": "演练 Page 主/备，验证确认、访问、交接、决定记录和一人缺席时连续性；确认 HR、值班、服务商记录一致，技术、法务和高层承认其权力。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "17.1",
          "control": 17,
          "title": {
            "en": "Designate Personnel to Manage Incident Handling",
            "zh": "事件处置负责人"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls17/",
          "snapshot_sha256": "A6DCCA0952C7F7B3C5FD75C759EA550966B498275E2E955D804B3D61D116E575",
          "retrieved_at": "2026-07-30T16:26:04.625Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-17.2",
      "safeguard_id": "17.2",
      "control": 17,
      "title": {
        "en": "Establish and Maintain Contact Information for Reporting Security Incidents",
        "zh": "事件联络信息"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Contacts include internal response/leadership, providers, legal/privacy, regulators, law enforcement, cyber insurer/broker, outside counsel/forensics, ISAC/sector bodies, facilities and other stakeholders selected by scenario and jurisdiction. Store role, primary/backup, secure and out-of-band routes and notification conditions.",
          "zh": "包括内部响应/领导、服务商、法务/隐私、监管、执法、网络保险/经纪、外部律师/取证、ISAC、设施和其他按场景/司法区需要的联系人，保存角色、主备、Secure/OOB 路径和通知条件。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Maintain a protected, offline-accessible contact directory and call tree, verify at least annually and on role/contract/regulatory change, and map contacts to incident thresholds and deadlines. Avoid unnecessary personal data while ensuring after-hours reachability.",
          "zh": "维护受保护且离线可用的目录/Call tree，至少每年及角色、合同、法规变化时验证，并关联事件门槛/期限；少存个人信息但保证下班可达。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Publishing sensitive direct contacts too broadly creates privacy/phishing risk, while locking them inside a compromised system makes them useless. Law-enforcement and regulator contact does not mean every event is reported; legal owners decide based on evidence and deadlines.",
          "zh": "太广发布直联会有隐私/钓鱼风险，锁在被攻陷系统又无用。知道执法/监管联系人不等于每事件都报告，法务按证据和期限决定。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Conduct a call-tree exercise without using the primary corporate directory/email, confirm identity and route, and test one provider/insurer/regulator escalation as permitted. Record failed contacts and correction time; sample contract/policy numbers and jurisdiction.",
          "zh": "不依赖主企业目录/邮件演练 Call tree，确认身份和通道，并按许可测试一个服务商/保险/监管升级；记录失败联系人和纠正时间，抽查合同/保单号和司法区。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "17.2",
          "control": 17,
          "title": {
            "en": "Establish and Maintain Contact Information for Reporting Security Incidents",
            "zh": "事件联络信息"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls17/",
          "snapshot_sha256": "A6DCCA0952C7F7B3C5FD75C759EA550966B498275E2E955D804B3D61D116E575",
          "retrieved_at": "2026-07-30T16:26:04.625Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-17.3",
      "safeguard_id": "17.3",
      "control": 17,
      "title": {
        "en": "Establish and Maintain an Enterprise Process for Reporting Incidents",
        "zh": "全员事件报告流程"
      },
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The reporting process is available to the whole workforce and states when, where, how and what minimum context to report, with urgent and anonymous/alternative paths as appropriate. It accepts uncertain observations; reporters do not need to prove or classify an incident.",
          "zh": "对全体人员公开报告流程，说明何时、向谁、怎样和最低上下文，按需有紧急、匿名/替代路径；接受不确定观察，不要求报告者先证明/定级。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Provide memorable channels, after-hours coverage, accessible/localized instructions, acknowledgement, privacy/non-retaliation and evidence-preservation guidance. Route into triage with correlation and escalation; review annually and on organizational, tooling or threat change.",
          "zh": "提供易记、下班可用、无障碍/本地化入口，确认、隐私和非报复，并讲证据保全；接分诊、关联和升级，每年及组织、工具、威胁变化时更新。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "An intranet-only form can fail during account compromise. Requiring excessive detail delays reporting. Anonymous channels may limit follow-up but can expose otherwise hidden issues. A documented process does not pass if queues are unmonitored or workers fear punishment.",
          "zh": "只有内网表单在账户受损时会失败。要求细节太多会延迟。匿名限制跟进但能暴露问题。文档存在但队列无人或员工怕惩罚，不能通过。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Have varied workforce members submit test reports from normal, locked-out, remote and after-hours contexts; verify receipt, useful metadata, triage and feedback. Inspect whether public availability survives identity/email outage and whether duplicate reports correlate.",
          "zh": "让不同人员从正常、锁号、远程和下班环境提交测试报告，验证接收、元数据、分诊与反馈；检查公开入口能否在身份/邮件故障时使用，重复报告能否关联。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "17.3",
          "control": 17,
          "title": {
            "en": "Establish and Maintain an Enterprise Process for Reporting Incidents",
            "zh": "全员事件报告流程"
          },
          "implementation_groups": [
            1,
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls17/",
          "snapshot_sha256": "A6DCCA0952C7F7B3C5FD75C759EA550966B498275E2E955D804B3D61D116E575",
          "retrieved_at": "2026-07-30T16:26:04.625Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-17.4",
      "safeguard_id": "17.4",
      "control": 17,
      "title": {
        "en": "Establish and Maintain an Incident Response Process",
        "zh": "事件响应流程"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The process covers preparation, detection/validation, classification, containment, evidence, eradication, recovery, communications, compliance and closure for cyber, privacy, availability and provider incidents. It links roles, decision authority and scenario playbooks without pretending every incident is linear.",
          "zh": "覆盖准备、检测/验证、分级、遏制、证据、清除、恢复、通信、合规和结案，适用于网络、隐私、可用与供应商事件；关联角色、决策权和场景 Playbook，但不假装所有事件线性。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Document and equip workflows, evidence/case systems, legal/privacy requirements, communication, third-party coordination, recovery criteria and escalation; integrate business continuity and vulnerability lessons. Review annually and after exercises, incidents or major architecture/requirement changes.",
          "zh": "写清并配齐工作流、证据/案件系统、法务/隐私要求、沟通、第三方协同、恢复标准和升级；对接连续性与漏洞学习，每年及演练、事件、架构/要求重大变化后更新。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "CAS checks three document topics only. Plans cannot assume SIEM, email, identity, cloud or provider is available. Destructive containment can harm safety/evidence; legal privilege and privacy vary by jurisdiction. Deviations are expected but must be recorded and reviewed.",
          "zh": "CAS 只检查三类文档主题。计划不能假设 SIEM、邮件、身份、云或服务商始终可用。破坏性遏制会伤安全/证据，法律特权和隐私随地区变化；偏离可发生但要记录复盘。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Run a scenario through alert/report, declaration, containment, evidence, business decision, recovery and notification, including ambiguous facts and failed tools. Measure decision and action times, handoffs, missing authority/data and plan deviations; retest material corrections.",
          "zh": "从告警/报告跑到宣告、遏制、证据、业务决定、恢复和通知，加入事实模糊和工具失败；测决定/动作时间、交接、缺失权限/数据和偏离，并复测重大修正。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "17.4",
          "control": 17,
          "title": {
            "en": "Establish and Maintain an Incident Response Process",
            "zh": "事件响应流程"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls17/",
          "snapshot_sha256": "A6DCCA0952C7F7B3C5FD75C759EA550966B498275E2E955D804B3D61D116E575",
          "retrieved_at": "2026-07-30T16:26:04.625Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-17.5",
      "safeguard_id": "17.5",
      "control": 17,
      "title": {
        "en": "Assign Key Roles and Responsibilities",
        "zh": "关键角色与职责"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Respond",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Map legal, IT, security, facilities, communications, HR, responders, analysts, business/data owners, privacy, executives and relevant third parties to scenario-specific responsibilities, authority, backup and conflicts. A generic RACI with unstaffed cells is not operational.",
          "zh": "把法务、IT、安全、设施、公关、HR、响应/分析、业务/数据所有者、隐私、高层和相关第三方映射到场景责任、权限、备份和冲突；空 RACI 不可运营。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Assign named role holders and backups, train them, provision least required emergency access, define decision/escalation and external interfaces, and review annually plus on personnel/provider/structure change. Use role accounts/contact paths that survive ordinary identity failure.",
          "zh": "指定具名主备，培训并给最小应急访问，定义决策/升级和外部接口，每年及人员/服务商/结构变化时更新；用能在普通身份故障时存活的角色账户/联系路径。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "One person may hold several roles in a small organization, but conflicting duties and overload need backup. Navigator omits “relevant third parties” while the core guide/CAS include them, so the source snapshot matters. Naming a provider does not assign enterprise legal/business decisions.",
          "zh": "小组织一人可兼多角，但冲突/过载需备份。Navigator 漏“相关第三方”，核心指南/CAS 有，说明来源快照重要。写供应商不等于把企业法律/业务决定交出去。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Tabletop ransomware, data breach, insider and physical/provider scenarios and require each role to make its decision and handoff. Verify access and coverage after-hours; compare HR, on-call, vendor and plan records and close unmapped responsibilities.",
          "zh": "桌演勒索、数据泄露、内部人、物理/服务商场景，让各角色做真实决定/交接；验证下班访问与覆盖，对比 HR、值班、厂商、计划并补空责任。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "17.5",
          "control": 17,
          "title": {
            "en": "Assign Key Roles and Responsibilities",
            "zh": "关键角色与职责"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls17/",
          "snapshot_sha256": "A6DCCA0952C7F7B3C5FD75C759EA550966B498275E2E955D804B3D61D116E575",
          "retrieved_at": "2026-07-30T16:26:04.625Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-17.6",
      "safeguard_id": "17.6",
      "control": 17,
      "title": {
        "en": "Define Mechanisms for Communicating During Incident Response",
        "zh": "事件期间通信机制"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Respond",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Primary and secondary mechanisms must serve responders, leadership, workforce, customers, providers and regulators as relevant, assuming corporate email/chat/identity or networks may be compromised. Separate confidential coordination, broad notification and evidentiary records.",
          "zh": "主、备通信要服务相关响应者、领导、员工、客户、服务商和监管，并假设企业邮件/聊天/身份/网络会失陷；分开机密协同、广泛通知和证据记录。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Preconfigure out-of-band phone/chat/bridge or alternate tenant, authenticate participants, protect distribution lists/templates, define approval and record custody, and review annually/change. Store minimum offline access and test capacity/privacy before an incident.",
          "zh": "预配 OOB 电话/聊天/Bridge 或备用租户，认证参与人，保护通讯录/模板，定义批准和记录保管，每年/变化时更新；离线留最低访问并提前测容量/隐私。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Consumer apps may violate retention/privacy and phone trees can be slow or spoofed. A secondary account dependent on the same IdP is not independent. Public statements and regulatory notices require authorized facts; responders still need a fast channel for uncertain working hypotheses.",
          "zh": "消费 App 可能不符保留/隐私，电话树又慢且可伪造。依赖同一 IdP 的“备用”不独立。公开声明和监管通知需授权事实；响应内部仍需快速交流未确认假设。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Disable the primary channel in an exercise, activate the secondary, verify identity, access, participant capacity, confidentiality, decision logging and message approval. Test external notification drafting and transition back without losing the record.",
          "zh": "演练关闭主通道，启动备通道，验证身份、访问、容量、机密、决定记录和消息批准；测试外部通知草拟与切回且不丢记录。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "17.6",
          "control": 17,
          "title": {
            "en": "Define Mechanisms for Communicating During Incident Response",
            "zh": "事件期间通信机制"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls17/",
          "snapshot_sha256": "A6DCCA0952C7F7B3C5FD75C759EA550966B498275E2E955D804B3D61D116E575",
          "retrieved_at": "2026-07-30T16:26:04.625Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-17.7",
      "safeguard_id": "17.7",
      "control": 17,
      "title": {
        "en": "Conduct Routine Incident Response Exercises",
        "zh": "常态化响应演练"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Recover",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Exercises at least annually should test communications, decisions and workflows with key personnel, and rotate realistic scenarios across technical, business, legal, provider and recovery boundaries. A discussion-only tabletop and a technical simulation test different capabilities.",
          "zh": "至少年度演练应让关键人员测试通信、决定和工作流，并在技术、业务、法务、服务商、恢复场景间轮换；Tabletop 与技术模拟测试不同能力。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Define objectives and no-fault rules, create injects and evidence, involve backups/providers, observe actions without scripting answers, and produce owned improvements with deadlines. Scale safely from tabletop to functional/technical drills and coordinate production impact.",
          "zh": "定目标和无责规则，设计 Inject/证据，纳入备份人员/服务商，观察真实动作而不提前给答案，形成有责任/日期的改进；从桌演安全进阶到功能/技术，并协调生产。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A yearly calendar event can pass CAS while never testing actual channels or authority. Overly secret simulations can create safety, labor or trust harm. Providers and executives who will act in reality need participation; real incidents may satisfy some objectives only if formally evaluated and gaps closed.",
          "zh": "年度日历事件可过 CAS，但可能没测通道/权力。过度保密模拟会造成安全、劳动与信任伤害。现实会参与的服务商/高层必须演；真实事件只有正式评估并关缺口时才可覆盖部分目标。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Measure paging, declaration, containment, decision, communication, and recovery times, evidence quality, handoffs, unavailable dependencies, and deviations. Include failed primary communication and ambiguous or false-positive injects; retest high-risk corrections before closure; meeting notes only record the planned action.",
          "zh": "测 Page、宣告、遏制、决策、通信、恢复时间，证据质量、交接、不可用依赖和偏离；加入主通信失败和模糊/误报，重大改进要复测，不以会议纪要关闭。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "17.7",
          "control": 17,
          "title": {
            "en": "Conduct Routine Incident Response Exercises",
            "zh": "常态化响应演练"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls17/",
          "snapshot_sha256": "A6DCCA0952C7F7B3C5FD75C759EA550966B498275E2E955D804B3D61D116E575",
          "retrieved_at": "2026-07-30T16:26:04.625Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-17.8",
      "safeguard_id": "17.8",
      "control": 17,
      "title": {
        "en": "Conduct Post-Incident Reviews",
        "zh": "事后复盘"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Recover",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Every material incident and selected near miss gets a timely, blameless review of timeline, detection, decisions, controls, impact, communications, recovery and systemic causes. Its purpose is verified improvement and recurrence reduction. Personal blame and polished chronology are outside that purpose.",
          "zh": "每个重大事件和选定 Near miss 要及时无责复盘时间线、检测、决定、控制、影响、沟通、恢复与系统根因，目标是验证改进和防复发，不是找人背锅或美化时间线。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Set review threshold/timing, preserve facts and uncertainty, include affected teams/providers, identify contributing conditions and assign prioritized actions with owners/dates. Feed changes into architecture, detections, recovery, training and risk records; leadership resolves overdue blockers.",
          "zh": "设复盘门槛/时间，保留事实与不确定，纳入相关团队/服务商，找促成条件并分配有优先、责任、日期的行动；反馈架构、检测、恢复、培训和风险，高层解逾期阻塞。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "CAS checks only whether a last review mentions lessons/actions, with no population or closure. Small/no-incident periods need exercise or near-miss learning, never an automatic pass. Legal privilege can constrain distribution; operations still need the lesson in an appropriate form. Action lists without verification are unfinished.",
          "zh": "CAS 只看上次复盘是否有经验/行动，无总体和关闭。少/无事件时用演练/Near miss 学习，不能自动过。法律特权可限制分发但不应抹运营经验；无验证的行动列表未完成。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Sample incidents from declaration to review and trace actions to implemented control and a retest or outcome. Compare recurrence and detection/recovery changes; verify assumptions and disputed facts are labelled, and sensitive/legal material has proper access.",
          "zh": "抽样从宣告追到复盘，把行动追到已实现控制和复测/结果；比较复发、检测/恢复变化，确认假设/争议已标识，敏感/法律材料访问合适。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "17.8",
          "control": 17,
          "title": {
            "en": "Conduct Post-Incident Reviews",
            "zh": "事后复盘"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls17/",
          "snapshot_sha256": "A6DCCA0952C7F7B3C5FD75C759EA550966B498275E2E955D804B3D61D116E575",
          "retrieved_at": "2026-07-30T16:26:04.625Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-17.9",
      "safeguard_id": "17.9",
      "control": 17,
      "title": {
        "en": "Establish and Maintain Security Incident Thresholds",
        "zh": "事件阈值与分级"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Recover",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Thresholds distinguish observable events, alerts, cases, incidents, privacy breaches and crises; prioritize known/potential impact and drive declaration, status frequency, escalation, containment authority and notification assessment. They cover confidentiality, integrity, availability, safety, fraud and provider scenarios.",
          "zh": "阈值区分 Event、Alert、Case、Incident、隐私 Breach 和 Crisis，按已知/潜在影响排序，并驱动宣告、状态频率、升级、遏制权和通知评估，覆盖机密、完整、可用、安全、欺诈和服务商。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Define qualitative/quantitative triggers with decision owners and override, map them to playbooks/SLAs and review annually plus on incidents, regulations, threats or business change. Preserve uncertainty and allow escalation before exact impact is known.",
          "zh": "定义定性/定量 Trigger、决策责任与 Override，映射 Playbook/SLA，每年及事件、法规、威胁、业务变化时更新；允许在影响未精确前升级并保留不确定。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "Rigid record counts can underreact to high-impact single cases and overreact to harmless volume. Regulatory “breach” and operational “incident” definitions differ. CAS document completeness establishes that thresholds are written; timely decision quality requires scenario and incident evidence. Automation may recommend, while accountable humans handle consequential ambiguity.",
          "zh": "死板记录数会漏掉单个高后果事件，也会放大无害数量。法规中的“泄露”和运营中的“事件”定义不同。CAS 文档完整度只建立阈值已写明；及时决策质量需要场景演练与真实事件证据。自动化可以提出建议，后果性模糊仍由具名责任人处理。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Give independent responders ambiguous scenarios and compare classification, actions and communications; inject growing impact and verify escalation/status changes. Review real cases near thresholds for delay, over-declaration and inconsistent treatment, then calibrate.",
          "zh": "给独立响应者模糊场景，比较分类/动作/通信；逐步扩大影响验证升级和状态频率，复查临界真实案件的延迟、过度宣告和不一致。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "17.9",
          "control": 17,
          "title": {
            "en": "Establish and Maintain Security Incident Thresholds",
            "zh": "事件阈值与分级"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls17/",
          "snapshot_sha256": "A6DCCA0952C7F7B3C5FD75C759EA550966B498275E2E955D804B3D61D116E575",
          "retrieved_at": "2026-07-30T16:26:04.625Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-18.1",
      "safeguard_id": "18.1",
      "control": 18,
      "title": {
        "en": "Establish and Maintain a Penetration Testing Program",
        "zh": "渗透测试计划"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "The program covers network, web/mobile applications, APIs, cloud/hosted services, identity, wireless, physical and social or provider surfaces according to risk, size and maturity. It defines cadence/change triggers, scope inventory, clear/opaque knowledge, attack limits, contacts, evidence, remediation, validation and retrospective.",
          "zh": "计划按规模、复杂度、行业和成熟度覆盖网络、Web/移动、API、云/托管、身份、无线、物理、社工或服务商面，定义周期/变更触发、范围台账、透明度、攻击限制、联系人、证据、修复、验证和复盘。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Assign an independent program owner, qualified testers, written authorization and safe rules, production coordination, data handling and emergency stop. Rotate adversary objectives and paths, link findings to remediation/root cause and review the program annually and after material change/test.",
          "zh": "指定独立计划负责人和合格测试者，书面授权与安全规则、生产协调、数据处理和急停；轮换对手目标/路径，把发现接修复/RCA，每年及重大变化/测试后更新。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "A report bought for compliance can repeat the same narrow scope. Exclusions may be necessary but carry explicit residual risk and alternate validation. Bug bounty, scanner and red-team work can contribute but differ in authorization, objectives and coverage; none proves absence of exploitable paths.",
          "zh": "为合规买的报告可能年年窄范围。排除可必要，但需剩余风险和替代验证。Bug bounty、扫描、Red team 可贡献但授权/目标/覆盖不同，谁都不能证明无可利用路径。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Select tests over a multi-year cycle and trace critical attack surfaces and changes to coverage; run a rules-of-engagement tabletop including outage, discovered active compromise and out-of-scope pivot. Inspect tester qualifications, evidence custody, limitations and finding closure.",
          "zh": "从多年测试周期把关键攻击面/变化追到覆盖，桌演 Rules of Engagement 中停机、发现真实入侵和越界 Pivot；检查资质、证据保管、限制和发现关闭。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "18.1",
          "control": 18,
          "title": {
            "en": "Establish and Maintain a Penetration Testing Program",
            "zh": "渗透测试计划"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls18/",
          "snapshot_sha256": "AA6508DA60A7DA98047C8EE9E1D8B688F97A3668EE857F585E9B87511299F62A",
          "retrieved_at": "2026-07-30T16:26:16.590Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-18.2",
      "safeguard_id": "18.2",
      "control": 18,
      "title": {
        "en": "Perform Periodic External Penetration Tests",
        "zh": "周期性外部渗透测试"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "At least annually, test the enterprise from outside using reconnaissance that includes public infrastructure, domains, cloud, applications/APIs, credentials/leaks and environmental information within authorization. Scope follows actual exposure, not last year's IP list, and includes clear- or opaque-box methods.",
          "zh": "至少年度从外部测试，侦察公开基础设施、域名、云、应用/API、凭据泄露和环境信息，范围跟真实暴露而非去年 IP 表；可 Clear-box 或 Opaque-box。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Use a qualified independent party, freeze and verify targets/contacts, define safe proof and stop rules, test discovery through exploit chains and business impact, and coordinate without over-whitelisting defenses. Trigger additional work after major exposure or architecture changes.",
          "zh": "用合格独立方，冻结并核对目标/联系人，定义安全证明/急停，测试从发现到利用链和业务影响，不要过度 Whitelist 防守；重大暴露/架构变化后追加。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "CAS checks only the report date, so a one-host scan can pass. CDNs/WAFs and provider restrictions may hide origins or constrain testing. Credentials from unrelated breaches need legal handling. Annual is a floor; external exposure changes continuously and requires ongoing discovery plus targeted testing.",
          "zh": "CAS 只看报告日期，一台主机扫描也可过。CDN/WAF 和服务商限制会隐藏 Origin/限制测试。外泄凭据需合法处理。年度是底线，持续发现加目标测试应对外暴露变化。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Compare tester reconnaissance with asset inventories, validate exploitable findings safely, test direct origin/IPv6/alternate domains and record detection/response observed. Preserve tested versions, dates, limitations and negative controls; route and retest findings.",
          "zh": "把测试者侦察与资产台账比较，安全验证可利用发现，测试直连 Origin、IPv6、替代域并记录检测/响应；保存版本、日期、限制和负控，发现路由并复测。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "18.2",
          "control": 18,
          "title": {
            "en": "Perform Periodic External Penetration Tests",
            "zh": "周期性外部渗透测试"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls18/",
          "snapshot_sha256": "AA6508DA60A7DA98047C8EE9E1D8B688F97A3668EE857F585E9B87511299F62A",
          "retrieved_at": "2026-07-30T16:26:16.590Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-18.3",
      "safeguard_id": "18.3",
      "control": 18,
      "title": {
        "en": "Remediate Penetration Test Findings",
        "zh": "渗透发现修复"
      },
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "Every penetration finding maps to affected path/assets, consequence, reproduction evidence, owner, risk-based deadline and treatment under the vulnerability process. Chained findings stay linked so fixing one step is not mistaken for removing the complete attack path.",
          "zh": "每个发现关联受影响路径/资产、后果、复现、责任人、风险到期和漏洞流程处置；串链发现保持关联，修掉一步不能误判整链消失。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Triage jointly with testers and owners, patch/redesign/configure/remove or contain, address root causes and retest the exact exploit plus normal business behavior. Time-bound exceptions state residual chain, compensating controls and expiry; track recurrence across later tests.",
          "zh": "测试者/责任人共同分诊，补丁/重设/改配/移除或遏制，处理根因，并复测准确利用与正常业务；例外写剩余链、补偿和到期，追踪后续复发。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "The CAS reverses M2/M3 meanings and its formula can reward still-unremediated findings, so it is unusable verbatim. A finding absent from the next annual report may simply be out of scope. Retest evidence requires replay of the repaired path; where destructive proof is unsafe, test the residual condition through a bounded equivalent.",
          "zh": "CAS 把 M2/M3 的已修/未修含义写反，公式反而会奖励未修，不能直接用。下次年报没出现可能只是出范围。工单关闭和扫描消失不是复测；破坏证明可限制，但剩余条件仍需安全测试。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Have the tester or independent reviewer repeat the exploit after treatment with positive controls proving the path/test still works. Verify running state and alternate paths; report verified fixed, mitigated, accepted, false-positive and overdue findings by risk and age.",
          "zh": "由测试者或独立者处理后复做利用，并用正控证明测试仍有效；核验运行状态和替代路径，分别报告验证修复、缓解、接受、误报和按风险逾期。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "18.3",
          "control": 18,
          "title": {
            "en": "Remediate Penetration Test Findings",
            "zh": "渗透发现修复"
          },
          "implementation_groups": [
            2,
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls18/",
          "snapshot_sha256": "AA6508DA60A7DA98047C8EE9E1D8B688F97A3668EE857F585E9B87511299F62A",
          "retrieved_at": "2026-07-30T16:26:16.590Z"
        },
        "cas_finding_ids": [
          "CAS-2026-07-31-040"
        ]
      }
    },
    {
      "delta_id": "DELTA-CIS-18.4",
      "safeguard_id": "18.4",
      "control": 18,
      "title": {
        "en": "Validate Security Measures",
        "zh": "验证安全措施"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "After each penetration test, evaluate whether preventive, detective and response controls observed the techniques and whether rules, telemetry, playbooks or architecture need change. This includes successful and blocked test actions; a blocked exploit can still reveal missing alerts or excessive permissions.",
          "zh": "每次渗透后核对预防、检测和响应是否看见测试技术，规则、遥测、Playbook 或架构是否要改；成功与被拦动作都要看，因为拦住也可能没告警或权限过宽。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Map tester actions and timestamps to expected controls, reconstruct visibility and response, tune or add measures through reviewed changes and preserve adversary-emulation cases for regression. Assign gaps to owners and distinguish prevention, detection, alert, triage and containment outcomes.",
          "zh": "把测试动作/时间映射预期控制，重建可见性/响应，经评审调或新增，并把对手模拟保存作回归；缺口有责任人，区分阻断、检测、告警、分诊、遏制。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "CAS counts measures marked modified but does not test that modifications work. Overfitting signatures to exact test indicators creates cosmetic success. Some tester activity is intentionally whitelisted or opaque; document those limits and run a separate unannounced/production-realistic validation when authorized.",
          "zh": "CAS 只数标为已修改的措施，不测试有效性。为测试 IOC 写死签名是表面成功。有些测试被授权 Whitelist 或不可见，需记录限制，并在授权时另做未预告/更真实验证。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Replay representative techniques and benign controls after modifications, verify intended block/detect/respond without unacceptable false positives, then monitor in production and rollback if needed. Measure addressed control gaps and validated outcomes, with empty “no change required” decisions evidenced.",
          "zh": "修改后回放代表技术和正常对照，验证预期阻断/检测/响应且误报可接受，再生产观察并可回滚；统计已解决控制缺口和验证结果，“无需改”也要证据。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "18.4",
          "control": 18,
          "title": {
            "en": "Validate Security Measures",
            "zh": "验证安全措施"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls18/",
          "snapshot_sha256": "AA6508DA60A7DA98047C8EE9E1D8B688F97A3668EE857F585E9B87511299F62A",
          "retrieved_at": "2026-07-30T16:26:16.590Z"
        },
        "cas_finding_ids": []
      }
    },
    {
      "delta_id": "DELTA-CIS-18.5",
      "safeguard_id": "18.5",
      "control": 18,
      "title": {
        "en": "Perform Periodic Internal Penetration Tests",
        "zh": "周期性内部渗透测试"
      },
      "implementation_groups": [
        3
      ],
      "asset_class": "Network",
      "security_function": "Detect",
      "fields": {
        "denominator": {
          "provenance": "sosec_analysis",
          "en": "At least annually, test from realistic internal starting points across workstation, server, identity, cloud, wireless, management and sensitive zones, including assumed breach, ordinary user and relevant privileged/contractor contexts. Scope includes lateral movement and data/object authorization, not only internal port scanning.",
          "zh": "至少年度从现实内部起点测试工作站、服务器、身份、云、无线、管理和敏感区，包括假设入侵、普通用户及相关特权/承包商情境；重点是横向和数据/对象授权，不只是内网端口扫。"
        },
        "control_point": {
          "provenance": "sosec_analysis",
          "en": "Use qualified independent testers, safe accounts/data and rules, coordinate critical/OT systems, vary knowledge level and starting points, and prevent broad defender whitelisting where the objective includes detection. Trigger targeted tests after material segmentation/identity changes.",
          "zh": "使用合格独立测试者、安全账户/数据和规则，协调关键/OT，变化知识和起点；目标含检测时避免广泛白名单，重大分段/身份变化后触发目标测试。"
        },
        "real_failure": {
          "provenance": "sosec_analysis",
          "en": "CAS again checks only test age. A test from one flat LAN or domain admin account can miss ordinary-user escalation and segmentation. Internal testing may encounter real sensitive data or active compromise, requiring stop/escalation rules; annual work and continuous control validation cover different time horizons.",
          "zh": "CAS 仍只看日期。从一个平网或 Domain Admin 起点会漏普通用户提权/分段。内部测试可能碰真实敏感数据或活跃入侵，需急停/升级；年度测试补连续控制验证，不能替代。"
        },
        "strongest_negative_test": {
          "provenance": "sosec_analysis",
          "en": "Validate paths safely through credential/privilege, lateral, trust, cloud and data boundaries; record what prevention/detection/response observed and retest findings. Include allowed business controls, test alternate routes/IPv6 and document untested high-risk systems and provider constraints.",
          "zh": "安全验证凭据/权限、横向、信任、云与数据边界，记录预防/检测/响应并复测；带允许业务正控，测试备用路由/IPv6，列未测高风险和服务商限制。"
        }
      },
      "source_boundary": {
        "provenance": "sosec_analysis",
        "official_anchor": {
          "provenance": "cis_official",
          "safeguard_id": "18.5",
          "control": 18,
          "title": {
            "en": "Perform Periodic Internal Penetration Tests",
            "zh": "周期性内部渗透测试"
          },
          "implementation_groups": [
            3
          ],
          "url": "https://cas.docs.cisecurity.org/en/latest/source/Controls18/",
          "snapshot_sha256": "AA6508DA60A7DA98047C8EE9E1D8B688F97A3668EE857F585E9B87511299F62A",
          "retrieved_at": "2026-07-30T16:26:16.590Z"
        },
        "cas_finding_ids": []
      }
    }
  ],
  "cas_findings_reference": {
    "path": "/static/research/cis-controls-v8-1-cas-findings-july-2026-v2.json",
    "schema": "/static/research/cis-controls-v8-1-cas-findings-schema-july-2026-v2.json",
    "sha256": "1989247C85C237A0621867EFB3E937AF1F86E42661CAAB4BFD621C1616EBC453",
    "schema_sha256": "030C5BB6292538187B620155E4875F9B45536CE29A4630868505920AB6D4B1F2",
    "finding_count": 40,
    "finding_ids": [
      "CAS-2026-07-31-001",
      "CAS-2026-07-31-002",
      "CAS-2026-07-31-003",
      "CAS-2026-07-31-004",
      "CAS-2026-07-31-005",
      "CAS-2026-07-31-006",
      "CAS-2026-07-31-007",
      "CAS-2026-07-31-008",
      "CAS-2026-07-31-009",
      "CAS-2026-07-31-010",
      "CAS-2026-07-31-011",
      "CAS-2026-07-31-012",
      "CAS-2026-07-31-013",
      "CAS-2026-07-31-014",
      "CAS-2026-07-31-015",
      "CAS-2026-07-31-016",
      "CAS-2026-07-31-017",
      "CAS-2026-07-31-018",
      "CAS-2026-07-31-019",
      "CAS-2026-07-31-020",
      "CAS-2026-07-31-021",
      "CAS-2026-07-31-022",
      "CAS-2026-07-31-023",
      "CAS-2026-07-31-024",
      "CAS-2026-07-31-025",
      "CAS-2026-07-31-026",
      "CAS-2026-07-31-027",
      "CAS-2026-07-31-028",
      "CAS-2026-07-31-029",
      "CAS-2026-07-31-030",
      "CAS-2026-07-31-031",
      "CAS-2026-07-31-032",
      "CAS-2026-07-31-033",
      "CAS-2026-07-31-034",
      "CAS-2026-07-31-035",
      "CAS-2026-07-31-036",
      "CAS-2026-07-31-037",
      "CAS-2026-07-31-038",
      "CAS-2026-07-31-039",
      "CAS-2026-07-31-040"
    ]
  },
  "reference_product_prds": [
    {
      "prd_id": "PRD-CIS-1.1-ASSET-AUTHORITY",
      "safeguard_id": "1.1",
      "name": {
        "en": "Cloud and endpoint asset authority",
        "zh": "云与终端资产权威台账"
      },
      "provenance": "example_local_solution",
      "scenario": {
        "en": "Security operations needs one traceable population across AWS EC2, Google Compute Engine, and EDR-managed servers and endpoints so source outages, aliases, duplicates, and disappearing observations cannot remove unknown assets from coverage.",
        "zh": "安全运营需要把 AWS EC2、Google Compute Engine 与 EDR 管理的服务器和终端合并成一个可追溯总体，使来源中断、别名、重复和观测消失不会把未知资产移出覆盖分母。"
      },
      "users": [
        {
          "en": "Security operations analyst",
          "zh": "安全运营分析员"
        },
        {
          "en": "Cloud platform administrator",
          "zh": "云平台管理员"
        },
        {
          "en": "Asset owner",
          "zh": "资产责任人"
        },
        {
          "en": "Evidence reviewer",
          "zh": "合规证据复核人员"
        }
      ],
      "goals": [
        {
          "en": "Discover, normalize, own, authorize, and retire assets without losing source lineage.",
          "zh": "在不丢失来源谱系的前提下发现、归一、认领、授权与退役资产。"
        },
        {
          "en": "Keep stale-source assets visible and mark coverage unevaluable instead of green.",
          "zh": "来源陈旧时仍保留资产，并把覆盖标为无法评估而非绿色通过。"
        }
      ],
      "scope": {
        "included": [
          {
            "en": "AWS EC2 instances in enrolled organizations and accounts",
            "zh": "已接入组织与账号中的 AWS EC2 实例"
          },
          {
            "en": "Google Compute Engine instances in enrolled organizations and projects",
            "zh": "已接入组织与项目中的 Google Compute Engine 实例"
          },
          {
            "en": "Servers and endpoints observed by enrolled EDR tenants",
            "zh": "已接入 EDR 租户观测的服务器与终端"
          },
          {
            "en": "Discovery, normalization, ownership, authorization, disposition, and retirement workflow",
            "zh": "发现、归一、认领、授权、处置与退役工作流"
          }
        ],
        "excluded": [
          {
            "en": "Pure SaaS tenants",
            "zh": "纯 SaaS 租户"
          },
          {
            "en": "Automatic deletion of cloud resources",
            "zh": "自动删除云资源"
          },
          {
            "en": "Replacement of procurement and finance ledgers",
            "zh": "替代采购与财务台账"
          }
        ]
      },
      "identity_contract": {
        "natural_key": "provider + organization_or_account_id + region + native_resource_id",
        "merge_rule": {
          "en": "Cloud-native identity is authoritative for cloud objects; EDR observations link by provider ID when present, then by an approved confidence-scored alias. Ambiguous aliases create a conflict and never auto-merge.",
          "zh": "云对象以云原生身份为权威；EDR 观测优先按 provider ID 关联，缺失时使用经批准且带置信度的别名。歧义别名进入冲突状态，禁止自动合并。"
        }
      },
      "data_model": [
        {
          "field": "asset_id",
          "type": "uuid",
          "required": true,
          "source": {
            "en": "system",
            "zh": "系统"
          },
          "lifecycle": {
            "en": "immutable",
            "zh": "不可变"
          }
        },
        {
          "field": "provider",
          "type": "enum(aws,gcp,edr)",
          "required": true,
          "source": {
            "en": "connector",
            "zh": "连接器"
          },
          "lifecycle": {
            "en": "immutable per source record",
            "zh": "每条来源记录内不可变"
          }
        },
        {
          "field": "account_or_project_id",
          "type": "string",
          "required": true,
          "source": {
            "en": "connector",
            "zh": "连接器"
          },
          "lifecycle": {
            "en": "versioned",
            "zh": "版本化"
          }
        },
        {
          "field": "region",
          "type": "string",
          "required": true,
          "source": {
            "en": "connector",
            "zh": "连接器"
          },
          "lifecycle": {
            "en": "versioned",
            "zh": "版本化"
          }
        },
        {
          "field": "native_resource_id",
          "type": "string",
          "required": true,
          "source": {
            "en": "connector",
            "zh": "连接器"
          },
          "lifecycle": {
            "en": "immutable",
            "zh": "不可变"
          }
        },
        {
          "field": "asset_type",
          "type": "string",
          "required": true,
          "source": {
            "en": "connector",
            "zh": "连接器"
          },
          "lifecycle": {
            "en": "versioned",
            "zh": "版本化"
          }
        },
        {
          "field": "owner_id",
          "type": "principal_id|null",
          "required": true,
          "source": {
            "en": "owner workflow",
            "zh": "责任人工作流"
          },
          "lifecycle": {
            "en": "audited",
            "zh": "可审计变更"
          }
        },
        {
          "field": "approval_status",
          "type": "enum(pending,approved,unauthorized,revoked)",
          "required": true,
          "source": {
            "en": "owner decision",
            "zh": "责任人决定"
          },
          "lifecycle": {
            "en": "state history",
            "zh": "状态历史"
          }
        },
        {
          "field": "lifecycle_status",
          "type": "enum(observed,active,source_conflict,stale,retirement_pending,retired)",
          "required": true,
          "source": {
            "en": "state machine",
            "zh": "状态机"
          },
          "lifecycle": {
            "en": "state history",
            "zh": "状态历史"
          }
        },
        {
          "field": "first_seen_at",
          "type": "timestamp",
          "required": true,
          "source": {
            "en": "connector",
            "zh": "连接器"
          },
          "lifecycle": {
            "en": "immutable minimum",
            "zh": "以最早值为准，仅可向前修正"
          }
        },
        {
          "field": "last_seen_at",
          "type": "timestamp",
          "required": true,
          "source": {
            "en": "connector",
            "zh": "连接器"
          },
          "lifecycle": {
            "en": "monotonic maximum",
            "zh": "单调递增的最大值"
          }
        },
        {
          "field": "source_health",
          "type": "enum(healthy,partial,failed,stale)",
          "required": true,
          "source": {
            "en": "connector health",
            "zh": "连接器健康探测"
          },
          "lifecycle": {
            "en": "time series",
            "zh": "时间序列"
          }
        },
        {
          "field": "source_records",
          "type": "array<source_record_ref>",
          "required": true,
          "source": {
            "en": "connectors",
            "zh": "连接器"
          },
          "lifecycle": {
            "en": "append-only lineage",
            "zh": "仅追加谱系"
          }
        }
      ],
      "states": [
        {
          "id": "observed",
          "definition": {
            "en": "Seen by at least one healthy source and awaiting normalization or ownership.",
            "zh": "至少被一个健康来源观测，等待归一或认领。"
          }
        },
        {
          "id": "active",
          "definition": {
            "en": "Stable identity, accountable owner, and current approval decision exist.",
            "zh": "已有稳定身份、责任人和当前批准决定。"
          }
        },
        {
          "id": "source_conflict",
          "definition": {
            "en": "Authoritative sources disagree on identity or lifecycle; the record remains in coverage.",
            "zh": "权威来源对身份或生命周期存在冲突；记录仍留在覆盖总体。"
          }
        },
        {
          "id": "stale",
          "definition": {
            "en": "No fresh observation exists because the source or evidence clock expired; compliance is unevaluable.",
            "zh": "因来源或证据时钟过期而缺少新鲜观测；合规状态无法评估。"
          }
        },
        {
          "id": "retirement_pending",
          "definition": {
            "en": "A retirement request exists but final lifecycle evidence is incomplete.",
            "zh": "已有退役请求但最终生命周期证据不完整。"
          }
        },
        {
          "id": "retired",
          "definition": {
            "en": "Approved retirement evidence exists; the record leaves active coverage but remains auditable.",
            "zh": "已有批准的退役证据；记录退出当前总体但继续可审计。"
          }
        }
      ],
      "transitions": [
        {
          "from": "observed",
          "event": "owner_approved",
          "to": "active",
          "guard": {
            "en": "stable identity and approval decision present",
            "zh": "已有稳定身份与批准决定"
          }
        },
        {
          "from": "observed|active",
          "event": "source_conflict_detected",
          "to": "source_conflict",
          "guard": {
            "en": "conflicting authoritative fields",
            "zh": "权威字段互相冲突"
          }
        },
        {
          "from": "observed|active|source_conflict",
          "event": "freshness_expired",
          "to": "stale",
          "guard": {
            "en": "no healthy source within local SLO",
            "zh": "本地 SLO 内没有健康来源"
          }
        },
        {
          "from": "stale|source_conflict",
          "event": "fresh_reconciliation_passed",
          "to": "active",
          "guard": {
            "en": "identity and owner decision valid",
            "zh": "身份与责任人决定仍有效"
          }
        },
        {
          "from": "active|stale",
          "event": "retirement_requested",
          "to": "retirement_pending",
          "guard": {
            "en": "requester authorized",
            "zh": "请求人具有相应权限"
          }
        },
        {
          "from": "retirement_pending",
          "event": "retirement_evidence_approved",
          "to": "retired",
          "guard": {
            "en": "cloud deletion, owner attestation, or approved lifecycle evidence",
            "zh": "已有云资源删除、责任人证明或经批准的生命周期证据"
          }
        }
      ],
      "functional_rules": [
        {
          "id": "A-01",
          "text": {
            "en": "Poll or receive events from every enrolled AWS, GCP, and EDR source on its approved schedule and persist connector cursor plus page completeness.",
            "zh": "按批准周期轮询或接收每个 AWS、GCP 和 EDR 来源事件，并保存连接器游标与分页完整性。"
          }
        },
        {
          "id": "A-02",
          "text": {
            "en": "Merge multi-source observations into one asset only when the identity rule resolves uniquely; preserve every source record.",
            "zh": "仅当身份规则唯一解析时才把多源观测合并为一项资产，并保留全部来源记录。"
          }
        },
        {
          "id": "A-03",
          "text": {
            "en": "Place newly discovered ownerless assets in observed and open an ownership task.",
            "zh": "新发现且无责任人的资产进入 observed，并创建认领任务。"
          }
        },
        {
          "id": "A-04",
          "text": {
            "en": "Place unapproved assets in the disposition queue and do not close them because a later scan is silent.",
            "zh": "未批准资产进入处置队列，后续扫描沉默不能自动结案。"
          }
        },
        {
          "id": "A-05",
          "text": {
            "en": "On connector failure, retain associated assets in the denominator and mark source health and coverage unevaluable.",
            "zh": "连接器失败时，保留关联资产在分母中，并把来源健康与覆盖标为无法评估。"
          }
        },
        {
          "id": "A-06",
          "text": {
            "en": "Reject an incomplete API page from replacing the last complete generation.",
            "zh": "API 分页不完整时，禁止覆盖上一轮完整代。"
          }
        },
        {
          "id": "A-07",
          "text": {
            "en": "Record actor, time, reason, old value, new value, and correlation ID for merge, ownership, approval, disposition, and retirement changes.",
            "zh": "合并、认领、批准、处置和退役变更均记录操作者、时间、原因、旧值、新值与关联 ID。"
          }
        }
      ],
      "exception_paths": [
        {
          "id": "AX-01",
          "text": {
            "en": "Credential failure raises source-health alert, freezes destructive reconciliation, and retains the last complete population.",
            "zh": "凭据失效触发来源健康告警，冻结破坏性对账，并保留上一轮完整总体。"
          }
        },
        {
          "id": "AX-02",
          "text": {
            "en": "Conflicting source state routes to source_conflict; neither source silently wins.",
            "zh": "来源状态冲突进入 source_conflict，不允许任何来源静默胜出。"
          }
        },
        {
          "id": "AX-03",
          "text": {
            "en": "Unparseable records enter a dead-letter queue with source identity and parser version; they remain in an unknown-count metric.",
            "zh": "无法解析的记录进入带来源身份和解析器版本的错误队列，并保留在未知数量指标中。"
          }
        },
        {
          "id": "AX-04",
          "text": {
            "en": "Retries use source event identity and upsert semantics, preventing duplicate assets and duplicate disposition tickets.",
            "zh": "重试使用来源事件身份与幂等更新语义，防止重复资产和重复处置工单。"
          }
        }
      ],
      "permissions_and_audit": {
        "roles": [
          {
            "role": "connector_operator",
            "actions": [
              {
                "en": "rotate credential",
                "zh": "轮换凭据"
              },
              {
                "en": "replay sync",
                "zh": "重放同步"
              }
            ],
            "separation": {
              "en": "cannot approve assets",
              "zh": "不得批准资产"
            }
          },
          {
            "role": "asset_owner",
            "actions": [
              {
                "en": "claim asset",
                "zh": "认领资产"
              },
              {
                "en": "request approval",
                "zh": "申请批准"
              },
              {
                "en": "request retirement",
                "zh": "申请退役"
              }
            ],
            "separation": {
              "en": "cannot erase audit history",
              "zh": "不得删除审计历史"
            }
          },
          {
            "role": "security_operator",
            "actions": [
              {
                "en": "mark unauthorized",
                "zh": "标记为未授权"
              },
              {
                "en": "open disposition",
                "zh": "创建处置事项"
              },
              {
                "en": "quarantine request",
                "zh": "提交隔离请求"
              }
            ],
            "separation": {
              "en": "cannot approve own exception",
              "zh": "不得批准本人提交的例外"
            }
          },
          {
            "role": "evidence_reviewer",
            "actions": [
              {
                "en": "view lineage",
                "zh": "查看来源谱系"
              },
              {
                "en": "approve retirement evidence",
                "zh": "批准退役证据"
              }
            ],
            "separation": {
              "en": "read-only source records",
              "zh": "来源记录只读"
            }
          }
        ],
        "audit_fields": [
          "actor_id",
          "action",
          "object_id",
          "old_value",
          "new_value",
          "reason",
          "occurred_at",
          "correlation_id",
          "policy_version"
        ]
      },
      "nfr": [
        {
          "id": "ANFR-01",
          "category": "latency",
          "text": {
            "en": "P95 source event to normalized record is within the locally approved discovery SLO; breach is observable.",
            "zh": "来源事件到归一记录的 P95 延迟符合本地批准的发现 SLO，超时可观测。"
          }
        },
        {
          "id": "ANFR-02",
          "category": "availability",
          "text": {
            "en": "A connector outage cannot delete assets or replace a complete generation with a partial one.",
            "zh": "连接器中断不能删除资产，也不能用部分代覆盖完整代。"
          }
        },
        {
          "id": "ANFR-03",
          "category": "security",
          "text": {
            "en": "Connector credentials are least-privilege, encrypted, rotated, and never present in exported evidence.",
            "zh": "连接器凭据最小权限、加密、轮换，且不进入导出证据。"
          }
        },
        {
          "id": "ANFR-04",
          "category": "capacity",
          "text": {
            "en": "Ingestion remains idempotent at the approved peak asset and event volume with a documented back-pressure path.",
            "zh": "在批准的资产与事件峰值下保持幂等，并有明确背压路径。"
          }
        },
        {
          "id": "ANFR-05",
          "category": "retention",
          "text": {
            "en": "State and audit history remain searchable for the organization retention period after retirement.",
            "zh": "资产退役后，状态与审计历史在组织保留期内仍可检索。"
          }
        }
      ],
      "acceptance_criteria": [
        {
          "id": "AAC-01",
          "text": {
            "en": "Creating one test cloud instance produces exactly one asset within the approved SLO.",
            "zh": "创建一个测试云实例后，在批准 SLO 内只生成一项资产。"
          }
        },
        {
          "id": "AAC-02",
          "text": {
            "en": "The same instance observed by cloud API and EDR appears once and exposes both source records.",
            "zh": "同一实例被云 API 与 EDR 观测时只出现一次，并可查看两条来源记录。"
          }
        },
        {
          "id": "AAC-03",
          "text": {
            "en": "Disabling one connector retains existing assets and changes coverage to source unhealthy or unevaluable.",
            "zh": "停用一个连接器后保留既有资产，并把覆盖状态改为来源异常或无法评估。"
          }
        },
        {
          "id": "AAC-04",
          "text": {
            "en": "An unauthorized test instance opens disposition work with its discovery source.",
            "zh": "未授权测试实例会生成带发现来源的处置事项。"
          }
        },
        {
          "id": "AAC-05",
          "text": {
            "en": "Silence after stop or deletion cannot close disposition without approved retirement evidence.",
            "zh": "实例停止或删除后的观测沉默不能在缺少批准退役证据时结案。"
          }
        },
        {
          "id": "AAC-06",
          "text": {
            "en": "Changing the owner produces an audit record that reconstructs actor, old value, new value, time, and reason.",
            "zh": "修改责任人后，审计记录可还原操作者、旧值、新值、时间与原因。"
          }
        }
      ],
      "release_and_rollback": {
        "migration": {
          "en": "Import source records in shadow mode, calculate identity conflicts, obtain owner sign-off, then make the new authority the coverage denominator.",
          "zh": "先以影子模式导入来源记录并计算身份冲突，责任人签字后再让新台账成为覆盖分母。"
        },
        "phases": [
          {
            "en": "Shadow ingestion and reconciliation",
            "zh": "影子采集与对账"
          },
          {
            "en": "Read-only owner review",
            "zh": "只读责任人复核"
          },
          {
            "en": "Disposition workflow enablement",
            "zh": "启用处置流程"
          },
          {
            "en": "Coverage cutover",
            "zh": "覆盖分母切换"
          }
        ],
        "monitoring": [
          {
            "en": "connector freshness",
            "zh": "连接器新鲜度"
          },
          {
            "en": "partial-page rejection",
            "zh": "不完整分页拒绝"
          },
          {
            "en": "identity conflict rate",
            "zh": "身份冲突率"
          },
          {
            "en": "ownerless age",
            "zh": "无责任人资产时长"
          },
          {
            "en": "unauthorized disposition age",
            "zh": "未授权资产处置时长"
          },
          {
            "en": "audit write failure",
            "zh": "审计写入失败"
          }
        ],
        "rollback_triggers": [
          {
            "en": "Duplicate or conflict rate exceeds the locally approved ceiling.",
            "zh": "重复或冲突率超过本地批准上限。"
          },
          {
            "en": "A partial generation replaces or removes a previously known asset.",
            "zh": "部分代覆盖或删除已知资产。"
          },
          {
            "en": "Audit writes fail for a state-changing action.",
            "zh": "状态变更操作的审计写入失败。"
          }
        ],
        "rollback": {
          "en": "Freeze state changes, restore the last complete generation as read authority, keep all new source events in an append-only queue, and reopen cutover only after replay passes.",
          "zh": "冻结状态变更，恢复上一完整代为读取权威，把所有新来源事件保存在追加队列；重放通过后才重新切换。"
        },
        "decommission": {
          "en": "Retire legacy spreadsheets only after two complete reconciliation cycles and export their immutable mapping to the new asset IDs.",
          "zh": "完成两个完整对账周期并把旧记录不可变映射到新 asset_id 后，才退役旧表格。"
        }
      }
    },
    {
      "prd_id": "PRD-CIS-4.1-CONFIG-BASELINE",
      "safeguard_id": "4.1",
      "name": {
        "en": "Versioned secure-configuration baseline service",
        "zh": "版本化安全配置基线服务"
      },
      "provenance": "example_local_solution",
      "scenario": {
        "en": "Platform owners need a reviewable service that turns a pinned hardening source into platform- and role-specific settings, deploys them safely, observes effective state, and manages time-bounded deviations without treating a benchmark name as implementation.",
        "zh": "平台责任人需要一个可评审服务，把固定的加固来源转换成特定平台与角色的设置，安全部署、观测有效状态，并管理会到期的偏差，避免把 Benchmark 名称当成已经实施。"
      },
      "users": [
        {
          "en": "Platform baseline author",
          "zh": "平台基线作者"
        },
        {
          "en": "Application or service owner",
          "zh": "应用或服务责任人"
        },
        {
          "en": "Security approver",
          "zh": "安全批准人"
        },
        {
          "en": "Change and incident operator",
          "zh": "变更与事件操作员"
        }
      ],
      "goals": [
        {
          "en": "Produce one immutable baseline version for each supported platform, version, role, and environment.",
          "zh": "为每个受支持的平台、版本、角色与环境生成一个不可变基线版本。"
        },
        {
          "en": "Separate intended policy, deployed policy, effective state, exception, and verification evidence.",
          "zh": "分开意图策略、已部署策略、有效状态、例外和验证证据。"
        }
      ],
      "scope": {
        "included": [
          {
            "en": "Managed operating systems, container base images, cloud resources, and tenant-configurable SaaS settings selected by the owner",
            "zh": "责任人选定的受管操作系统、容器基础镜像、云资源与租户可配 SaaS 设置"
          },
          {
            "en": "Baseline authoring, approval, canary, deployment, drift, exception, rollback, and retirement",
            "zh": "基线编写、批准、金丝雀、部署、漂移、例外、回滚与退役"
          }
        ],
        "excluded": [
          {
            "en": "Automatic adoption of every setting in a CIS Benchmark",
            "zh": "自动采用 CIS Benchmark 的全部设置"
          },
          {
            "en": "Unsupported products without an enforceable or observable setting plane",
            "zh": "缺少可执行或可观测设置面的不支持产品"
          },
          {
            "en": "Replacing application functional testing",
            "zh": "替代应用功能测试"
          }
        ]
      },
      "identity_contract": {
        "natural_key": "platform_family + platform_version_range + role + environment + baseline_version",
        "merge_rule": {
          "en": "Published baseline versions are immutable. A change creates a new version linked to its source and decision; effective-state evidence always references the exact version.",
          "zh": "已发布基线版本不可变；变更创建带来源与决定的新版本，有效状态证据始终引用准确版本。"
        }
      },
      "data_model": [
        {
          "field": "baseline_id",
          "type": "uuid",
          "required": true,
          "source": {
            "en": "system",
            "zh": "系统"
          },
          "lifecycle": {
            "en": "immutable",
            "zh": "不可变"
          }
        },
        {
          "field": "platform_family",
          "type": "string",
          "required": true,
          "source": {
            "en": "author",
            "zh": "编写人员"
          },
          "lifecycle": {
            "en": "versioned",
            "zh": "版本化"
          }
        },
        {
          "field": "platform_version_range",
          "type": "semver_or_vendor_range",
          "required": true,
          "source": {
            "en": "author",
            "zh": "编写人员"
          },
          "lifecycle": {
            "en": "versioned",
            "zh": "版本化"
          }
        },
        {
          "field": "role",
          "type": "string",
          "required": true,
          "source": {
            "en": "service catalog",
            "zh": "服务目录"
          },
          "lifecycle": {
            "en": "versioned",
            "zh": "版本化"
          }
        },
        {
          "field": "environment",
          "type": "enum(dev,test,stage,prod,other)",
          "required": true,
          "source": {
            "en": "asset authority",
            "zh": "资产权威台账"
          },
          "lifecycle": {
            "en": "versioned",
            "zh": "版本化"
          }
        },
        {
          "field": "source_refs",
          "type": "array<url+version+sha256>",
          "required": true,
          "source": {
            "en": "official or vendor source",
            "zh": "官方或供应商来源"
          },
          "lifecycle": {
            "en": "immutable per version",
            "zh": "每个版本内不可变"
          }
        },
        {
          "field": "settings",
          "type": "array<setting_id,value,rationale,severity,rollback>",
          "required": true,
          "source": {
            "en": "author and review",
            "zh": "编写与评审"
          },
          "lifecycle": {
            "en": "immutable per version",
            "zh": "每个版本内不可变"
          }
        },
        {
          "field": "approval",
          "type": "principal+time+decision",
          "required": true,
          "source": {
            "en": "workflow",
            "zh": "工作流"
          },
          "lifecycle": {
            "en": "append-only",
            "zh": "仅追加"
          }
        },
        {
          "field": "deployment_state",
          "type": "enum(draft,review,canary,approved,deploying,active,superseded,rolled_back)",
          "required": true,
          "source": {
            "en": "state machine",
            "zh": "状态机"
          },
          "lifecycle": {
            "en": "history",
            "zh": "历史记录"
          }
        },
        {
          "field": "effective_state_receipt",
          "type": "policy+asset+collector+time+result",
          "required": true,
          "source": {
            "en": "evaluator",
            "zh": "评估器"
          },
          "lifecycle": {
            "en": "time series",
            "zh": "时间序列"
          }
        },
        {
          "field": "exception_ref",
          "type": "exception_id|null",
          "required": true,
          "source": {
            "en": "exception service",
            "zh": "例外服务"
          },
          "lifecycle": {
            "en": "expiring",
            "zh": "到期失效"
          }
        }
      ],
      "states": [
        {
          "id": "draft",
          "definition": {
            "en": "Editable settings with pinned source but no deployment authority.",
            "zh": "已有固定来源但无部署授权的可编辑设置。"
          }
        },
        {
          "id": "review",
          "definition": {
            "en": "Security, platform, and service owners review risk, compatibility, and rollback.",
            "zh": "安全、平台与服务责任人评审风险、兼容和回滚。"
          }
        },
        {
          "id": "canary",
          "definition": {
            "en": "Approved for a bounded representative population only.",
            "zh": "仅批准用于受限代表总体。"
          }
        },
        {
          "id": "approved",
          "definition": {
            "en": "Canary acceptance and required approvals complete; rollout may start.",
            "zh": "金丝雀验收和必要批准完成，可开始发布。"
          }
        },
        {
          "id": "deploying",
          "definition": {
            "en": "Rollout in progress with per-wave health and effective-state evidence.",
            "zh": "正在分波发布，并收集每波健康与有效状态证据。"
          }
        },
        {
          "id": "active",
          "definition": {
            "en": "Current default baseline for its exact applicability tuple.",
            "zh": "该准确适用元组的当前默认基线。"
          }
        },
        {
          "id": "superseded",
          "definition": {
            "en": "A newer active version replaced it; evidence remains auditable.",
            "zh": "已被更新活动版本替代，证据继续可审计。"
          }
        },
        {
          "id": "rolled_back",
          "definition": {
            "en": "Deployment authority withdrawn and last known good version restored.",
            "zh": "部署授权撤回并恢复上一已知良好版本。"
          }
        }
      ],
      "transitions": [
        {
          "from": "draft",
          "event": "submit_review",
          "to": "review",
          "guard": {
            "en": "source refs and rollback present",
            "zh": "已有来源引用与回滚方案"
          }
        },
        {
          "from": "review",
          "event": "approve_canary",
          "to": "canary",
          "guard": {
            "en": "security, platform, service approvals",
            "zh": "安全、平台与服务责任人均已批准"
          }
        },
        {
          "from": "canary",
          "event": "acceptance_passed",
          "to": "approved",
          "guard": {
            "en": "functional and negative tests pass",
            "zh": "功能测试与反向测试均通过"
          }
        },
        {
          "from": "approved",
          "event": "start_rollout",
          "to": "deploying",
          "guard": {
            "en": "change window and monitoring ready",
            "zh": "变更窗口与监控已就绪"
          }
        },
        {
          "from": "deploying",
          "event": "all_waves_verified",
          "to": "active",
          "guard": {
            "en": "effective state and business health pass",
            "zh": "有效配置状态与业务健康检查均通过"
          }
        },
        {
          "from": "review|canary|approved|deploying|active",
          "event": "rollback_declared",
          "to": "rolled_back",
          "guard": {
            "en": "authorized trigger recorded",
            "zh": "已记录经授权的触发原因"
          }
        },
        {
          "from": "active",
          "event": "new_version_activated",
          "to": "superseded",
          "guard": {
            "en": "new version evidence complete",
            "zh": "新版本证据完整"
          }
        }
      ],
      "functional_rules": [
        {
          "id": "C-01",
          "text": {
            "en": "Each setting records source, exact value, applicability, rationale, operational risk, verification, and rollback.",
            "zh": "每项设置记录来源、准确值、适用性、理由、运营风险、验证和回滚。"
          }
        },
        {
          "id": "C-02",
          "text": {
            "en": "A benchmark profile is input evidence; the service requires explicit adopt, modify, or reject decisions per setting.",
            "zh": "Benchmark Profile 只是输入证据；服务要求逐项作出采用、修改或拒绝决定。"
          }
        },
        {
          "id": "C-03",
          "text": {
            "en": "One active baseline is allowed per applicability tuple; overlapping tuples fail publication until precedence is explicit.",
            "zh": "每个适用元组只允许一个活动基线；重叠元组在优先级明确前禁止发布。"
          }
        },
        {
          "id": "C-04",
          "text": {
            "en": "Deployment receipts bind asset, baseline version, policy-engine version, intended value, effective value, result, and observation time.",
            "zh": "部署回执绑定资产、基线版本、策略引擎版本、意图值、有效值、结果和观测时间。"
          }
        },
        {
          "id": "C-05",
          "text": {
            "en": "A drifted or unevaluable asset remains in the denominator and opens remediation or exception work.",
            "zh": "漂移或无法评估的资产继续留在分母，并创建修复或例外事项。"
          }
        },
        {
          "id": "C-06",
          "text": {
            "en": "Exceptions cannot wildcard future assets and expire into remediation or renewed owner approval.",
            "zh": "例外不能通配未来资产；到期后进入修复或重新批准。"
          }
        }
      ],
      "exception_paths": [
        {
          "id": "CX-01",
          "text": {
            "en": "Unsupported setting creates an applicability decision with vendor evidence, compensating control, and replacement trigger.",
            "zh": "不支持的设置创建带厂商证据、补偿控制和替换触发器的适用性决定。"
          }
        },
        {
          "id": "CX-02",
          "text": {
            "en": "Evaluator failure marks evidence stale or unevaluable and cannot preserve pass beyond the freshness clock.",
            "zh": "评估器失败会把证据标为陈旧或无法评估，不能在新鲜度时钟后保留通过。"
          }
        },
        {
          "id": "CX-03",
          "text": {
            "en": "Canary business-health regression stops rollout and invokes the setting-level rollback order.",
            "zh": "金丝雀业务健康回退时停止发布，并按设置级回滚顺序执行。"
          }
        },
        {
          "id": "CX-04",
          "text": {
            "en": "Conflicting parent and child policy records both effective sources and resolves precedence before compliance calculation.",
            "zh": "父子策略冲突时记录两者的有效来源，并在计算合规前解析优先级。"
          }
        }
      ],
      "permissions_and_audit": {
        "roles": [
          {
            "role": "baseline_author",
            "actions": [
              {
                "en": "edit draft",
                "zh": "编辑草稿"
              },
              {
                "en": "propose source",
                "zh": "提交来源建议"
              }
            ],
            "separation": {
              "en": "cannot self-approve production",
              "zh": "不得自行批准进入生产"
            }
          },
          {
            "role": "security_approver",
            "actions": [
              {
                "en": "approve security decision",
                "zh": "批准安全决定"
              },
              {
                "en": "approve exception",
                "zh": "批准例外"
              }
            ],
            "separation": {
              "en": "cannot deploy",
              "zh": "不得执行部署"
            }
          },
          {
            "role": "platform_operator",
            "actions": [
              {
                "en": "canary",
                "zh": "执行金丝雀发布"
              },
              {
                "en": "deploy",
                "zh": "部署"
              },
              {
                "en": "rollback",
                "zh": "回滚"
              }
            ],
            "separation": {
              "en": "cannot rewrite published version",
              "zh": "不得改写已发布版本"
            }
          },
          {
            "role": "service_owner",
            "actions": [
              {
                "en": "approve business compatibility",
                "zh": "批准业务兼容性"
              },
              {
                "en": "accept downtime",
                "zh": "接受停机窗口"
              }
            ],
            "separation": {
              "en": "cannot delete evidence",
              "zh": "不得删除证据"
            }
          }
        ],
        "audit_fields": [
          "actor_id",
          "baseline_version",
          "setting_id",
          "decision",
          "old_value",
          "new_value",
          "reason",
          "source_ref",
          "occurred_at",
          "change_id"
        ]
      },
      "nfr": [
        {
          "id": "CNFR-01",
          "category": "reproducibility",
          "text": {
            "en": "The same baseline version renders byte-identical policy input for the same platform adapter version.",
            "zh": "同一基线版本和平台适配器版本生成字节一致的策略输入。"
          }
        },
        {
          "id": "CNFR-02",
          "category": "safety",
          "text": {
            "en": "Every enforceable setting has a preflight and rollback; settings without rollback require explicit irreversible-change approval.",
            "zh": "每项可执行设置都有预检与回滚；无法回滚的设置需不可逆变更批准。"
          }
        },
        {
          "id": "CNFR-03",
          "category": "freshness",
          "text": {
            "en": "Effective-state receipts expire on the local risk clock and surface collector failure.",
            "zh": "有效状态回执按本地风险时钟过期，并显露采集器失败。"
          }
        },
        {
          "id": "CNFR-04",
          "category": "availability",
          "text": {
            "en": "A central service outage cannot erase the last active policy or block emergency rollback.",
            "zh": "中央服务中断不能删除上一活动策略，也不能阻断紧急回滚。"
          }
        },
        {
          "id": "CNFR-05",
          "category": "privacy",
          "text": {
            "en": "Receipts avoid secrets and collect only settings needed for the declared control decision.",
            "zh": "回执不含秘密，只采集控制决定所需的设置。"
          }
        }
      ],
      "acceptance_criteria": [
        {
          "id": "CAC-01",
          "text": {
            "en": "A clean representative instance reaches the intended settings and passes required business paths.",
            "zh": "干净代表实例达到意图设置并通过必要业务路径。"
          }
        },
        {
          "id": "CAC-02",
          "text": {
            "en": "Introducing one prohibited setting creates drift and restores the approved value or opens an exception.",
            "zh": "引入一个禁止设置会产生漂移，并恢复批准值或创建例外。"
          }
        },
        {
          "id": "CAC-03",
          "text": {
            "en": "An unreachable evaluator leaves the asset unevaluable, not compliant.",
            "zh": "评估器不可达时，资产显示无法评估而非合规。"
          }
        },
        {
          "id": "CAC-04",
          "text": {
            "en": "Overlapping baseline applicability blocks publication until precedence is approved.",
            "zh": "基线适用范围重叠时，在优先级批准前阻止发布。"
          }
        },
        {
          "id": "CAC-05",
          "text": {
            "en": "Rollback restores the prior effective state and records assets that did not converge.",
            "zh": "回滚恢复上一有效状态，并记录未收敛资产。"
          }
        },
        {
          "id": "CAC-06",
          "text": {
            "en": "An expired exception no longer suppresses drift and opens owner action.",
            "zh": "例外到期后不再压制漂移，并创建责任人事项。"
          }
        }
      ],
      "release_and_rollback": {
        "migration": {
          "en": "Import existing standards as drafts, map each asset to an applicability tuple, and keep legacy enforcement authoritative until canary evidence passes.",
          "zh": "把现有标准作为草稿导入，将每项资产映射到适用元组；金丝雀证据通过前由旧执行保持权威。"
        },
        "phases": [
          {
            "en": "Draft and source reconciliation",
            "zh": "草稿与来源对账"
          },
          {
            "en": "Representative canary",
            "zh": "代表性金丝雀"
          },
          {
            "en": "Low-risk rollout waves",
            "zh": "低风险发布波次"
          },
          {
            "en": "Critical and production rollout",
            "zh": "关键与生产发布"
          }
        ],
        "monitoring": [
          {
            "en": "policy render failure",
            "zh": "策略渲染失败"
          },
          {
            "en": "canary business health",
            "zh": "金丝雀业务健康度"
          },
          {
            "en": "effective-state mismatch",
            "zh": "有效状态不一致"
          },
          {
            "en": "evaluator freshness",
            "zh": "评估器新鲜度"
          },
          {
            "en": "exception expiry",
            "zh": "例外到期"
          },
          {
            "en": "rollback convergence",
            "zh": "回滚收敛"
          }
        ],
        "rollback_triggers": [
          {
            "en": "Business health breaches the approved canary gate.",
            "zh": "业务健康超过批准的金丝雀门槛。"
          },
          {
            "en": "Effective-state mismatch grows after a wave.",
            "zh": "发布波次后有效状态不匹配扩大。"
          },
          {
            "en": "Rollback or out-of-band recovery is unavailable.",
            "zh": "回滚或带外恢复不可用。"
          }
        ],
        "rollback": {
          "en": "Stop new waves, restore the last active version through the same adapter, verify effective state and business paths, and retain failed assets in a recovery queue.",
          "zh": "停止新波次，经同一适配器恢复上一活动版本，验证有效状态与业务路径，并把失败资产留在恢复队列。"
        },
        "decommission": {
          "en": "Retire legacy standards after every active asset maps to a verified baseline or expiring exception and the old rollback path is archived.",
          "zh": "全部活动资产映射到已验证基线或会到期例外，且旧回滚路径已归档后，才退役旧标准。"
        }
      }
    },
    {
      "prd_id": "PRD-CIS-8.2-AUDIT-LOG-PIPELINE",
      "safeguard_id": "8.2",
      "name": {
        "en": "Security audit-log collection and health authority",
        "zh": "安全审计日志采集与健康权威"
      },
      "provenance": "example_local_solution",
      "scenario": {
        "en": "Detection and investigation teams need to know which in-scope sources are expected to emit security audit logs, whether events arrived completely and on time, and whether a quiet source is healthy, misconfigured, or disconnected.",
        "zh": "检测与调查团队需要知道哪些在范围来源应产生日志、事件是否完整及时到达，以及沉默来源究竟正常、配置错误还是已经断开。"
      },
      "users": [
        {
          "en": "Detection engineer",
          "zh": "检测工程师"
        },
        {
          "en": "Incident responder",
          "zh": "事件响应人员"
        },
        {
          "en": "Platform log owner",
          "zh": "平台日志责任人"
        },
        {
          "en": "Evidence reviewer",
          "zh": "证据复核人员"
        }
      ],
      "goals": [
        {
          "en": "Maintain one expected-source population with parsing, routing, retention, and health state.",
          "zh": "维护包含解析、路由、保留和健康状态的应有日志来源总体。"
        },
        {
          "en": "Prevent collector silence and partial delivery from being reported as complete coverage.",
          "zh": "防止采集器沉默和部分交付被报告为完整覆盖。"
        }
      ],
      "scope": {
        "included": [
          {
            "en": "Authentication, authorization, administrative, configuration, process, network-security, cloud-control-plane, and sensitive-data audit sources selected by risk",
            "zh": "按风险选定的认证、授权、管理、配置、进程、网络安全、云控制面与敏感数据审计来源"
          },
          {
            "en": "Source onboarding, transport, parsing, clock validation, health, routing, retention, and evidence receipts",
            "zh": "来源接入、传输、解析、时钟验证、健康、路由、保留与证据回执"
          }
        ],
        "excluded": [
          {
            "en": "Content of every application business event",
            "zh": "每个应用业务事件的内容"
          },
          {
            "en": "Detection-rule quality beyond source and field prerequisites",
            "zh": "超出来源与字段前置条件的检测规则质量"
          },
          {
            "en": "Indefinite retention of raw sensitive payloads",
            "zh": "无限期保留原始敏感载荷"
          }
        ]
      },
      "identity_contract": {
        "natural_key": "tenant_or_org + source_type + source_native_id + environment",
        "merge_rule": {
          "en": "High-availability members may roll up to one logical source only when member identity and loss are separately observable.",
          "zh": "高可用成员只有在成员身份与丢失可分别观测时才能汇总为一个逻辑来源。"
        }
      },
      "data_model": [
        {
          "field": "log_source_id",
          "type": "uuid",
          "required": true,
          "source": {
            "en": "system",
            "zh": "系统"
          },
          "lifecycle": {
            "en": "immutable",
            "zh": "不可变"
          }
        },
        {
          "field": "source_native_id",
          "type": "string",
          "required": true,
          "source": {
            "en": "platform",
            "zh": "平台"
          },
          "lifecycle": {
            "en": "immutable",
            "zh": "不可变"
          }
        },
        {
          "field": "source_type",
          "type": "enum",
          "required": true,
          "source": {
            "en": "catalog",
            "zh": "目录"
          },
          "lifecycle": {
            "en": "versioned",
            "zh": "版本化"
          }
        },
        {
          "field": "owner_id",
          "type": "principal_id",
          "required": true,
          "source": {
            "en": "service catalog",
            "zh": "服务目录"
          },
          "lifecycle": {
            "en": "audited",
            "zh": "可审计变更"
          }
        },
        {
          "field": "expected_event_classes",
          "type": "array<event_class>",
          "required": true,
          "source": {
            "en": "risk decision",
            "zh": "风险决定"
          },
          "lifecycle": {
            "en": "versioned",
            "zh": "版本化"
          }
        },
        {
          "field": "transport",
          "type": "protocol+auth+endpoint",
          "required": true,
          "source": {
            "en": "onboarding",
            "zh": "接入流程"
          },
          "lifecycle": {
            "en": "secret references only",
            "zh": "仅保存密钥引用"
          }
        },
        {
          "field": "parser_version",
          "type": "string",
          "required": true,
          "source": {
            "en": "pipeline",
            "zh": "采集管道"
          },
          "lifecycle": {
            "en": "versioned",
            "zh": "版本化"
          }
        },
        {
          "field": "freshness_slo",
          "type": "duration",
          "required": true,
          "source": {
            "en": "owner decision",
            "zh": "责任人决定"
          },
          "lifecycle": {
            "en": "versioned",
            "zh": "版本化"
          }
        },
        {
          "field": "last_event_at",
          "type": "timestamp|null",
          "required": true,
          "source": {
            "en": "collector",
            "zh": "采集器"
          },
          "lifecycle": {
            "en": "monotonic maximum",
            "zh": "单调递增的最大值"
          }
        },
        {
          "field": "last_heartbeat_at",
          "type": "timestamp|null",
          "required": true,
          "source": {
            "en": "health probe",
            "zh": "健康探针"
          },
          "lifecycle": {
            "en": "monotonic maximum",
            "zh": "单调递增的最大值"
          }
        },
        {
          "field": "health_state",
          "type": "enum(onboarding,healthy,late,partial,failed,retired)",
          "required": true,
          "source": {
            "en": "state machine",
            "zh": "状态机"
          },
          "lifecycle": {
            "en": "history",
            "zh": "历史记录"
          }
        },
        {
          "field": "retention_policy_id",
          "type": "string",
          "required": true,
          "source": {
            "en": "retention service",
            "zh": "保留服务"
          },
          "lifecycle": {
            "en": "versioned",
            "zh": "版本化"
          }
        },
        {
          "field": "evidence_receipt",
          "type": "source+event_id+ingest_time+parse_result+route_result",
          "required": true,
          "source": {
            "en": "pipeline",
            "zh": "采集管道"
          },
          "lifecycle": {
            "en": "sampled or aggregated",
            "zh": "抽样或聚合"
          }
        }
      ],
      "states": [
        {
          "id": "onboarding",
          "definition": {
            "en": "Identity and expected event contract exist; end-to-end proof is incomplete.",
            "zh": "已有身份与应有事件契约，但端到端证明未完成。"
          }
        },
        {
          "id": "healthy",
          "definition": {
            "en": "Heartbeat and representative events arrive within SLO, parse, route, and retain successfully.",
            "zh": "心跳与代表事件在 SLO 内到达，并成功解析、路由与保留。"
          }
        },
        {
          "id": "late",
          "definition": {
            "en": "Events or heartbeat exceed freshness SLO but the pipeline remains reachable.",
            "zh": "事件或心跳超过新鲜度 SLO，但管道仍可达。"
          }
        },
        {
          "id": "partial",
          "definition": {
            "en": "Some members, event classes, pages, partitions, or routes are missing.",
            "zh": "部分成员、事件类、分页、分区或路由缺失。"
          }
        },
        {
          "id": "failed",
          "definition": {
            "en": "Source, transport, parser, route, or storage is unavailable or rejects events.",
            "zh": "来源、传输、解析器、路由或存储不可用或拒绝事件。"
          }
        },
        {
          "id": "retired",
          "definition": {
            "en": "Approved source retirement evidence exists and dependent detections were migrated or closed.",
            "zh": "已有批准的来源退役证据，依赖检测已迁移或关闭。"
          }
        }
      ],
      "transitions": [
        {
          "from": "onboarding",
          "event": "end_to_end_test_passed",
          "to": "healthy",
          "guard": {
            "en": "positive, negative, and retention proof complete",
            "zh": "正向、反向与保留验证证据完整"
          }
        },
        {
          "from": "healthy",
          "event": "freshness_breached",
          "to": "late",
          "guard": {
            "en": "last event or heartbeat exceeds SLO",
            "zh": "最后事件或心跳已超过 SLO"
          }
        },
        {
          "from": "healthy|late",
          "event": "partial_loss_detected",
          "to": "partial",
          "guard": {
            "en": "member, class, page, partition, or route incomplete",
            "zh": "成员、事件类别、分页、分区或路由不完整"
          }
        },
        {
          "from": "healthy|late|partial",
          "event": "pipeline_failure",
          "to": "failed",
          "guard": {
            "en": "source, transport, parser, route, or storage failure",
            "zh": "来源、传输、解析器、路由或存储失败"
          }
        },
        {
          "from": "late|partial|failed",
          "event": "recovery_test_passed",
          "to": "healthy",
          "guard": {
            "en": "backlog reconciled and representative event visible",
            "zh": "积压已对账且代表性事件可查询"
          }
        },
        {
          "from": "healthy|late|partial|failed",
          "event": "retirement_approved",
          "to": "retired",
          "guard": {
            "en": "dependencies migrated and retention preserved",
            "zh": "依赖方已迁移且保留要求不受损"
          }
        }
      ],
      "functional_rules": [
        {
          "id": "L-01",
          "text": {
            "en": "Every source declares expected event classes, cadence or heartbeat, owner, parser, route, retention, and consumers.",
            "zh": "每个来源声明应有事件类、周期或心跳、责任人、解析器、路由、保留与消费者。"
          }
        },
        {
          "id": "L-02",
          "text": {
            "en": "Coverage counts only sources with fresh representative events and successful parse, route, and retention evidence.",
            "zh": "覆盖只计算有新鲜代表事件且解析、路由、保留成功的来源。"
          }
        },
        {
          "id": "L-03",
          "text": {
            "en": "A valid empty interval requires a healthy heartbeat or independent activity expectation; zero events alone is unknown.",
            "zh": "合法空区间必须有健康心跳或独立活动预期；仅零事件属于未知。"
          }
        },
        {
          "id": "L-04",
          "text": {
            "en": "Parser rejects enter a dead-letter queue with source, parser version, reason, and original event identity.",
            "zh": "解析拒绝进入带来源、解析器版本、原因和原始事件身份的错误队列。"
          }
        },
        {
          "id": "L-05",
          "text": {
            "en": "Clock skew beyond the approved bound marks timestamps unreliable and preserves receive time separately.",
            "zh": "时钟偏差超过批准范围时，把事件时间标为不可靠并单独保存接收时间。"
          }
        },
        {
          "id": "L-06",
          "text": {
            "en": "Source retirement cannot complete while an active detection or investigation workflow depends on it.",
            "zh": "仍有活动检测或调查流程依赖来源时，禁止完成退役。"
          }
        }
      ],
      "exception_paths": [
        {
          "id": "LX-01",
          "text": {
            "en": "Rate limiting or API pagination failure marks the generation partial and retains the prior complete coverage state as historical evidence only.",
            "zh": "限流或 API 分页失败把本代标为部分；上一完整覆盖状态仅作为历史证据保留。"
          }
        },
        {
          "id": "LX-02",
          "text": {
            "en": "Parser deployment failure routes the old parser if safe; otherwise the source becomes failed and raw backlog is isolated.",
            "zh": "解析器发布失败时在安全条件下路由旧版本，否则来源进入 failed 并隔离原始积压。"
          }
        },
        {
          "id": "LX-03",
          "text": {
            "en": "Storage rejection stops success acknowledgement, alerts, and retains retry identity without duplicate ingestion.",
            "zh": "存储拒绝时停止成功确认、发出告警，并保留重试身份防止重复采集。"
          }
        },
        {
          "id": "LX-04",
          "text": {
            "en": "Privacy redaction removes only approved fields and records the redaction policy version in evidence.",
            "zh": "隐私脱敏只移除批准字段，并在证据中记录脱敏策略版本。"
          }
        }
      ],
      "permissions_and_audit": {
        "roles": [
          {
            "role": "source_owner",
            "actions": [
              {
                "en": "request onboarding",
                "zh": "申请接入"
              },
              {
                "en": "approve event contract",
                "zh": "批准事件契约"
              },
              {
                "en": "request retirement",
                "zh": "申请退役"
              }
            ],
            "separation": {
              "en": "cannot alter collector audit",
              "zh": "不得修改采集器审计记录"
            }
          },
          {
            "role": "pipeline_operator",
            "actions": [
              {
                "en": "deploy parser",
                "zh": "部署解析器"
              },
              {
                "en": "route source",
                "zh": "配置来源路由"
              },
              {
                "en": "replay backlog",
                "zh": "重放积压"
              }
            ],
            "separation": {
              "en": "cannot approve own exception",
              "zh": "不得批准本人提交的例外"
            }
          },
          {
            "role": "detection_owner",
            "actions": [
              {
                "en": "declare dependency",
                "zh": "登记依赖"
              },
              {
                "en": "approve migration",
                "zh": "批准迁移"
              }
            ],
            "separation": {
              "en": "cannot mark unhealthy source healthy",
              "zh": "不得把异常来源标为健康"
            }
          },
          {
            "role": "privacy_reviewer",
            "actions": [
              {
                "en": "approve redaction",
                "zh": "批准脱敏"
              }
            ],
            "separation": {
              "en": "cannot change raw retention alone",
              "zh": "不得单独变更原始日志保留策略"
            }
          }
        ],
        "audit_fields": [
          "actor_id",
          "log_source_id",
          "action",
          "parser_version",
          "route_version",
          "old_state",
          "new_state",
          "reason",
          "occurred_at",
          "correlation_id"
        ]
      },
      "nfr": [
        {
          "id": "LNFR-01",
          "category": "latency",
          "text": {
            "en": "P95 event-to-search latency and maximum tolerable lateness are declared per source class and continuously measured.",
            "zh": "按来源类别声明并持续测量 P95 事件到检索延迟与最大可容忍迟到。"
          }
        },
        {
          "id": "LNFR-02",
          "category": "durability",
          "text": {
            "en": "Acknowledged events survive the required retention and can be retrieved by event identity.",
            "zh": "已确认事件在要求保留期内可按事件身份检索。"
          }
        },
        {
          "id": "LNFR-03",
          "category": "integrity",
          "text": {
            "en": "Transport authentication, append-only evidence, and access audit protect the pipeline without placing secrets in events.",
            "zh": "通过传输认证、追加证据和访问审计保护管道，事件中不放秘密。"
          }
        },
        {
          "id": "LNFR-04",
          "category": "capacity",
          "text": {
            "en": "Burst handling preserves per-source ordering requirements and exposes dropped, delayed, and back-pressured counts.",
            "zh": "突发处理保持每来源排序要求，并显露丢弃、延迟与背压数量。"
          }
        },
        {
          "id": "LNFR-05",
          "category": "resilience",
          "text": {
            "en": "A collector or route failure fails visibly and supports idempotent replay from the last confirmed cursor.",
            "zh": "采集器或路由失败会显式失败，并支持从最后确认游标幂等重放。"
          }
        }
      ],
      "acceptance_criteria": [
        {
          "id": "LAC-01",
          "text": {
            "en": "A known successful login and a known denied login appear with actor, target, result, source, and timestamps.",
            "zh": "已知成功与拒绝登录事件均带行为人、目标、结果、来源和时间进入平台。"
          }
        },
        {
          "id": "LAC-02",
          "text": {
            "en": "Stopping one source heartbeat moves it to late or failed and removes it from fresh coverage without deleting it.",
            "zh": "停止来源心跳后进入 late 或 failed，并退出新鲜覆盖但不删除。"
          }
        },
        {
          "id": "LAC-03",
          "text": {
            "en": "A malformed event reaches the dead-letter queue and raises parser-health evidence without blocking unrelated sources.",
            "zh": "畸形事件进入错误队列并产生解析健康证据，不阻断无关来源。"
          }
        },
        {
          "id": "LAC-04",
          "text": {
            "en": "Dropping one pagination page marks the generation partial and prevents a complete-coverage result.",
            "zh": "丢失一个分页会把本代标为 partial，并阻止完整覆盖结论。"
          }
        },
        {
          "id": "LAC-05",
          "text": {
            "en": "Replaying the same event identity does not create duplicate searchable events or duplicate alerts.",
            "zh": "重放同一事件身份不会产生重复可搜索事件或重复告警。"
          }
        },
        {
          "id": "LAC-06",
          "text": {
            "en": "Retiring a source with active detection dependencies is rejected and audited.",
            "zh": "退役仍有活动检测依赖的来源会被拒绝并审计。"
          }
        }
      ],
      "release_and_rollback": {
        "migration": {
          "en": "Run dual delivery, compare counts and representative fields by source, then switch consumers only after completeness and latency gates pass.",
          "zh": "双路投递并按来源比较数量与代表字段；完整性与延迟门槛通过后才切换消费者。"
        },
        "phases": [
          {
            "en": "Source contract and shadow route",
            "zh": "来源契约与影子路由"
          },
          {
            "en": "Dual delivery and field comparison",
            "zh": "双路投递与字段比较"
          },
          {
            "en": "Consumer migration",
            "zh": "消费者迁移"
          },
          {
            "en": "Legacy route retirement",
            "zh": "旧路由退役"
          }
        ],
        "monitoring": [
          {
            "en": "source freshness",
            "zh": "来源新鲜度"
          },
          {
            "en": "event count deviation",
            "zh": "事件数量偏差"
          },
          {
            "en": "parser rejection",
            "zh": "解析器拒绝"
          },
          {
            "en": "dead-letter age",
            "zh": "错误队列积压时长"
          },
          {
            "en": "route failure",
            "zh": "路由失败"
          },
          {
            "en": "search latency",
            "zh": "检索延迟"
          },
          {
            "en": "retention retrieval",
            "zh": "保留数据可检索性"
          }
        ],
        "rollback_triggers": [
          {
            "en": "A required event class disappears or field parity fails.",
            "zh": "必要事件类消失或字段一致性失败。"
          },
          {
            "en": "Latency or rejection exceeds the locally approved gate.",
            "zh": "延迟或拒绝率超过本地批准门槛。"
          },
          {
            "en": "Incident responders cannot retrieve a known test event.",
            "zh": "事件响应人员无法检索已知测试事件。"
          }
        ],
        "rollback": {
          "en": "Return consumers to the last verified route, keep the new backlog isolated with cursors, and replay only after count and identity reconciliation passes.",
          "zh": "消费者恢复上一已验证路由，新积压带游标隔离保存；数量与身份对账通过后才重放。"
        },
        "decommission": {
          "en": "Remove the legacy route after all consumers acknowledge migration, retention is preserved, and one fault/replay exercise passes.",
          "zh": "所有消费者确认迁移、保留得到维持并通过一次故障/重放演练后，才移除旧路由。"
        }
      }
    },
    {
      "prd_id": "PRD-CIS-11.5-RECOVERY-EXERCISE",
      "safeguard_id": "11.5",
      "name": {
        "en": "Recovery-test orchestration and proof service",
        "zh": "恢复测试编排与证明服务"
      },
      "provenance": "example_local_solution",
      "scenario": {
        "en": "Service owners and recovery operators need to prove that selected systems, data, identities, keys, dependencies, and runbooks can restore to a clean isolated environment and meet approved recovery objectives without treating backup-job success as recovery.",
        "zh": "服务责任人与恢复操作员需要证明选定系统、数据、身份、密钥、依赖和手册能恢复到干净隔离环境并达到批准目标，不能把备份任务成功当成已经恢复。"
      },
      "users": [
        {
          "en": "Service owner",
          "zh": "服务责任人"
        },
        {
          "en": "Backup and recovery operator",
          "zh": "备份与恢复操作员"
        },
        {
          "en": "Incident commander",
          "zh": "事件指挥人员"
        },
        {
          "en": "Security and evidence reviewer",
          "zh": "安全与证据复核人员"
        }
      ],
      "goals": [
        {
          "en": "Schedule risk-based recovery exercises across every in-scope service and backup class.",
          "zh": "按风险为每个在范围服务与备份类别安排恢复演练。"
        },
        {
          "en": "Capture immutable evidence for clean restore, dependency readiness, business validation, RTO/RPO, gaps, and remediation retest.",
          "zh": "为干净恢复、依赖就绪、业务验证、RTO/RPO、缺口与修复复测保存不可变证据。"
        }
      ],
      "scope": {
        "included": [
          {
            "en": "Production services selected by business impact, their data stores, configuration, identities, secrets, keys, network dependencies, and backup copies",
            "zh": "按业务影响选定的生产服务及其数据存储、配置、身份、秘密、密钥、网络依赖和备份副本"
          },
          {
            "en": "Exercise planning, isolation, restore, integrity validation, business acceptance, gap remediation, and retest",
            "zh": "演练计划、隔离、恢复、完整性验证、业务验收、缺口修复与复测"
          }
        ],
        "excluded": [
          {
            "en": "Destructive testing against live production data or customer traffic",
            "zh": "针对实时生产数据或客户流量的破坏性测试"
          },
          {
            "en": "Assuming a vendor disaster-recovery attestation proves tenant restoration",
            "zh": "假设厂商灾难恢复证明可代表租户恢复"
          },
          {
            "en": "Replacing incident-response command decisions",
            "zh": "替代事件响应指挥决定"
          }
        ]
      },
      "identity_contract": {
        "natural_key": "service_id + recovery_profile_version + exercise_id",
        "merge_rule": {
          "en": "One exercise may cover several components only when each component, copy, restore result, and unmet dependency remains individually traceable.",
          "zh": "一次演练可覆盖多个组件，但每个组件、副本、恢复结果和未满足依赖必须分别可追溯。"
        }
      },
      "data_model": [
        {
          "field": "exercise_id",
          "type": "uuid",
          "required": true,
          "source": {
            "en": "system",
            "zh": "系统"
          },
          "lifecycle": {
            "en": "immutable",
            "zh": "不可变"
          }
        },
        {
          "field": "service_id",
          "type": "service_catalog_id",
          "required": true,
          "source": {
            "en": "service catalog",
            "zh": "服务目录"
          },
          "lifecycle": {
            "en": "immutable reference",
            "zh": "不可变引用"
          }
        },
        {
          "field": "recovery_profile_version",
          "type": "string",
          "required": true,
          "source": {
            "en": "owner-approved profile",
            "zh": "责任人批准的恢复档案"
          },
          "lifecycle": {
            "en": "immutable per exercise",
            "zh": "每次演练内不可变"
          }
        },
        {
          "field": "target_rto",
          "type": "duration",
          "required": true,
          "source": {
            "en": "business impact decision",
            "zh": "业务影响决定"
          },
          "lifecycle": {
            "en": "versioned",
            "zh": "版本化"
          }
        },
        {
          "field": "target_rpo",
          "type": "duration",
          "required": true,
          "source": {
            "en": "business impact decision",
            "zh": "业务影响决定"
          },
          "lifecycle": {
            "en": "versioned",
            "zh": "版本化"
          }
        },
        {
          "field": "backup_copy_refs",
          "type": "array<provider+vault+copy_id+created_at>",
          "required": true,
          "source": {
            "en": "backup authority",
            "zh": "备份权威台账"
          },
          "lifecycle": {
            "en": "immutable refs",
            "zh": "不可变引用"
          }
        },
        {
          "field": "isolation_environment",
          "type": "account+network+identity boundary",
          "required": true,
          "source": {
            "en": "exercise plan",
            "zh": "演练计划"
          },
          "lifecycle": {
            "en": "per exercise",
            "zh": "按次演练"
          }
        },
        {
          "field": "restore_steps",
          "type": "ordered array<step+owner+expected>",
          "required": true,
          "source": {
            "en": "runbook",
            "zh": "操作手册"
          },
          "lifecycle": {
            "en": "versioned",
            "zh": "版本化"
          }
        },
        {
          "field": "timestamps",
          "type": "declared_start+data_point+service_ready+accepted",
          "required": true,
          "source": {
            "en": "orchestrator",
            "zh": "编排器"
          },
          "lifecycle": {
            "en": "immutable",
            "zh": "不可变"
          }
        },
        {
          "field": "validation_results",
          "type": "array<control+expected+observed+evidence>",
          "required": true,
          "source": {
            "en": "tests",
            "zh": "测试"
          },
          "lifecycle": {
            "en": "append-only",
            "zh": "仅追加"
          }
        },
        {
          "field": "gap_records",
          "type": "array<gap_id+severity+owner+due+status>",
          "required": true,
          "source": {
            "en": "review",
            "zh": "评审"
          },
          "lifecycle": {
            "en": "state history",
            "zh": "状态历史"
          }
        },
        {
          "field": "evidence_bundle_hash",
          "type": "sha256",
          "required": true,
          "source": {
            "en": "evidence service",
            "zh": "证据服务"
          },
          "lifecycle": {
            "en": "immutable",
            "zh": "不可变"
          }
        }
      ],
      "states": [
        {
          "id": "planned",
          "definition": {
            "en": "Scope, objectives, copy, isolation, safety, owners, and acceptance are approved.",
            "zh": "范围、目标、副本、隔离、安全、责任人和验收已批准。"
          }
        },
        {
          "id": "ready",
          "definition": {
            "en": "Environment, credentials, copy access, monitoring, and stop conditions pass preflight.",
            "zh": "环境、凭据、副本访问、监控与急停条件通过预检。"
          }
        },
        {
          "id": "restoring",
          "definition": {
            "en": "Restore is executing with step and timestamp evidence.",
            "zh": "正在恢复，并记录步骤与时间证据。"
          }
        },
        {
          "id": "validating",
          "definition": {
            "en": "Technical integrity, security, dependency, and business checks run.",
            "zh": "正在执行技术完整性、安全、依赖和业务检查。"
          }
        },
        {
          "id": "accepted",
          "definition": {
            "en": "Required checks and objectives pass with no open acceptance blocker.",
            "zh": "必要检查与目标通过，且无未关闭验收阻断。"
          }
        },
        {
          "id": "failed",
          "definition": {
            "en": "Restore, validation, safety, or objective failed; gaps and safe cleanup are required.",
            "zh": "恢复、验证、安全或目标失败；需要缺口和安全清理。"
          }
        },
        {
          "id": "retest_required",
          "definition": {
            "en": "Remediation claims exist but the failed path has not passed a new exercise.",
            "zh": "已有修复声明但失败路径尚未通过新演练。"
          }
        },
        {
          "id": "closed",
          "definition": {
            "en": "Accepted result or successful remediation retest is signed and evidence retained.",
            "zh": "验收结果或成功修复复测已签字并保留证据。"
          }
        }
      ],
      "transitions": [
        {
          "from": "planned",
          "event": "preflight_passed",
          "to": "ready",
          "guard": {
            "en": "isolation, access, monitoring, stop conditions ready",
            "zh": "隔离、访问、监控与停止条件均已就绪"
          }
        },
        {
          "from": "ready",
          "event": "restore_started",
          "to": "restoring",
          "guard": {
            "en": "approved change and copy identity",
            "zh": "已有批准的变更与备份副本身份"
          }
        },
        {
          "from": "restoring",
          "event": "service_bootstrapped",
          "to": "validating",
          "guard": {
            "en": "restore steps complete enough for tests",
            "zh": "恢复步骤已完成到可执行测试的程度"
          }
        },
        {
          "from": "validating",
          "event": "all_acceptance_passed",
          "to": "accepted",
          "guard": {
            "en": "RTO/RPO and security/business checks pass",
            "zh": "RTO/RPO 及安全和业务检查均通过"
          }
        },
        {
          "from": "ready|restoring|validating",
          "event": "blocking_failure",
          "to": "failed",
          "guard": {
            "en": "safety, restore, validation, RTO or RPO failure",
            "zh": "安全、恢复、验证、RTO 或 RPO 任一失败"
          }
        },
        {
          "from": "failed",
          "event": "remediation_declared",
          "to": "retest_required",
          "guard": {
            "en": "owner, due date, and change evidence present",
            "zh": "已有责任人、到期时间与变更证据"
          }
        },
        {
          "from": "accepted|retest_required",
          "event": "closure_approved",
          "to": "closed",
          "guard": {
            "en": "accepted exercise or successful retest bundle",
            "zh": "演练已验收或复测证据包通过"
          }
        }
      ],
      "functional_rules": [
        {
          "id": "R-01",
          "text": {
            "en": "Every in-scope service maps to a recovery profile, approved RTO/RPO, required copy classes, and an exercise cadence based on risk.",
            "zh": "每个在范围服务映射到恢复档案、批准的 RTO/RPO、必要副本类别和风险驱动演练周期。"
          }
        },
        {
          "id": "R-02",
          "text": {
            "en": "The selected copy identity and creation time are frozen before restore; operators cannot substitute an easier copy without a new decision.",
            "zh": "恢复前固定所选副本身份与创建时间；操作员不能无新决定换用更容易的副本。"
          }
        },
        {
          "id": "R-03",
          "text": {
            "en": "Restore runs in an isolated target with separate identity and network controls; no production write path is permitted.",
            "zh": "恢复在具备独立身份和网络控制的隔离目标中执行，禁止生产写路径。"
          }
        },
        {
          "id": "R-04",
          "text": {
            "en": "Validation covers data integrity, authorization, secrets and keys, logging, required dependencies, business transactions, and declared security controls.",
            "zh": "验证覆盖数据完整性、授权、秘密与密钥、日志、必要依赖、业务交易和声明的安全控制。"
          }
        },
        {
          "id": "R-05",
          "text": {
            "en": "RTO starts at the declared incident or exercise trigger and ends only at business acceptance; RPO compares the accepted data point to the declared trigger.",
            "zh": "RTO 从声明的事件或演练触发开始，到业务验收才结束；RPO 比较验收数据点与触发时刻。"
          }
        },
        {
          "id": "R-06",
          "text": {
            "en": "A failed component, missing dependency, skipped step, or unverified copy prevents a complete-pass result.",
            "zh": "组件失败、依赖缺失、步骤跳过或副本未验证均阻止完整通过。"
          }
        },
        {
          "id": "R-07",
          "text": {
            "en": "Remediation closure requires a retest of the original failed path, not a document update.",
            "zh": "修复结案要求复测原失败路径，文档更新不能替代。"
          }
        }
      ],
      "exception_paths": [
        {
          "id": "RX-01",
          "text": {
            "en": "Unavailable clean room delays the exercise with owner escalation; it cannot convert to a tabletop pass.",
            "zh": "干净恢复环境不可用时延迟演练并升级责任人，不能转换成桌面推演通过。"
          }
        },
        {
          "id": "RX-02",
          "text": {
            "en": "Corrupt or inaccessible copy moves the exercise to failed, preserves evidence, and tests the next copy only as a separate result.",
            "zh": "副本损坏或不可访问时演练失败并保留证据；测试下一副本必须作为独立结果。"
          }
        },
        {
          "id": "RX-03",
          "text": {
            "en": "Missing key or secret is a dependency failure even when files restore.",
            "zh": "即使文件恢复，密钥或秘密缺失仍属于依赖失败。"
          }
        },
        {
          "id": "RX-04",
          "text": {
            "en": "Safety stop leaves the environment quarantined, records the trigger, and requires cleanup approval before reuse.",
            "zh": "急停后环境保持隔离、记录触发原因，获得清理批准后才能复用。"
          }
        }
      ],
      "permissions_and_audit": {
        "roles": [
          {
            "role": "service_owner",
            "actions": [
              {
                "en": "approve profile",
                "zh": "批准恢复档案"
              },
              {
                "en": "accept business result",
                "zh": "验收业务结果"
              },
              {
                "en": "own gaps",
                "zh": "负责缺口整改"
              }
            ],
            "separation": {
              "en": "cannot alter raw exercise evidence",
              "zh": "不得修改原始演练证据"
            }
          },
          {
            "role": "recovery_operator",
            "actions": [
              {
                "en": "select approved copy",
                "zh": "选择获批副本"
              },
              {
                "en": "execute runbook",
                "zh": "执行操作手册"
              },
              {
                "en": "record step",
                "zh": "记录步骤"
              }
            ],
            "separation": {
              "en": "cannot self-accept result",
              "zh": "不得自行验收执行结果"
            }
          },
          {
            "role": "security_reviewer",
            "actions": [
              {
                "en": "approve isolation",
                "zh": "批准隔离方案"
              },
              {
                "en": "validate security controls",
                "zh": "验证安全控制"
              },
              {
                "en": "declare safety stop",
                "zh": "宣布安全停止"
              }
            ],
            "separation": {
              "en": "cannot change business objective",
              "zh": "不得变更业务目标"
            }
          },
          {
            "role": "evidence_reviewer",
            "actions": [
              {
                "en": "verify bundle",
                "zh": "核验证据包"
              },
              {
                "en": "approve closure",
                "zh": "批准结案"
              }
            ],
            "separation": {
              "en": "read-only restore environment",
              "zh": "恢复环境只读"
            }
          }
        ],
        "audit_fields": [
          "actor_id",
          "exercise_id",
          "service_id",
          "step_id",
          "copy_id",
          "action",
          "expected",
          "observed",
          "occurred_at",
          "evidence_ref",
          "reason"
        ]
      },
      "nfr": [
        {
          "id": "RNFR-01",
          "category": "isolation",
          "text": {
            "en": "Recovery targets have no production write route and use exercise-specific identities and secrets.",
            "zh": "恢复目标无生产写路由，并使用演练专用身份与秘密。"
          }
        },
        {
          "id": "RNFR-02",
          "category": "integrity",
          "text": {
            "en": "Evidence bundle ordering, hashes, and access audit make post-exercise alteration detectable.",
            "zh": "证据包顺序、哈希和访问审计使演练后篡改可检测。"
          }
        },
        {
          "id": "RNFR-03",
          "category": "timing",
          "text": {
            "en": "All RTO/RPO timestamps use synchronized clocks and preserve source plus receive time when clocks disagree.",
            "zh": "所有 RTO/RPO 时间使用同步时钟；时钟冲突时保留来源时间与接收时间。"
          }
        },
        {
          "id": "RNFR-04",
          "category": "privacy",
          "text": {
            "en": "Restored sensitive data remains in approved isolation and is disposed through an evidenced cleanup workflow.",
            "zh": "恢复的敏感数据留在批准隔离区，并通过有证据的清理流程处置。"
          }
        },
        {
          "id": "RNFR-05",
          "category": "capacity",
          "text": {
            "en": "The target has measured capacity for the selected service; a capacity shortcut is recorded as a scope limitation.",
            "zh": "目标具备所选服务的实测容量；容量缩减必须登记为范围限制。"
          }
        }
      ],
      "acceptance_criteria": [
        {
          "id": "RAC-01",
          "text": {
            "en": "A pinned backup copy restores into the isolated target without a production write path.",
            "zh": "固定备份副本恢复到无生产写路径的隔离目标。"
          }
        },
        {
          "id": "RAC-02",
          "text": {
            "en": "Integrity checks reconcile expected objects and identify any missing, extra, or corrupt data.",
            "zh": "完整性检查对账应有对象，并识别缺失、多余或损坏数据。"
          }
        },
        {
          "id": "RAC-03",
          "text": {
            "en": "Approved and denied identities exercise restored authorization and produce audit logs.",
            "zh": "批准与拒绝身份验证恢复后的授权并产生日志。"
          }
        },
        {
          "id": "RAC-04",
          "text": {
            "en": "Required business transaction, dependency, key, secret, and monitoring checks pass before acceptance.",
            "zh": "必要业务交易、依赖、密钥、秘密和监控检查在验收前通过。"
          }
        },
        {
          "id": "RAC-05",
          "text": {
            "en": "Measured RTO and RPO use declared start/end events and meet the approved profile or open a gap.",
            "zh": "实测 RTO/RPO 使用声明起止事件，并达到批准档案或创建缺口。"
          }
        },
        {
          "id": "RAC-06",
          "text": {
            "en": "A deliberately withheld dependency makes the exercise fail and names the boundary.",
            "zh": "故意撤去一个依赖会使演练失败并指出失效边界。"
          }
        },
        {
          "id": "RAC-07",
          "text": {
            "en": "A remediation item cannot close until the same failed path passes a later retest.",
            "zh": "修复项在同一失败路径后续复测通过前不能关闭。"
          }
        }
      ],
      "release_and_rollback": {
        "migration": {
          "en": "Import recovery profiles and copy inventories, dry-run access and isolation, then begin with low-criticality services before the critical-service cadence.",
          "zh": "导入恢复档案与副本清单，干跑访问与隔离，再从低关键服务开始进入关键服务周期。"
        },
        "phases": [
          {
            "en": "Profile and dependency reconciliation",
            "zh": "档案与依赖对账"
          },
          {
            "en": "Low-criticality pilot",
            "zh": "低关键试点"
          },
          {
            "en": "Critical-service exercise waves",
            "zh": "关键服务演练波次"
          },
          {
            "en": "Recurring evidence cycle",
            "zh": "周期证据循环"
          }
        ],
        "monitoring": [
          {
            "en": "exercise overdue",
            "zh": "演练逾期"
          },
          {
            "en": "preflight failure",
            "zh": "预检失败"
          },
          {
            "en": "copy access failure",
            "zh": "副本访问失败"
          },
          {
            "en": "restore step duration",
            "zh": "恢复步骤耗时"
          },
          {
            "en": "RTO/RPO breach",
            "zh": "RTO/RPO 违约"
          },
          {
            "en": "open gap age",
            "zh": "未结缺口时长"
          },
          {
            "en": "cleanup incomplete",
            "zh": "清理未完成"
          }
        ],
        "rollback_triggers": [
          {
            "en": "Isolation cannot be proven or a production write route appears.",
            "zh": "无法证明隔离或出现生产写路径。"
          },
          {
            "en": "Unexpected sensitive-data exposure or unsafe system behavior occurs.",
            "zh": "发生意外敏感数据暴露或不安全系统行为。"
          },
          {
            "en": "Evidence capture fails for a state-changing step.",
            "zh": "状态变更步骤的证据采集失败。"
          }
        ],
        "rollback": {
          "en": "Stop restore, revoke exercise identities, isolate the target, preserve evidence, clean up through approval, and reschedule from planned with the same unresolved gap.",
          "zh": "停止恢复、撤销演练身份、隔离目标、保留证据，经批准清理后带同一未决缺口从 planned 重新安排。"
        },
        "decommission": {
          "en": "Retire old runbooks only after their services map to approved profiles and one full exercise using the new profile passes.",
          "zh": "旧手册对应服务映射到批准档案并使用新档案通过一次完整演练后，才退役旧手册。"
        }
      }
    },
    {
      "prd_id": "PRD-CIS-16.2-VULNERABILITY-INTAKE",
      "safeguard_id": "16.2",
      "name": {
        "en": "Security vulnerability report intake and closure workflow",
        "zh": "安全漏洞报告接收与闭环工作流"
      },
      "provenance": "example_local_solution",
      "scenario": {
        "en": "External researchers, customers, employees, and automated channels need one safe reporting entry point that acknowledges receipt, protects sensitive material, assigns a product owner, prevents duplicate silence, and closes only after validated remediation or an explicit risk decision.",
        "zh": "外部研究人员、客户、员工和自动化渠道需要一个安全统一入口，确认收件、保护敏感材料、分配产品责任人、防止重复报告石沉大海，并仅在验证修复或明确风险决定后结案。"
      },
      "users": [
        {
          "en": "External security reporter",
          "zh": "外部安全报告者"
        },
        {
          "en": "Product security triager",
          "zh": "产品安全分诊人员"
        },
        {
          "en": "Product and engineering owner",
          "zh": "产品与研发责任人"
        },
        {
          "en": "Legal, privacy, and communications reviewer",
          "zh": "法务、隐私与沟通复核人员"
        }
      ],
      "goals": [
        {
          "en": "Receive reports through a published monitored channel and maintain one stable case across duplicates and updates.",
          "zh": "通过公开且受监控的渠道接收报告，并在重复与更新之间维护一个稳定案件。"
        },
        {
          "en": "Separate receipt, validation, severity, remediation, disclosure, verification, and closure decisions.",
          "zh": "分开收件、验证、严重性、修复、披露、验证与结案决定。"
        }
      ],
      "scope": {
        "included": [
          {
            "en": "Reports about SOSEC-owned products, services, websites, APIs, integrations, and supported releases named by policy",
            "zh": "政策中列明的 SOSEC 自有产品、服务、网站、API、集成与受支持版本报告"
          },
          {
            "en": "Submission, acknowledgement, deduplication, safe attachment handling, triage, ownership, coordination, remediation, retest, disclosure, and closure",
            "zh": "提交、确认、去重、安全附件、分诊、认领、协调、修复、复测、披露与结案"
          }
        ],
        "excluded": [
          {
            "en": "Reports solely about third-party products without a SOSEC-controlled impact path",
            "zh": "仅涉及第三方产品且无 SOSEC 可控影响路径的报告"
          },
          {
            "en": "Authorization for destructive testing, persistence, data access, or service disruption",
            "zh": "授权破坏性测试、持久化、数据访问或服务中断"
          },
          {
            "en": "Automatic public disclosure or bounty payment",
            "zh": "自动公开披露或奖金支付"
          }
        ]
      },
      "identity_contract": {
        "natural_key": "case_id (system) with duplicate links by affected_product + root_cause_fingerprint + reporter evidence",
        "merge_rule": {
          "en": "Potential duplicates remain separate submissions linked to one case until a triager confirms shared root cause; reporter attribution, consent, and attachments never merge silently.",
          "zh": "疑似重复提交在分诊确认同一根因前保持独立并链接到一个案件；报告者归属、同意与附件禁止静默合并。"
        }
      },
      "data_model": [
        {
          "field": "submission_id",
          "type": "uuid",
          "required": true,
          "source": {
            "en": "intake",
            "zh": "接收渠道"
          },
          "lifecycle": {
            "en": "immutable",
            "zh": "不可变"
          }
        },
        {
          "field": "case_id",
          "type": "uuid",
          "required": true,
          "source": {
            "en": "triage",
            "zh": "分诊"
          },
          "lifecycle": {
            "en": "immutable",
            "zh": "不可变"
          }
        },
        {
          "field": "reporter_contact",
          "type": "encrypted_contact|null",
          "required": true,
          "source": {
            "en": "reporter",
            "zh": "报告者"
          },
          "lifecycle": {
            "en": "consent and retention bound",
            "zh": "受同意范围与保留期约束"
          }
        },
        {
          "field": "affected_product",
          "type": "catalog_id",
          "required": true,
          "source": {
            "en": "reporter+triage",
            "zh": "报告者与分诊"
          },
          "lifecycle": {
            "en": "versioned",
            "zh": "版本化"
          }
        },
        {
          "field": "affected_versions",
          "type": "range+evidence",
          "required": true,
          "source": {
            "en": "reporter+reproduction",
            "zh": "报告者与复现"
          },
          "lifecycle": {
            "en": "versioned",
            "zh": "版本化"
          }
        },
        {
          "field": "report_summary",
          "type": "text",
          "required": true,
          "source": {
            "en": "reporter",
            "zh": "报告者"
          },
          "lifecycle": {
            "en": "redacted export",
            "zh": "脱敏后导出"
          }
        },
        {
          "field": "attachments",
          "type": "array<object_ref+sha256+scan_state>",
          "required": true,
          "source": {
            "en": "reporter",
            "zh": "报告者"
          },
          "lifecycle": {
            "en": "quarantined",
            "zh": "隔离保存"
          }
        },
        {
          "field": "authorization_context",
          "type": "scope+method+impact",
          "required": true,
          "source": {
            "en": "reporter+policy",
            "zh": "报告者与政策"
          },
          "lifecycle": {
            "en": "immutable submission",
            "zh": "提交后不可变"
          }
        },
        {
          "field": "triage_state",
          "type": "enum(received,acknowledged,needs_info,validating,accepted,rejected,remediating,verification,disclosure,closed,reopened)",
          "required": true,
          "source": {
            "en": "state machine",
            "zh": "状态机"
          },
          "lifecycle": {
            "en": "history",
            "zh": "历史记录"
          }
        },
        {
          "field": "severity_decision",
          "type": "method+vector+score+owner+time",
          "required": true,
          "source": {
            "en": "triage",
            "zh": "分诊"
          },
          "lifecycle": {
            "en": "versioned",
            "zh": "版本化"
          }
        },
        {
          "field": "owner_id",
          "type": "principal_id",
          "required": true,
          "source": {
            "en": "product catalog",
            "zh": "产品目录"
          },
          "lifecycle": {
            "en": "audited",
            "zh": "可审计变更"
          }
        },
        {
          "field": "remediation_refs",
          "type": "array<change_or_release_ref>",
          "required": true,
          "source": {
            "en": "engineering",
            "zh": "工程团队"
          },
          "lifecycle": {
            "en": "append-only",
            "zh": "仅追加"
          }
        },
        {
          "field": "verification_result",
          "type": "test+environment+expected+observed+time",
          "required": true,
          "source": {
            "en": "product security",
            "zh": "产品安全团队"
          },
          "lifecycle": {
            "en": "append-only",
            "zh": "仅追加"
          }
        },
        {
          "field": "disclosure_decision",
          "type": "scope+date+owner+constraints",
          "required": true,
          "source": {
            "en": "coordination",
            "zh": "协调流程"
          },
          "lifecycle": {
            "en": "versioned",
            "zh": "版本化"
          }
        }
      ],
      "states": [
        {
          "id": "received",
          "definition": {
            "en": "Submission stored, attachment isolated, and receipt clock started.",
            "zh": "提交已保存、附件已隔离并启动收件时钟。"
          }
        },
        {
          "id": "acknowledged",
          "definition": {
            "en": "Reporter received a case reference and safe next-step guidance.",
            "zh": "报告者收到案件引用与安全的下一步指引。"
          }
        },
        {
          "id": "needs_info",
          "definition": {
            "en": "A bounded question blocks validation; current evidence and deadline remain visible.",
            "zh": "有具名问题阻断验证；当前证据与截止时间仍可见。"
          }
        },
        {
          "id": "validating",
          "definition": {
            "en": "Product security tests the claim in an authorized isolated environment.",
            "zh": "产品安全在授权隔离环境中验证主张。"
          }
        },
        {
          "id": "accepted",
          "definition": {
            "en": "Security impact and affected boundary are established; severity and owner are assigned.",
            "zh": "安全影响与受影响边界已建立，并分配严重性与责任人。"
          }
        },
        {
          "id": "rejected",
          "definition": {
            "en": "Evidence does not establish an in-scope security issue; reason and reopen condition are recorded.",
            "zh": "证据未建立在范围安全问题；记录原因与重开条件。"
          }
        },
        {
          "id": "remediating",
          "definition": {
            "en": "A product decision and implementation path are active.",
            "zh": "已有活动的产品决定与实施路径。"
          }
        },
        {
          "id": "verification",
          "definition": {
            "en": "A candidate fix or risk decision awaits independent security verification.",
            "zh": "候选修复或风险决定等待独立安全验证。"
          }
        },
        {
          "id": "disclosure",
          "definition": {
            "en": "Reporter and public or customer communication are coordinated under the approved decision.",
            "zh": "按批准决定协调报告者与公开或客户沟通。"
          }
        },
        {
          "id": "closed",
          "definition": {
            "en": "Verified remediation, supported non-fix decision, or rejected claim meets closure evidence.",
            "zh": "已验证修复、受支持的不修复决定或拒绝主张满足结案证据。"
          }
        },
        {
          "id": "reopened",
          "definition": {
            "en": "New evidence, regression, affected-version expansion, or failed fix invalidates closure.",
            "zh": "新证据、回归、受影响版本扩大或修复失败使结案失效。"
          }
        }
      ],
      "transitions": [
        {
          "from": "received",
          "event": "receipt_sent",
          "to": "acknowledged",
          "guard": {
            "en": "case reference and policy guidance delivered",
            "zh": "已交付案例编号与政策指引"
          }
        },
        {
          "from": "acknowledged|validating",
          "event": "bounded_question_sent",
          "to": "needs_info",
          "guard": {
            "en": "question, owner, deadline present",
            "zh": "已记录待答问题、责任人与截止时间"
          }
        },
        {
          "from": "acknowledged|needs_info",
          "event": "validation_started",
          "to": "validating",
          "guard": {
            "en": "safe environment and authorization confirmed",
            "zh": "已确认安全环境与测试授权"
          }
        },
        {
          "from": "validating",
          "event": "impact_confirmed",
          "to": "accepted",
          "guard": {
            "en": "reproducible boundary and affected scope",
            "zh": "已确认可复现边界与受影响范围"
          }
        },
        {
          "from": "validating",
          "event": "claim_not_established",
          "to": "rejected",
          "guard": {
            "en": "evidence, reason, and reopen condition recorded",
            "zh": "已记录证据、原因与重新打开条件"
          }
        },
        {
          "from": "accepted",
          "event": "remediation_committed",
          "to": "remediating",
          "guard": {
            "en": "owner, target, and tracking reference",
            "zh": "已有责任人、目标与跟踪编号"
          }
        },
        {
          "from": "remediating",
          "event": "candidate_ready",
          "to": "verification",
          "guard": {
            "en": "build or control identity pinned",
            "zh": "已固定构建或控制身份"
          }
        },
        {
          "from": "verification",
          "event": "verification_passed",
          "to": "disclosure",
          "guard": {
            "en": "positive, negative, and regression checks pass",
            "zh": "正向、反向与回归检查均通过"
          }
        },
        {
          "from": "rejected|disclosure",
          "event": "closure_approved",
          "to": "closed",
          "guard": {
            "en": "required evidence and communication complete",
            "zh": "必需证据与沟通均已完成"
          }
        },
        {
          "from": "closed",
          "event": "contradictory_evidence",
          "to": "reopened",
          "guard": {
            "en": "new submission, regression, scope expansion, or failed fix",
            "zh": "出现新提交、回归、范围扩大或修复失败"
          }
        }
      ],
      "functional_rules": [
        {
          "id": "V-01",
          "text": {
            "en": "The public policy names supported channels, scope, safe harbor, prohibited activity, response expectations, and required report fields.",
            "zh": "公开政策列明支持渠道、范围、安全港、禁止行为、响应预期和必填报告字段。"
          }
        },
        {
          "id": "V-02",
          "text": {
            "en": "Every valid submission receives an immutable submission ID and acknowledgement inside the locally published SLO.",
            "zh": "每个有效提交获得不可变 submission_id，并在本地公布 SLO 内确认。"
          }
        },
        {
          "id": "V-03",
          "text": {
            "en": "Attachments remain quarantined, content-addressed, malware scanned, access logged, and never opened in privileged production context.",
            "zh": "附件保持隔离、按内容寻址、恶意软件扫描、访问留痕，禁止在特权生产环境打开。"
          }
        },
        {
          "id": "V-04",
          "text": {
            "en": "Duplicate linkage preserves each reporter, chronology, evidence, consent, and contribution.",
            "zh": "重复关联保留每位报告者、时间线、证据、同意与贡献。"
          }
        },
        {
          "id": "V-05",
          "text": {
            "en": "Acceptance identifies executing component, affected condition, security consequence, tested versions, evidence limits, and accountable product owner.",
            "zh": "接受报告时明确执行组件、受影响条件、安全后果、测试版本、证据边界与产品责任人。"
          }
        },
        {
          "id": "V-06",
          "text": {
            "en": "Severity changes record method, old and new decision, evidence, approver, and communication effect.",
            "zh": "严重性变更记录方法、旧/新决定、证据、批准人和沟通影响。"
          }
        },
        {
          "id": "V-07",
          "text": {
            "en": "Closure after remediation requires pinned candidate identity, original-path retest, negative control, regression result, affected-release decision, and reporter communication state.",
            "zh": "修复后结案要求固定候选身份、原路径复测、负控制、回归结果、受影响发布决定与报告者沟通状态。"
          }
        }
      ],
      "exception_paths": [
        {
          "id": "VX-01",
          "text": {
            "en": "Spam or abuse rejection preserves minimal abuse evidence and never exposes other reporters or internal case data.",
            "zh": "垃圾或滥用拒绝只保留最小滥用证据，不暴露其他报告者或内部案件数据。"
          }
        },
        {
          "id": "VX-02",
          "text": {
            "en": "Suspected live exploitation escalates to incident response while the vulnerability case remains linked and auditable.",
            "zh": "疑似在野利用升级到事件响应，漏洞案件保持关联与可审计。"
          }
        },
        {
          "id": "VX-03",
          "text": {
            "en": "A report involving personal data routes to privacy response with access minimization; deletion requests follow legal and evidence holds.",
            "zh": "涉及个人数据的报告进入隐私响应并最小化访问；删除请求遵循法律与证据保全。"
          }
        },
        {
          "id": "VX-04",
          "text": {
            "en": "No owner or unsupported product state escalates to the product governance owner and cannot close as routing failure.",
            "zh": "无责任人或不支持产品状态升级给产品治理责任人，不能因路由失败结案。"
          }
        },
        {
          "id": "VX-05",
          "text": {
            "en": "A missed SLO creates an operational breach and escalation without changing technical validity.",
            "zh": "错过 SLO 会产生运营违约并升级，但不改变技术有效性。"
          }
        }
      ],
      "permissions_and_audit": {
        "roles": [
          {
            "role": "intake_operator",
            "actions": [
              {
                "en": "view submission metadata",
                "zh": "查看提交元数据"
              },
              {
                "en": "send acknowledgement",
                "zh": "发送回执"
              }
            ],
            "separation": {
              "en": "cannot accept own validation",
              "zh": "不得验收本人完成的验证"
            }
          },
          {
            "role": "product_security_triager",
            "actions": [
              {
                "en": "validate",
                "zh": "验证"
              },
              {
                "en": "accept",
                "zh": "接受"
              },
              {
                "en": "reject",
                "zh": "拒绝"
              },
              {
                "en": "score",
                "zh": "评定严重性"
              },
              {
                "en": "verify",
                "zh": "复核"
              }
            ],
            "separation": {
              "en": "cannot delete submission history",
              "zh": "不得删除提交历史"
            }
          },
          {
            "role": "engineering_owner",
            "actions": [
              {
                "en": "propose fix",
                "zh": "提交修复方案"
              },
              {
                "en": "pin candidate",
                "zh": "固定候选版本"
              },
              {
                "en": "provide rollout",
                "zh": "提供发布方案"
              }
            ],
            "separation": {
              "en": "cannot self-verify security closure",
              "zh": "不得自行验证安全结案"
            }
          },
          {
            "role": "disclosure_coordinator",
            "actions": [
              {
                "en": "approve communication",
                "zh": "批准沟通内容"
              },
              {
                "en": "schedule disclosure",
                "zh": "安排披露"
              }
            ],
            "separation": {
              "en": "cannot alter technical evidence",
              "zh": "不得修改技术证据"
            }
          },
          {
            "role": "privacy_legal_reviewer",
            "actions": [
              {
                "en": "apply hold",
                "zh": "应用保全"
              },
              {
                "en": "approve redaction",
                "zh": "批准脱敏"
              }
            ],
            "separation": {
              "en": "access only when triggered",
              "zh": "仅在触发相应事项时访问"
            }
          }
        ],
        "audit_fields": [
          "actor_id",
          "submission_id",
          "case_id",
          "action",
          "old_state",
          "new_state",
          "reason",
          "evidence_ref",
          "occurred_at",
          "communication_ref"
        ]
      },
      "nfr": [
        {
          "id": "VNFR-01",
          "category": "availability",
          "text": {
            "en": "At least one monitored reporting channel and a tested fallback remain available; failure alerts do not depend on the failed channel.",
            "zh": "至少一个受监控报告渠道和测试过的备用渠道可用；故障告警不依赖故障渠道。"
          }
        },
        {
          "id": "VNFR-02",
          "category": "confidentiality",
          "text": {
            "en": "Reporter data and vulnerability material use least privilege, encryption, access audit, and retention tied to case state and law.",
            "zh": "报告者数据与漏洞材料采用最小权限、加密、访问审计，并按案件状态和法律保留。"
          }
        },
        {
          "id": "VNFR-03",
          "category": "integrity",
          "text": {
            "en": "Submissions, attachments, state events, and evidence use stable IDs and content hashes; edits append new versions.",
            "zh": "提交、附件、状态事件与证据使用稳定 ID 与内容哈希；编辑只追加新版本。"
          }
        },
        {
          "id": "VNFR-04",
          "category": "latency",
          "text": {
            "en": "Acknowledgement, first triage, owner assignment, and stale-case escalation SLOs are published as local service commitments and measured.",
            "zh": "确认、首次分诊、责任人分配和陈旧案件升级 SLO 作为本地服务承诺公布并测量。"
          }
        },
        {
          "id": "VNFR-05",
          "category": "resilience",
          "text": {
            "en": "Queue, mail, or portal failures retain idempotent submissions and support replay without duplicate acknowledgements.",
            "zh": "队列、邮件或门户失败时保留幂等提交，并支持无重复确认的重放。"
          }
        }
      ],
      "acceptance_criteria": [
        {
          "id": "VAC-01",
          "text": {
            "en": "A test submission receives one immutable submission ID and acknowledgement through the published channel.",
            "zh": "测试提交通过公开渠道收到一个不可变 submission_id 与确认。"
          }
        },
        {
          "id": "VAC-02",
          "text": {
            "en": "The same test report through two channels links as a potential duplicate without losing reporter or attachment identity.",
            "zh": "同一测试报告经两个渠道提交后关联为疑似重复，且不丢失报告者或附件身份。"
          }
        },
        {
          "id": "VAC-03",
          "text": {
            "en": "A harmless test attachment stays quarantined and all access is audited; a malware fixture is rejected or isolated.",
            "zh": "无害测试附件保持隔离且全部访问受审计；恶意软件夹具被拒绝或隔离。"
          }
        },
        {
          "id": "VAC-04",
          "text": {
            "en": "A valid in-scope report reaches validating and accepted with affected product, owner, evidence boundary, and severity decision.",
            "zh": "有效在范围报告进入 validating 与 accepted，并具有受影响产品、责任人、证据边界与严重性决定。"
          }
        },
        {
          "id": "VAC-05",
          "text": {
            "en": "An out-of-scope report is rejected with reason and reopen condition, without exposing internal details.",
            "zh": "范围外报告带原因与重开条件被拒绝，且不暴露内部细节。"
          }
        },
        {
          "id": "VAC-06",
          "text": {
            "en": "A candidate fix fails closure when the original path or negative control still fails.",
            "zh": "候选修复在原路径或负控制仍失败时不能结案。"
          }
        },
        {
          "id": "VAC-07",
          "text": {
            "en": "New contradictory evidence against a closed case creates a reopened state and preserves prior closure history.",
            "zh": "针对已结案件的新矛盾证据会创建 reopened，并保留原结案历史。"
          }
        }
      ],
      "release_and_rollback": {
        "migration": {
          "en": "Import active cases with stable mapping, run old and new channels in parallel, verify acknowledgement and ownership, then switch the public policy link.",
          "zh": "以稳定映射导入活动案件，并行运行新旧渠道，验证确认与责任分配后切换公开政策链接。"
        },
        "phases": [
          {
            "en": "Internal workflow and access test",
            "zh": "内部工作流与访问测试"
          },
          {
            "en": "Shadow intake and duplicate comparison",
            "zh": "影子接收与重复比较"
          },
          {
            "en": "Public channel cutover",
            "zh": "公开渠道切换"
          },
          {
            "en": "Legacy case reconciliation and retirement",
            "zh": "旧案件对账与退役"
          }
        ],
        "monitoring": [
          {
            "en": "channel health",
            "zh": "渠道健康度"
          },
          {
            "en": "acknowledgement latency",
            "zh": "回执延迟"
          },
          {
            "en": "unowned case age",
            "zh": "无责任人案例时长"
          },
          {
            "en": "needs-info age",
            "zh": "待补充信息时长"
          },
          {
            "en": "attachment scan failure",
            "zh": "附件扫描失败"
          },
          {
            "en": "verification backlog",
            "zh": "验证积压"
          },
          {
            "en": "reopen rate",
            "zh": "重新打开率"
          },
          {
            "en": "audit write failure",
            "zh": "审计写入失败"
          }
        ],
        "rollback_triggers": [
          {
            "en": "A submission is lost, duplicated without linkage, or acknowledged without durable storage.",
            "zh": "提交丢失、无关联重复，或在未持久保存时确认。"
          },
          {
            "en": "Reporter or vulnerability data is exposed outside approved roles.",
            "zh": "报告者或漏洞数据暴露给未批准角色。"
          },
          {
            "en": "State change or communication occurs without an audit record.",
            "zh": "状态变更或沟通缺少审计记录。"
          }
        ],
        "rollback": {
          "en": "Restore the prior public channel, freeze nonessential state changes, preserve the new queue and IDs, reconcile every receipt, and replay only after identity parity passes.",
          "zh": "恢复上一公开渠道，冻结非必要状态变更，保留新队列与 ID，对账每个回执，并在身份一致后重放。"
        },
        "decommission": {
          "en": "Retire the old channel after all active cases map, reporter references remain valid, retention and holds migrate, and fallback delivery is tested.",
          "zh": "全部活动案件完成映射、报告者引用仍有效、保留与保全已迁移且备用投递通过测试后，才退役旧渠道。"
        }
      }
    }
  ]
}
